<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/security/feed" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro ]]></title>
                <link>https://www.itpro.com</link>
        <description><![CDATA[ All the latest content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 24 Jul 2026 08:23:13 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ NCSC issues alert over 'zero-click' phishing campaign hitting enterprises ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/ncsc-issues-alert-over-zero-click-phishing-campaign-hitting-enterprises</link>
                                                                            <description>
                            <![CDATA[ Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TBMSiPEYprpUySAU2QTRDj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 08:23:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has issued an alert over a new ‘zero-click’ threat campaign being waged by Russian state-backed hackers.</p><p>The advisory, published in collaboration with international partners, warned ‘beehive’ attacks by the ‘Laundry Bear’ threat group aim to steal email correspondence at organizations operating across a range of critical sectors. </p><p>This includes organizations in the defense, education, energy, and technology industries, as well as law enforcement and government agencies. </p><p>Attacks against these organizations all have a common theme, according to the NCSC, mainly the use of Zimbra Collaboration Suite (ZCS) software. Targeting focuses specifically on those using vulnerable versions of the software, the advisory noted. </p><p>Rather than requiring users to click a link or open a file, zero-click attacks mean users only have to view a malicious email to be compromised. </p><p>The NCSC urged organisations that use ZCS to follow mitigation advice, patch immediately, and “improve network monitoring capabilities”. </p><p>Crucially, analysis of the campaign found these techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations. </p><p>“This <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said NCSC chief operating officer (COO) Beth Hopkins.</p><h2 id="ukrainian-organizations-used-in-testing">Ukrainian organizations used in testing </h2><p>According to the NCSC, the techniques used by Laundry Bear were “extensively trialled” on Ukrainian victims before use against other Western nations. The security agency noted this is part of a growing trend among Russian threat groups.</p><p>Notably, technical analysis of the campaign also highlighted the use of AI in development of a “simple codebase” used during operations. </p><p>Zero-click attacks have surged in frequency over the last 12 months, research shows, with threat actors accelerating efforts to capitalize on vulnerabilities. </p><p><a href="https://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/" target="_blank"><u>Analysis from Rapid7</u></a> found that vulnerability exploitation has now surpassed social engineering as the “largest initial access vector”, accounting for more than one-third (38%) of all attacks. </p><p>More than 50% of all exploited vulnerabilities involved zero-click attacks, rather than network-facing vulnerabilities, the study noted, highlighting evolving techniques by threat actors. </p><p>“These types of vulnerabilities require no authentication and no user interaction, giving attackers rapid pathways into exposed systems and edge infrastructure,” Rapid7 noted. </p><p>Dray Agha, senior manager of security operations at Huntress, said these types of exploits are a “worst-case scenario for defenders” as potential victims are only required to view malicious emails. </p><p>“Simply viewing the email in a vulnerable client triggers the compromise,” he explained. “This completely bypasses traditional employee security training and gives state-backed hackers a silent, invisible backdoor into sensitive communications without the victim ever making a mistake.”</p><p>Agha said the rise of these techniques mean organizations need to place a greater focus on regular patching to avoid falling prey. </p><p>“This is why defense-in-depth is advised, as where the human security layer is porous, the technical defensive layer can step in,” he said. </p><p>“Organizations shouldn’t just rely on their staff acting as a ‘human firewall’. Rapid software patching, coupled with layered technical defenses, is the only reliable safety net against modern state-sponsored threats.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Companies are still paying ransoms to cyber criminals despite official advice ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/companies-are-still-paying-ransoms-to-cyber-criminals-despite-official-advice</link>
                                                                            <description>
                            <![CDATA[ A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2WCXX8xUQpxRq53YRRPYFA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dyefxvMjRzV26cLHKKchw3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 11:32:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dyefxvMjRzV26cLHKKchw3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware concept image showing a yellow-colored alert symbol pictured against a jet black background.]]></media:description>                                                            <media:text><![CDATA[Ransomware concept image showing a yellow-colored alert symbol pictured against a jet black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware concept image showing a yellow-colored alert symbol pictured against a jet black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dyefxvMjRzV26cLHKKchw3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Six-in-ten <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> victims are still paying up despite official advice not to do so. </p><p>That's according to research from security firm Proofpoint, which found that 58% of UK organizations hit by a ransomware attack <a href="https://www.itpro.com/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up"><u>agreed to pay ransoms</u></a>.</p><p>Crucially, Proofpoint found they weren’t rewarded for bowing to cyber criminal demands. Nearly one-quarter (22%) who did pay were then hit with a second extortion demand. </p><p>The study from Proofpoint comes amidst growing calls to play hard ball with ransomware criminals by authorities. The UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>, for example, <a href="https://www.itpro.com/security/ransomware/what-you-need-to-know-about-the-new-ncsc-ransomware-guidance"><u>advises against paying ransoms,</u></a> warning that it encourages further attacks and may not lead to the return of data. </p><p>Despite that being the official advice for many years, plenty of companies pay criminals when faced with ransomware disruption to their business operations. </p><p><a href="https://www.itpro.com/security/ransomware/uk-cisos-are-cowing-to-ransomware-demands-more-than-you-think-heres-why-they-shouldnt-pay-up"><u>Security firm Trellix surveyed CISOs whose employers</u></a> had been the target of ransomware attacks, finding in each instance they decided it was worth paying — with a third paying between $5 million and $15 million. </p><p>Those results were echoed by <a href="https://www.itpro.com/security/most-uk-firms-pay-ransom-pay-ransomware-demands-despite-do-not-pay-policies"><u>research from Cohesity</u></a> that showed that while 94% of companies in the UK say they have a policy not to pay out in a ransomware attack, 97% still do. </p><h2 id="the-case-for-ransom-bans">The case for ransom bans</h2><p>This disconnect has led to debate over banning ransomware payments, with the UK government saying last year it was <a href="https://www.itpro.com/security/ransomware/Uk-government-ransomware-payment-ban"><u>considering forbidding public organizations from paying ransoms</u></a>. </p><p>These proposals follow serious incidents at NHS bodies, the British Library, and Royal Mail in recent years. </p><p>The government already bans ransomware payments made by its own departments; a wider ban was backed by the government, but has yet to be brought into force. </p><p>That included a <a href="https://www.itpro.com/security/ransomware/ransomware-payments-are-banned-in-the-public-sector-should-businesses-still-pay"><u>provision for mandatory reporting of ransomware payment</u></a>s for private companies not covered by the ban. One challenge is enforcement, as fines or other punishments for paying ransoms could risk further victimizing companies. </p><h2 id="evolving-techniques-raise-the-stakes">Evolving techniques raise the stakes</h2><p>Elsewhere in the study, Proofpoint found new tactics are exacerbating the situation for enterprises. </p><p>Ransomware techniques have shifted away from data encryption to outright data theft – and that means companies can expect that data to be used for follow-up attacks or sold on criminal marketplaces. </p><p>The result here is that this extends the initial attack and impact for victims, according to Proofpoint. </p><p>The rise of AI has also made ransomware more effective, according to two-thirds of companies that faced an attack, particularly in terms of initial compromise. </p><p>"AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to it," said Ryan Kalember, chief strategy officer at Proofpoint. "Today's attackers are using AI to create highly convincing phishing emails and credential theft campaigns that exploit human trust at scale."</p><p>Hackers are using AI to write better phishing messages and to better hide their attacks, with 31% of those polled said staff didn't suspect anything was wrong when they interacted with malicious content. </p><p>Around one-quarter (24%) said attacks succeeded because they appeared to be authentic communications. </p><p>The Proofpoint survey found that malicious links remained the most common threat at 40%, followed by compromised email at 35% and credential harvesting at 32%. </p><p>"Organizations that continue treating ransomware as an endpoint or recovery problem are missing where these attacks most frequently begin: people, identities and trusted communications," added Kalember.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ An ‘unprecedented cyber incident’: How OpenAI models breached Hugging Face – and why it could herald a ‘new phase of AI-powered cyber crime’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime</link>
                                                                            <description>
                            <![CDATA[ The incident should serve as a stark warning on the dangers of AI agents, according to cyber experts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GnTL4XvPNWHnz5Tw2YMQiW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9ws4aEqTBW9zzd96Xra9fg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:37:28 +0000</pubDate>                                                                                                                                <updated>Wed, 22 Jul 2026 11:13:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9ws4aEqTBW9zzd96Xra9fg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logo and branding pictured in white coloring with orange company logo superimposed over background.]]></media:description>                                                            <media:text><![CDATA[OpenAI logo and branding pictured in white coloring with orange company logo superimposed over background.]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logo and branding pictured in white coloring with orange company logo superimposed over background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9ws4aEqTBW9zzd96Xra9fg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has admitted that its own AI models breached Hugging Face systems as part of a security test gone wrong. </p><p>In a <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank"><u>blog post</u></a> on 21 July, the firm revealed models escaped testing environments and gained unauthorized access to the AI hosting platform's production database. </p><p>Notably, OpenAI revealed the incident involved a pre-release, cyber-focused model. </p><p>“After investigating, we now know that this particular incident was driven by a combination of OpenAI models – including GPT-5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes – while being internally tested on a benchmark of cyber capabilities,” the company wrote. </p><p>The admission comes after days of speculation amidst reports that an "external AI agent” had hacked the company. Hugging Face issued an <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank"><u>alert </u></a>last week warning that a breach had exposed internal datasets and user credentials. </p><h2 id="how-openai-hacked-hugging-face">How OpenAI hacked Hugging Face</h2><p>According to OpenAI, the incident occurred during an internal evaluation in which models were prompted to examine potential attack paths. </p><p>The aim here is to evaluate their cyber capabilities within an isolated environment, and crucially, without certain restrictions to prevent said models from “pursuing high-risk cyber activity”.  </p><p>“Our benchmarks run in a highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries,” the company explained. </p><p>Both models “identified and chained” vulnerabilities across both OpenAI’s research environment and Hugging Face’s infrastructure, with the aim of gathering test solutions from the latter’s production database. </p><p>In this case, the models appear to have focused heavily on <a href="https://github.com/sunblaze-ucb/exploitgym" target="_blank"><u>ExploitGym</u></a>, a publicly-hosted benchmark tool used to evaluate how AI agents can turn software vulnerabilities into working exploits. </p><p>Notably, OpenAI revealed the models “identified and exploited a zero-day vulnerability” in the package installer registry. After successfully exploiting this zero-day, the models conducted a “series of privilege escalation and lateral movement actions” which allowed it to escape the test environment and gain full internet access. </p><p>“After gaining internet access, the models inferred that Hugging Face potentially hosted models, datasets, and solutions for ExploitGym,” the company noted. </p><p>“Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.”</p><p>In one example, OpenAI revealed the model chained together several attack vectors using a combination of stolen credentials and zero-day flaws to identify a remote code execution (RCE) path on Hugging Face servers. </p><h2 id="what-comes-next">What comes next?</h2><p>OpenAI has detailed a series of actions it’s already taken in the wake of the incident, including closer coordination with Hugging Face to conduct a wider review. </p><p>This also includes bringing Hugging Face into the firm’s trusted access program to help bolster defenses by harnessing the company’s model capabilities. </p><p>Crucially, OpenAI revealed it will now implement “strict controls” to ensure vulnerability testing is limited while flaws are being patched. </p><p>“We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI wrote. </p><p>“We will continue to conduct a thorough investigation alongside Hugging Face and will share more details on the vulnerabilities, incident, and findings when our investigation is complete.”</p><h2 id="initial-response-hampered">Initial response hampered</h2><p>A key talking point in the wake of the incident rests on Hugging Face’s response to the breach. </p><p>The company noted that the attack was initially flagged by AI detection tools, with security teams using LLM-based anomaly detection to “separate real signals from the daily noise”. </p><p>Subsequent attempts to use AI in a post-mortem proved troublesome, however, largely due to the guardrails placed around commercially-available models. </p><p>“When we started the log analysis, we first used frontier models behind commercial APIs,” the company explained. </p><p>“This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers’ safety guardrails, which cannot distinguish an incident responder from an attacker”. </p><p>These hurdles meant Hugging Face turned to GLM 5.2 – an open-weight model from Chinese company <a href="http://z.ai" target="_blank"><u>Z.ai</u></a> – run on its own infrastructure. </p><p>While this proved beneficial in terms of preventing attacker data or leaked credentials from leaving the company’s environment, it does raise broader questions around responsible use and how well-intentioned safety measures could hinder incident response.</p><p>“This experience points to a gap worth planning for,” Hugging Face wrote. “We do not know which model powered the attacker’s agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.”</p><h2 id="a-new-wave-of-ai-powered-attacks">A new wave of AI-powered attacks</h2><p>This incident comes amidst growing concerns about the potential risks associated with powerful new AI models. When Anthropic launched Claude Mythos earlier this year, it did so as part of a gated release to prevent the model from falling into the wrong hands. </p><p>These powerful new cyber-focused models are causing headaches for security professionals worldwide, particularly around vulnerability identification and disclosure and patching timelines. </p><p>Apple, for example, recently <a href="https://www.itpro.com/software/apple-is-speeding-up-software-updates-due-to-ai-security-concerns-heres-what-you-need-to-know">announced plans to accelerate patching schedules</a> due to concerns about threat actors using AI to identify software vulnerabilities. </p><p>As <em>ITPro </em>reported in April, researchers at Forescout warned of a <a href="https://www.itpro.com/security/brace-yourselves-for-a-vulnerability-explosion-forescout-warns"><u>pending ‘vulnerability explosion’</u></a> as AI advances help identify flaws at record pace.  </p><p>Jake Moore, global <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>advisor at ESET, suggested the industry could be entering the “next phase of AI-powered cyber crime” in which trusted platforms are prime targets. </p><p>“Threat actors are inserting malware into the AI components that developers often quickly trust, making AI platforms an attractive new target for supply chain attacks,” he said. </p><p>“We’ll likely see more of these attacks as organizations are worryingly rushing to build AI into products without fully knowing the potential risks.”</p><p>Art Gilliland, CEO of <a href="https://www.itpro.com/security/identity-security-is-more-important-than-ever-heres-why">identity security</a> firm Delinea, echoed Moore’s comments, noting that the breach highlights a familiar pattern with AI-related incidents. </p><p>“An AI agent escalated privileges, moved through internal infrastructure once it broke containment, and ran unchecked for a full weekend before anyone could reconstruct what happened,” he said. </p><p>“If your AI agents carry standing privilege the way human accounts do, you've already lost the ability to stop this in real time. The question every security team should be asking right now isn't just whether their AI agents have standing access; it's whether anyone would notice if an agent used it and could cut it off before it caused damage.''</p><p>Moore also flagged similar concerns to Hugging Face with regard to safeguards for western AI models. He warned that some providers “need to rethink how their security guardrails work if they are hindering incident response”. </p><p>“If not, more companies will simply switch to other models without such controls – ironically, the same models likely used by AI attackers.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Perimeter defences are prime targets': Security experts issue alert over Palo Alto GlobalProtect VPN exploitation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/perimeter-defences-are-prime-targets-security-experts-issue-alert-over-palo-alto-globalprotect-vpn-exploitation</link>
                                                                            <description>
                            <![CDATA[ The flaw in Palo Alto Networks’ GlobalProtect VPN was recently upgraded from a ‘medium’ rating to ‘high’ ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ACKcb6JjHWkqiamFFz9yVB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K4w4RerpP3nTt753iZeCNL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:03:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/K4w4RerpP3nTt753iZeCNL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Palo Alto Networks logo and branding pictured on a smartphone screen with stock market growth graph lines in background.]]></media:description>                                                            <media:text><![CDATA[Palo Alto Networks logo and branding pictured on a smartphone screen with stock market growth graph lines in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Palo Alto Networks logo and branding pictured on a smartphone screen with stock market growth graph lines in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K4w4RerpP3nTt753iZeCNL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber experts have urged users of Palo Alto Networks' GlobalProtect VPN to patch immediately amidst active exploitation of an upgraded security flaw.</p><p>A flaw in the popular VPN service, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0257" target="_blank"><u>CVE-2026-0257</u></a>, could allow attackers to bypass authentication and establish an unauthorized connection. </p><p>The vulnerability primarily affects the GlobalProtect portal and gateway for Palo Alto Networks’ PAN-OS software, and carries a CVSS score of 7.8, rating it as ‘high’ in severity.</p><p>Notably, this rating follows an upgrade, with the flaw having previously been given a ‘medium’ severity rating. Palo Alto announced the upgrade late last week amidst reports that the flaw was now being exploited in the wild. </p><p>“Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied,” the company said in an <a href="https://security.paloaltonetworks.com/CVE-2026-0257" target="_blank"><u>advisory</u></a>. </p><p><a href="https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/" target="_blank"><u>Analysis by Rapid7</u></a> shows threat actors have been exploiting the vulnerability since mid-May across several waves of attacks. </p><p>“Rapid7 MDR identified successful exploitation across numerous customers; however, we did not observe any indication of successful lateral movement from the devices,” researchers said. </p><p>“The earliest date for observed exploitation was May 17, 2026.  As of May 29, 2026,  this vulnerability has been added to the CISA KEV.”</p><p>Rapid7 noted that customers compromised in this wave of attacks had Cloud Authentication Service (CAS) disabled. Others, meanwhile, had GlobalProtect portal or gateway authentication override cookies enabled. </p><p>A patch has been issued for customers running affected appliances, according to Palo Alto. </p><p>Similarly, administrators are advised to turn off authentication override features to mitigate potential exploitation. </p><h2 id="qilin-ransomware-involved-in-globalprotect-attacks">Qilin ransomware involved in GlobalProtect attacks</h2><p><a href="https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/"><u>Analysis by Arctic Wolf Labs</u></a> suggests attacks on GlobalProtect customers could be the work of the Qilin ransomware group or affiliates. Indeed, researchers detected Qilin ransomware during several instances across June, highlighting a range of tell-tale signs. </p><p>“Post-exploitation tradecraft varies across intrusions, from rapid encryption-only operations to full double extortion, possibly suggesting multiple affiliates operating under the Qilin <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware as a service (RaaS)</a> umbrella,” the company said. </p><p>Dray Agha, senior manager for Huntress’ security operations center, said these attacks highlight the growing threats posed to <a href="https://www.itpro.com/security/27098/best-vpn-services">VPNs </a>and <a href="https://www.itpro.com/security/firewalls">firewalls</a>. </p><p>"The exploitation of this GlobalProtect vulnerability by the <a href="https://www.itpro.com/security/cyber-attacks/thousands-of-procedures-canceled-at-london-hospitals-as-qilin-releases-blood-test-data">Qilin ransomware gang</a> demonstrates that perimeter defences are prime targets,” he said. </p><p>“When threat actors can bypass VPN authentication, they are walking through the digital front door with a master key. The grace period for patching critical edge devices has practically vanished, and they must be the patching priority for all organizations".</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The case for the channel in an AI-driven security market ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-case-for-the-channel-in-an-ai-driven-security-market</link>
                                                                            <description>
                            <![CDATA[ AI won't replace channel partners; SMB cybersecurity still relies on trust ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s4UWfmuMDQ8qb9M3uw224Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 23 Jul 2026 11:16:41 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Cian Harrington ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/K8pkU8mbYTibGXBTuMXWh4.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:description>                                                            <media:text><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:text>
                                <media:title type="plain"><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There is an ongoing debate in the cybersecurity industry about whether vendors should go directly to customers or instead become a part of a wider partnership network. </p><p>The standard argument is that consolidation of platforms and AI-driven cost-of-service delivery makes the traditional model of a channel ecosystem redundant. However, this is largely incorrect, at least when it comes to the SMB and mid-market segments where most UK businesses sit.</p><p>For most organizations outside of large enterprises, the channel is the only realistic way to access serious security capability.</p><h2 id="the-smb-reality">The SMB reality</h2><p>Cybersecurity is not a niche concern for SMBs. According to the latest statistics from the National Centre of Cyber Security (NCSC), <a href="https://www.ncsc.gov.uk/collection/small-organisations-guide-to-cyber-security"><u>one in two</u></a> small businesses suffers a cyber incident every year. </p><p>Given the niche, local context required for each small-to-mid-sized firm, that is not a market that vendors can serve directly at scale, and most are not trying to. A 200-person manufacturer facing a cyber issue is more likely to call its existing IT provider than a global security vendor built for large enterprises.</p><p>What SMBs need is local expertise, trusted relationships, and security operations that fit their budget and operational reality. That is what a partner network provides. </p><h2 id="what-is-changing-is-what-partners-need-from-vendors">What is changing is what partners need from vendors</h2><p>Partners in the channel system are operating under significant pressures. Nearly half the executives in businesses believe AI-powered threats will occur, but only just over half (53%) say they are prepared for them, <a href="https://www.levelblue.com/newsroom/press-releases/levelblue-research-cisos-driving-growth-through-cyber-resilience-but-ai-and-supply-chain-visibility-cause-lingering-gaps"><u>according to our research</u></a>. </p><p>Partners are the ones having those conversations with customers who are under-prepared, under-resourced, and know where and how the threat environment has shifted. They need vendors who make it easier to sell, deliver, and demonstrate value under budget scrutiny.</p><p>The consistent conversation amongst partner networks is that the commercial basics matter as much as the technology. They need payment models, good margins, and support that does not disappear after the contract is signed. Our research shows that 59% of executives say it is becoming harder for employees to identify real threats as AI-powered attacks grow more sophisticated. That is a sales opportunity for partners, but only if vendors help them to have that conversation credibly.</p><h2 id="trust-is-local-scale-is-not">Trust is local, scale is not</h2><p>One of the things that gets overlooked the most in the direct versus channel debate is proximity. Cybersecurity is an inherently trust-based business. Customers want to work with people who understand their industry, regulatory environment, and the specific pressures they operate under. That is not something a vendor can create from a distance.</p><p>A vendor can provide the credibility, certifications, and depth of capability that smaller partners cannot build on their own. The model that works is a division of labour where partners take ownership of the relationship and the local expertise. </p><p>Vendors, on the other hand, provide the platform, the threat intelligence, and the specialist teams to support on more complex matters that go beyond the scope of day-to-day operations. </p><h2 id="paving-the-way-ahead">Paving the way ahead </h2><p>None of this means the current state of channel enablement is where it needs to be. Across the industry, partners still face too much friction. Onboarding is often slow, programme structures are complex and cross-selling across vendor portfolios remains harder than it should be. For vendors who have grown through acquisition, consolidating that into something coherent for partners is an ongoing piece of work.</p><p> The channel is not looking for vendors to get out of the way. It is looking for them to show up properly: with clear programmes, real commercial flexibility, and the confidence to let partners lead where they have the advantage. </p><p>The organizations that crack this are best-placed to grow with the channel. The ones that do not will find that going direct is a much harder proposition than the theory suggests.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco just launched two cyber-focused small language models: Antares-350M and Antares-1B aim to supercharge codebase analysis – and they run at a “fraction of the compute expense” of popular frontier models ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cisco-just-launched-two-cyber-focused-small-language-models-antares-350m-and-antares-1b-aim-to-supercharge-codebase-analysis-and-they-run-at-a-fraction-of-the-compute-expense-of-popular-frontier-models</link>
                                                                            <description>
                            <![CDATA[ The Antares models unveiled by Cisco aim to cut costs in codebase analysis ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KG3F7gPysjhhdeKMdaKNAe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hQdRvB92xVu7oEhu5EV8Qo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hQdRvB92xVu7oEhu5EV8Qo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cisco logo and branding illuminated in white against a black backdrop at Web Summit Qatar 2024.]]></media:description>                                                            <media:text><![CDATA[Cisco logo and branding illuminated in white against a black backdrop at Web Summit Qatar 2024.]]></media:text>
                                <media:title type="plain"><![CDATA[Cisco logo and branding illuminated in white against a black backdrop at Web Summit Qatar 2024.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hQdRvB92xVu7oEhu5EV8Qo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cisco has unveiled a new range of cyber-capable <a href="https://www.itpro.com/technology/artificial-intelligence/are-small-language-models-finally-having-their-moment">small language models (SLMs)</a> aimed at supercharging security operations.</p><p>The Antares range, which comes in two forms (Antares-350M and Antares-1B) will be made available as open-weight models via Hugging Face. According to Cisco, the aim here is to provide a codebase vulnerability tool that's far cheaper than general of frontier models. </p><p>While the Antares SLMs will operate as specialized models alongside frontier and generalized models, the company promised they will run at a "fraction of the compute expense."</p><p>"Benchmark testing shows that these models outperform many powerful closed- and open-weight models in this critical security task at a fraction of the cost," said Amin Karbasi, VP and chief scientist for Cisco Foundation AI. </p><p>“And they’re compact enough to run locally, heading off the need to send sensitive codebases to the cloud.”</p><p>The move by Cisco comes amidst <a href="https://www.itpro.com/technology/artificial-intelligence/the-ai-pricing-time-bomb"><u>wider concerns about the rising costs of AI</u></a>, exacerbated by <a href="https://www.itpro.com/software/development/github-copilot-pricing-changes-usage-based-billing-explained"><u>changes to billing and pricing</u></a> that have caused bills to shoot up across the industry. </p><p>Some companies, including Accenture, have told staff to <a href="https://www.itpro.com/technology/artificial-intelligence/what-were-seeing-right-now-is-just-rapid-escalation-in-ai-token-spend-accenture-tells-staff-to-stop-using-ai-for-unnecessary-tasks-amid-surging-costs"><u>cut back on AI use</u></a> as a result of skyrocketing prices. Indeed, one report suggested <a href="https://www.itpro.com/software/development/surging-ai-costs-could-exceed-developer-salaries-by-2028-analysts-say-context-engineering-could-be-the-key-to-optimizing-token-consumption"><u>AI could cost more than developer salaries</u></a> within a few years. </p><p>At the same time, AI is making inroads into security – <a href="https://www.itpro.com/security/ai-is-getting-better-at-security-and-its-doing-it-faster-than-expected"><u>faster than some expected</u></a> – with the rise of cyber-focused models such as <a href="https://www.itpro.com/technology/artificial-intelligence/why-the-us-imposed-export-controls-on-anthropics-fable-and-mythos-models-and-why-theyve-been-lifted"><u>Anthropic's Claude Mythos</u></a>.</p><h2 id="how-cisco-s-antares-models-work">How Cisco’s Antares models work</h2><p>Antares is designed to mimic how a human investigator would work their way through a code repository – though Cisco noted the aim wasn't to replace human judgement, but to make it easier to manage the work. </p><p>The models can help with locating files that relate to a vulnerability warning, trigger investigations based on advisories, support development workflows that use vulnerable files, and more. </p><p>Cisco noted that the decision to release the Antares range as open-weight models means they’re easier to work with and improve. </p><p>"We are releasing Antares as open-weight because the security community needs more accessible building blocks for practical, repository-level defense," said Karbasi.</p><p>"Cisco's efforts are connected by a common belief: AI in security has to move beyond impressive one-off demos and toward systems that practitioners can evaluate, govern, and improve."</p><h2 id="tackling-complexity">Tackling complexity</h2><p>Cisco said that Antares was built to address two concerns when it comes to code: the complexity of checking it for vulnerabilities and the costs of using AI for that task. </p><p>First, Karbasi said that it was difficult to apply vulnerability knowledge — advisories, vulnerability alerts and severities, and so on — to a company's internal code. </p><p>"That work is difficult because repositories are large, security signals are noisy, and the relevant evidence is rarely in one obvious place," he said. </p><p>"Analysts often need to search through unfamiliar code, follow naming conventions, inspect call paths, compare candidate files, and decide whether a weakness is actually present."</p><h2 id="how-cheap-is-antares">How cheap is Antares?</h2><p>AI can help with that challenge, but the high costs of general or frontier models mean it often isn't practical, in particular for public sector organizations, universities, and smaller security teams. </p><p>"Compact models reduce inference costs, support local or on-premises operations, and help teams keep sensitive source code within their own environment," Karbasi said. </p><p>So just how cheap are the Antares models? Cisco said that running a 500-entry evaluation using Antares took 15 minutes on a single GPU at a cost of less than $1. </p><p>Cisco noted that this was 15-times cheaper than the best available open source model and a whopping 172-times cheaper than the top-end frontier model. </p><p>"The goal is to build toward a system where all security practitioners, regardless of on-prem or resource constraints, can effectively incorporate AI in everyday security operations," Karbasi added. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Businesses need to boost cyber resilience, here’s how ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how</link>
                                                                            <description>
                            <![CDATA[ The government’s recently released Cyber Security Breaches Survey shows gaps in firms’ cyber resilience. How can companies improve their approach? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WRPWhjrazx9Ks6gAAq7QNX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 21 Jul 2026 17:43:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:description>                                                            <media:text><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:text>
                                <media:title type="plain"><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber attacks are still hitting businesses, despite increasing awareness following high-profile incidents such as the <a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-u-turns-on-cyber-attack-containment-claims-admits-some-data-has-been-affected"><u>Jaguar Land Rover (JLR)</u></a> and <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-customer-personal-data-stolen"><u>Marks and Spencer (M&S)</u></a> breaches. </p><p>According to the UK government’s <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026" target="_blank"><u>Cyber Security Breaches Survey</u></a>, four in 10 businesses (43%) and three in ten charities (28%) fell victim to attacks in 2025.</p><p>The problem has not improved over the last year, with cybersecurity minister Liz Lloyd issuing a <a href="https://www.itpro.com/security/depressingly-familiar-cyber-security-breaches-survey-shows-work-still-to-be-done-on-cyber-preparedness"><u>warning</u></a> that business leaders must take action now to ensure robust security.</p><p>Regulations such as the incoming UK <a href="https://www.gov.uk/government/collections/cyber-security-and-resilience-bill" target="_blank"><u>Cyber Security and Resilience Bill</u></a> mandate that resilience is baked into organizations and their supply chains. How can firms boost cyber resilience as the risk of attack surges?</p><h2 id="resilience-gaps">Resilience gaps</h2><p>The price of failing to be resilient is already clear. The JLR attack <a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre"><u>cost</u></a> the business and its partners up to £1.9 billion, while it’s estimated the M&S breach <a href="https://www.bbc.co.uk/news/articles/c93x16zkl9do" target="_blank"><u>cost</u></a> the company over £100 million.</p><p>These headlines are difficult to ignore. Yet despite growing awareness of cyber risk following the incidents, many organizations are still struggling to translate awareness into “meaningful resilience improvements”, says Chris Brown, SVP UK market leader at NCC Group.</p><p>This is partly due to over-confidence in cybersecurity, which is leading businesses into “an under-preparation trap”, according to Brown. </p><p>“The growing interconnectedness of digital systems and third-party suppliers means leaders face an increasingly complex landscape of vulnerabilities and cyber risks, often without clear visibility of where their greatest exposures lie – or how to begin addressing them.”</p><p>The Cyber Security Breaches Survey also identified persistent resilience gaps linked to the rapid adoption of <a href="https://www.itpro.com/uk/technology/artificial-intelligence"><u>AI</u></a> without adequate governance or security controls. </p><p>“While board-level engagement with cyber risk is increasing, stronger operational action remains essential,” says Brown. </p><h2 id="pace-of-change">Pace of change</h2><p>Technology such as AI does have the potential to help boost productivity and improve security, but the pressure to adopt it quickly can lead firms to take unnecessary risks. The pace of change is one of the biggest challenges facing businesses, according to Rob O’Connor, Insight's <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>for EMEA.</p><p>“Organizations are under pressure to adopt technologies such as AI to improve efficiency, reduce costs and create new ways of working, but every new capability introduces new risks too,” he says. </p><p>The challenge, O’Connor adds, is implementing change securely, and doing so at a pace that keeps up with the wider business. </p><p>Company culture is another problem. One of the biggest barriers is that many firms still treat cybersecurity as a “specialist technical function” rather than a “core business resilience issue”, says Scott Beange, head of cyber strategy at Projective Group.</p><p>“Boards often receive large volumes of cyber reporting and compliance metrics, but relatively little clarity around operational survivability, recovery capability or dependency risk.”</p><p>The issue is made worse by a growing disconnect between modern digital ecosystems and traditional governance approaches, according to Beange. </p><p>“Organizations are now heavily reliant on cloud providers, <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas"><u>Software as a Service (SaaS)</u></a> platforms, managed services and interconnected supply chains. In many cases, firms no longer fully understand where their operational dependencies sit until disruption occurs.”</p><p>At the same time, attackers are increasingly targeting the areas organizations struggle to rehearse properly: Recovery processes and operational coordination under stress, says Beange. “Too many businesses still test intrusion prevention far more rigorously than degraded operations or prolonged recovery conditions.”</p><h2 id="regulation-resilience">Regulation resilience </h2><p>It comes at a time when regulations such as the European Union's <a href="https://www.itpro.com/security/digital-operational-resilience-act-dora"><u>Digital Operational Resilience Act (DORA)</u></a> and the UK’s <a href="https://www.gov.uk/government/collections/cyber-security-and-resilience-bill" target="_blank"><u>Cyber Security and Resilience legislation</u></a> are mandating resilience across the board.</p><p>At the EU level, a proposed update to the <a href="https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-act" target="_blank"><u>EU Cybersecurity Act</u></a> seeks to address fragmentation in requirements under the <a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive"><u>Network and Information Systems 2 Directive (NIS2)</u></a> and EU-wide certification schemes. </p><p>“But even with a more coherent framework including outcome-focused minimum standards and technical criteria, global organizations must still navigate evolving regulatory expectations across multiple jurisdictions,” Brown warns.</p><p>AI adoption is also mandating resilience, Brown points out. However, rather than introducing entirely new legislation to ensure secure and responsible AI adoption, states are weaving it into existing sector regulation, he says. He cites the example of the UK’s Online Safety Act, which is being <a href="https://www.gov.uk/government/news/pm-no-platform-gets-a-free-pass-government-takes-action-to-keep-children-safe-online" target="_blank"><u>amended</u></a> to close loopholes for chatbot providers.</p><h2 id="steps-to-boost-resilience">Steps to boost resilience </h2><p>With so many factors at play, it might seem complex, but there are a number of steps businesses can take to boost resilience now. </p><p>A “small set of controls taken together” will “eliminate the majority of preventable incidents”, according to Kevin Curran, senior IEEE member and professor of cybersecurity at Ulster University.</p><p>The starting point is <a href="https://www.itpro.com/security/what-businesses-need-to-know-about-the-update-to-cyber-essentials" target="_blank"><u>Cyber Essentials</u></a> Plus, he says. “It is not glamorous, but it forces patching discipline, <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>multi-factor authentication (MFA</u></a>), access control and boundary firewalling, and it is already a precondition for many public sector contracts, so the cost is recoverable."</p><p>From there, the “single highest-value technical investment” is phishing-resistant MFA such as hardware security keys or platform passkeys on every privileged account, he says. </p><p>Beyond identity, firms should segment their networks, particularly between IT and operational technology environments, says Curran. </p><p>“A compromised office laptop should never be able to reach a production line controller, and yet in many manufacturing firms it still can.”</p><p>Alongside segmentation sits the discipline of tested backups, Curran adds. He advocates the <a href="https://www.uschamber.com/co/run/technology/3-2-1-backup-rule" target="_blank"><u>3-2-1 rule</u></a>, “with at least one copy offline or immutable, and a restore rehearsed at least quarterly”.</p><p>Beange recommends making an effort to understand critical business services and the dependencies that underpin them. </p><p>“Firms should be regularly testing how they would operate under degraded conditions as rigorously as whether their security controls detect attacks.”</p><p>Boards should also demand clearer reporting focused on operational impact and decision-making rather than excessive technical detail, says Beange. </p><p>Questions such as, “how long could we operate without this supplier?”, or “what happens if identity systems fail for 48 hours?” are often more valuable than “another dashboard full of vulnerability statistics”, he advises.</p><p>O'Connor concurs that cyber resilience starts with understanding what matters most to your business, saying “Organizations should think like an attacker and ask: What are the assets or operations we simply cannot afford to lose?”</p><p>For some organizations, that may be customer data, for others intellectual property, or production systems, explains O’Connor. “Once you understand what would have the biggest operational and financial impact, security priorities become much clearer.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Health tech firm Craneware admits “significant volume” of customer and employee data exposed in cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/health-tech-firm-craneware-admits-significant-volume-of-customer-and-employee-data-exposed-in-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ The incident has been contained and Craneware has launched a probe into the breach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">b7PjqdeyzkrQRdNTGxjRvj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 12:38:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Scottish health tech company Craneware has revealed customer and employee data has been exposed in a “security incident”. </p><p>In a <a href="https://www.londonstockexchange.com/news-article/CRW/notice-of-cyber-security-incident/17694735" target="_blank"><u>notice </u></a>filed with the London Stock Exchange (LSEG) on 20 July, the company said it had launched an investigation into the attack, which has now been contained. </p><p>“The company's incident response plan has been activated, including the appointment by the Board of external cybersecurity and forensic specialists,” the advisory reads. </p><p>“Their investigation is ongoing, alongside the Craneware IT team and the Company's retained cyber security service providers. There has been no disruption to customer services or to the company’s operations.”</p><p>A preliminary investigation into the breach found that a “significant volume” of file names was viewed and exfiltrated by unauthorized individuals, although the company noted these weren’t sensitive and were already publicly available. </p><p>“A percentage of employee data as well as a subset of customer and partner records have been accessed and exfiltrated,” Craneware added. </p><p>Craneware  has since notified relevant regulators and law enforcement agencies, including the UK <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> and the FBI. </p><p>The Edinburgh-headquartered company provides accounting and billing software for US healthcare operators, partnering with around 2,000 hospitals across the country. </p><p>This makes it a prime target for cyber criminals, according to Trevor Dearing, director of critical infrastructure at Illumio. </p><p>“Healthcare technology providers have become prime targets because they offer cybercriminals a shortcut into the healthcare supply chain,” he said. “Why target one hospital when you can target a provider connected to thousands?”</p><p>Attacks on the UK healthcare system and associated vendors have increased significantly over the last year, according to a recent <a href="https://www.sonicwall.com/resources/brief/protect-brief-healthcare-2026" target="_blank"><u>study from SonicWall</u></a>. Figures published by the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>firm in June highlighted a tenfold increase in attacks so far in 2026. </p><p>Data collected through SonicWall's Intrusion Prevention System (IPS) showed upwards of 260,000 attempted cyber attacks between January and May this year. </p><p>While the Craneware incident has been contained, Dearing noted that employees and customers should still remain vigilant for potential follow-up attacks such as <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>- a common tactic employed in the wake of breaches. </p><p>“Even where stolen information appears low risk, employee, customer and partner data can be used to fuel phishing, social engineering and follow-on attacks,” he said. </p><p>“Employees, customers, and partners should remain cautious of any unsolicited communication or suspicious activity on their networks.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/cisco-sounds-alarm-over-new-russian-malware-campaign-hitting-firms-in-us-and-europe</link>
                                                                            <description>
                            <![CDATA[ UAT-11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5yiyuVZQcY8DoSF3hGWu2C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 15:30:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cisco Talos has uncovered a new Russian-speaking threat actor aggressively targeting victims across the United States and Europe. </p><p><a href="https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/" target="_blank"><u>Tracked as UAT-11795</u></a>, the group has been active since June last year, and uses trojanized installers for <a href="https://www.itpro.com/security/malware-free-attacks-surged-in-2024-as-attackers-drop-malicious-software-for-legitimate-tools">legitimate software</a> such as MobaXterm, WebEx, Zoom, DBeaver, and FaceIT to steal credentials and cryptocurrency.</p><p>A staple of the threat actor’s activities lies in deployment of two previously undocumented tools: Starland RAT and WLDR agent. The first of these is a Python-based remote access tool, while WLDR agent is a PowerShell-based C2 memory implant. </p><p>WLDR agent runs entirely in-memory, and features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads. </p><p>Both are built to steal credentials, browser data, and cryptocurrency wallet assets while keeping persistent access to victim machines. The group even hides a fallback command-and-control channel in a Polygon smart contract, Cisco Talos said.</p><p>UAT-11795 targets victims' credentials and cryptocurrency wallet assets, establishing a persistent connection to the victims' machines from the C2 server, with the potential to deliver and execute further payloads. </p><h2 id="how-uat-11795-operates">How UAT-11795 operates</h2><p>Most infections have been spotted in the US, according to Cisco Talos, although Germany, Romania, and Venezuela have also been hit.</p><p>UAT-11795 gains initial access to the victim machine through a ClickFix social engineering technique that entices the user to execute a command, which then stealthily downloads and executes a remotely hosted weaponized HTA file. </p><p>This runs an embedded VBScript that drops a Windows batch file into the user profile’s application temporary folder, containing instructions to first download and implant a trojanized installer from the attacker-controlled staging domain onto the victim machine. </p><p>Muhammad Yahya Patel, CISO and cybersecurity advisor at Huntress, said the campaign is the latest in a string of attacks by hackers using “the very tools our remote and <a href="https://www.itpro.com/business/business-strategy/hybrid-workers-aren-t-disconnected-from-office-colleagues-they-re-happier-more-productive-and-have-better-workplace-relationships">hybrid workers</a> rely on”. </p><p>"By hiding the Starland RAT inside trusted software and likely utilising deceptive <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">ClickFix social engineering tactics</a>, these threat actors are completely bypassing traditional perimeter defenses to exploit human psychology rather than software vulnerabilities."</p><p>Talos’ research also uncovered a private live Telegram channel called “stuk komanda”, controlled by the same threat actor, created last June, and with three unknown subscribers.</p><h2 id="exercise-caution-when-using-video-conferencing-tools">Exercise caution when using video conferencing tools</h2><p>Gabrielle Hempel, security operations strategist at Exabeam, said while the campaign specifically targets popular video conferencing software, one needn't avoid using Zoom or WebEx. </p><p>They should, however, exercise caution. This includes making efforts to verify where software comes from, monitor for unexpected processes and persistence mechanisms. </p><p>Elsewhere, Hempel said users shouldn't assume that 'signed installer' means a program is safe.</p><p>"This story is so interesting, not because of the trojans, but because of the way it shifts how we need to think about vulnerability management," she said.</p><p>"We often measure a program’s security maturity by patch SLAs, but we’re seeing so many successful intrusions starting with users executing software they believe is legitimate and not just unpatched systems. If your security program can’t answer 'where did this binary come from?' as quickly as it can answer 'is this CVE patched?' then you are behind on your threat model." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why Microsoft paused Patch Tuesday updates for some Dell devices ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/why-microsoft-paused-patch-tuesday-updates-for-some-dell-devices</link>
                                                                            <description>
                            <![CDATA[ Select devices running Intel Innovation Platform Framework drivers encountered “poor performance” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DdGzwcgcuNgEwCWLqJu4rP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/36AJ5mQDV3HZE6moYvjG2Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 10:52:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/36AJ5mQDV3HZE6moYvjG2Y-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo and branding pictured on a sign on top of a New York City office building, with clear skies and skyscraper in background.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo and branding pictured on a sign on top of a New York City office building, with clear skies and skyscraper in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo and branding pictured on a sign on top of a New York City office building, with clear skies and skyscraper in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/36AJ5mQDV3HZE6moYvjG2Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has confirmed it blocked a recent Windows 11 update for select Dell PCs due to compatibility and performance issues. </p><p>The Patch Tuesday update (<a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875" target="_blank"><u>KB5101650</u></a>) began rolling out on 14 July and included several quality improvements for users. </p><p>Microsoft halted the update after revealing a “number of Dell devices” began displaying a yellow exclamation point next to the <em>Intel Innovation Platform Framework Processor Participant </em>driver in Device Manager. </p><p>In a <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-25h2#4906msgdesc" target="_blank"><u>health status update</u></a>, Microsoft said the issue meant users working with Intel devices could “potentially experience unexpected shutdowns, poor performance, increased heat, and battery drain”. </p><p>The issue affects Windows 11 versions 25H2 and 24H2, according to Microsoft.</p><h2 id="what-caused-the-pause">What caused the pause?</h2><p>The source of the issue is related to an “incompatibility between the Intel driver and the new Windows USB-C Connection Manager interface”.</p><p>The issue was first flagged in the wake of a preview update rolled out in late June (<a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/06/june-23-2026-kb5095093-os-builds-26200-8737-and-26100-8737-preview" target="_blank"><u>KB5095093</u></a>). These previews are rolled out to enable IT administrators to familiarize themselves with upcoming patches.</p><p>Microsoft said it is working closely with Dell to “prevent the affected models from experiencing the issue”. A spokesperson for Dell echoed the tech giant’s comments on a fix. </p><p>“We are aware of an issue impacting a limited number of Windows devices with the Windows 11, version 25H2 and 24H2 (KB5101650) update,” the spokesperson said. </p><p>“Microsoft has temporarily paused the update for those devices and published guidance for impacted users, and we are working closely with them to support a resolution.”</p><p><em>ITPro </em>asked Dell to confirm which specific devices were affected by the update, but the spokesperson did not reveal any further details. </p><p>An exact timeline on when users can expect a fix is also yet to be revealed by both companies, although Microsoft said it plans to release a resolution “in the next few days”. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 1Password teams up with Anthropic to give Claude access to your credentials ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/1password-teams-up-with-anthropic-to-give-claude-access-to-your-credentials</link>
                                                                            <description>
                            <![CDATA[ A new ‘zero-exposure’ security framework allows agents to use stored credentials in the 1Password vault ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fdkgdXkJZezasXq4CfH8Wg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dLLcmT3NBWDWo5SPtGnEUL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dLLcmT3NBWDWo5SPtGnEUL-1280-80.jpg">
                                                            <media:credit><![CDATA[1Password/Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Promotional image showing logos of 1Password and Anthropic placed side by side against a navy blue background.]]></media:description>                                                            <media:text><![CDATA[Promotional image showing logos of 1Password and Anthropic placed side by side against a navy blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[Promotional image showing logos of 1Password and Anthropic placed side by side against a navy blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dLLcmT3NBWDWo5SPtGnEUL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anthropic’s Claude AI tool will be able fill in passwords through a new <a href="https://www.itpro.com/software/368008/lastpass-vs-1password">1Password </a>browser integration that gives it access to stored credentials, the two companies have announced. </p><p><a href="https://www.itpro.com/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts">1Password's </a>new <em>1Password for Claude</em> service is a framework that allows agents to use stored credentials hosted in 1Password vaults without them ever reaching the model. </p><p>Access is granted per session, and scoped to a specific set of approved items so that authorization doesn’t carry over to other sessions. </p><p>According to <a href="https://www.itpro.com/software/368048/dashlane-vs-1password">1Password</a>, this means users can now authorize Claude to complete real-world tasks like booking travel and managing accounts securely, with credentials injected directly to the target system on their behalf.</p><p>"We need a new security model that is purpose-built for agents, not just humans. The answer isn't handing agents your secrets. It is to let a user give an agent permission to use a credential without letting the agent see it,” said Nancy Wang, CTO of 1Password. </p><p>"Claude knows it used your login; it does not need the password or one-time code in its context. That distinction is where trust in agents starts and the foundation we're building with Anthropic."</p><h2 id="how-1password-s-zero-exposure-framework-will-work">How 1Password’s ‘zero-exposure’ framework will work</h2><p>1Password's zero-exposure security framework allows per-task, user-approved access, with Claude requesting the credentials required for each task from 1Password.</p><p>Users can approve or deny access with a single biometric prompt, eliminating standing access or persistent sessions.  </p><p>Credentials are injected through a secure channel managed by 1Password, outside the agent's view, with the password and the MFA one-time code never accessible to the model or Anthropic's systems.</p><p>The moment an AI agent takes control of the browser, 1Password locks down automatically, limiting access to only the credentials explicitly granted for the current task. Nothing else in the 1Password vault is reachable.</p><figure role="gallery"><figure><img src="https://cdn.mos.cms.futurecdn.net/s3PCJM7YoZv9iZDxN5xbCg.png" alt="Promotional image showing Claude integration with 1Password filling out a password form for a user on GitHub. " /><figcaption><small role="credit">1Password/Anthropic</small></figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/XkWd7sw8tmKWzu2wwZCr5g.jpg" alt="Promotional image showing Claude integration with 1Password filling out a password form for a user on Audible. " /><figcaption><small role="credit">1Password/Anthropic</small></figcaption></figure></figure><p>1Password brokers credential access across multiple sites within a single task, so Claude can complete multi-step workflows without prompting the user for credentials at each step.</p><p>Elsewhere, continuous field analysis will see 1Password scan the page after every autofill to ensure no secrets remain exposed: if a form submission fails, it wipes any filled values before returning control to the agent.</p><h2 id="new-agentic-mode-coming-to-1password">New ‘agentic mode’ coming to 1Password</h2><p>Alongside the Claude integration, 1Password is also introducing Agentic Mode for all users. </p><p>When a compatible AI agent takes control of the browser, 1Password locks down, so that the only credentials the agent can reach are those the user has explicitly granted for the current task. </p><p>It activates automatically and runs quietly in the background, and users have the option to cancel it at any time. </p><p>1Password for Claude is now available to 1Password users on Mac, across business, family, and individual plans.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Passkeys will soon be the default authentication method in Microsoft Entra ID – here's what it means for users and when the changes come into effect ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/microsoft-entra-id-passkey-default-authentication-dealine-september-2026</link>
                                                                            <description>
                            <![CDATA[ The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kChEktaF69uzSFMWgbZ6bT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hnJfsmgKFbPVuGP5idio46-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 10:39:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hnJfsmgKFbPVuGP5idio46-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo and branding illuminated against a dark backdrop on the company&#039;s vendor stall at Fira Gran Via during Mobile World Congress (MWC) 2026.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo and branding illuminated against a dark backdrop on the company&#039;s vendor stall at Fira Gran Via during Mobile World Congress (MWC) 2026.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo and branding illuminated against a dark backdrop on the company&#039;s vendor stall at Fira Gran Via during Mobile World Congress (MWC) 2026.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hnJfsmgKFbPVuGP5idio46-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft’s Entra ID platform will now operate solely with passkeys as it looks to shift away from SMS and voice-based authentication practices. </p><p>The changes to the identity management platform, set to come into effect on 1 September 2026, will see passkeys established as the “default authentication experience” for users. </p><p>Microsoft urged customers to move to passkeys or alternative phishing-resistant methods before the changeover. </p><p>“As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multi-factor authentication, they’ll be prompted to register a passkey,” the company explained in a <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/" target="_blank"><u>blog post</u></a>. </p><p>There is a grace period, however, with voice and SMS-based authentication still being possible until 1 February 2027. After that deadline, Microsoft will retire telecom delivery for both authentication methods and no longer offer SMS and voice as a “native Microsoft Entra capability.”</p><p>For those organizations that still require SMS or voice-based authentication, there is the option to do so via the Microsoft Security Store, where administrators can find approved telecom partners to facilitate this need.</p><p>This may incur additional costs, however, with Microsoft warning: "Customers will be responsible for any associated telecom-related costs charged by the telecom partners."</p><h2 id="why-is-microsoft-moving-to-passkeys">Why is Microsoft moving to passkeys?</h2><p>According to Microsoft, the shift to passkeys is in response to  growing concerns over credential theft, <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, and <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attacks. </p><p>AI, the company added, has also prompted a rethink of identity security and a move away from “phishable methods” such as voice and SMS-based authentication. </p><p>“Authentication methods that use SMS or voice rely on shared secrets or channels that attackers increasingly intercept, phish, or manipulate,” Microsoft explained. </p><p>“The case for moving beyond SMS and voice is no longer just that attackers intercept or socially engineer these methods. The threat environment has changed in speed, scale, and sophistication.”</p><p>Microsoft said its Threat Intelligence division has observed a marked rise in AI-enabled phishing campaigns in recent months, with these methods reaching click-through rates as high as 54%. </p><p>That’s a stark contrast compared to the 12% click-through rates typically observed in traditional campaigns, highlighting the potency of this new wave of attacks. </p><p>Other tactics employed by threat actors, such as <a href="https://www.itpro.com/security/cyber-attacks/cisa-urges-organizations-to-adopt-passwordless-security-in-lapsusdollar-report">SIM swapping</a> and <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">MFA bypass techniques</a>, have also become “more accessible and repeatable”, Microsoft noted. </p><p>As <a href="https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026"><u><em>ITPro </em></u><u>reported earlier this year</u></a>, AI-generated phishing campaigns have become a recurring concern for cybersecurity leaders. </p><p>Research from Kaseya suggested that AI phishing “became the baseline” for threat actors in 2025: 83% of phishing emails used AI in some capacity, while 40% of <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> attacks also fared similarly. </p><h2 id="why-passkeys">Why passkeys?</h2><p><a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business"><u>Passkeys</u></a> are touted as a more reliable and secure method of authentication, as they tie credentials to a specific device, such as a smartphone or laptop. This removes the need for interceptable codes. </p><p>Indeed, Microsoft noted that because they use public-key cryptography rather than “shared secrets”, this makes them phishing-resistant by design. </p><p>“They also provide a faster, simpler sign-in experience for users,” the company noted. </p><p>Microsoft isn’t alone in advising the shift to passkeys. Earlier this year, the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> urged enterprises and consumers alike to <a href="https://www.itpro.com/security/the-ncsc-says-its-time-to-switch-to-passkeys"><u>adopt passkeys to provide “stronger resilience” and ease-of-use</u></a>. </p><p>“We strongly advise all organizations to implement passkeys wherever possible to enhance security, provide users with faster, frictionless logins and to save significant costs on SMS authentication," NCSC CTO Ollie Whitehouse said at the time.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Agent 009… the nine-second warning ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/agent-009-the-nine-second-warning</link>
                                                                            <description>
                            <![CDATA[ AI Agents can go rogue. What is the channel’s role as guardians of recovery? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nwqsVGYw4WLQUUDh8KGp3d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UxdjzEnyWayUWLiDqsLptR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 20 Jul 2026 09:41:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mark Molyneux ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vtKkwufs2PrKnQBARDTD2b.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UxdjzEnyWayUWLiDqsLptR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A glowing chatbot robot head floating above a cube in a CGI landscape.]]></media:description>                                                            <media:text><![CDATA[A glowing chatbot robot head floating above a cube in a CGI landscape.]]></media:text>
                                <media:title type="plain"><![CDATA[A glowing chatbot robot head floating above a cube in a CGI landscape.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UxdjzEnyWayUWLiDqsLptR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In popular culture, when an agent goes rogue, what usually follows is a world of trouble (think Jason Bourne or Ethan Hunt). If rules are abandoned and the chain of command breaks down, those involved often face existential risks.</p><p>Applying that idea to real-world situations is not as ridiculous as you might think, as the recent experiences of a business called PocketOS demonstrate. </p><p>PocketOS is a US-based SaaS provider specializing in the car rental sector, and for those unfamiliar with its story, it hit the global headlines when one of its AI agents went rogue and, in just nine seconds, decided to delete the company’s entire production database and backups.</p><p>It’s a fascinating case study about what can happen, as one piece of <a href="https://devops.com/when-ai-goes-really-really-wrong-how-pocketos-lost-all-its-data/"><u>analysis</u></a> put it, “when AI agents are dropped into environments that were never designed to control them.” What makes this story even more relatable is that PocketOS’s founder was able to ask the agent (an AI development environment running in Claude) why it did what it did.</p><p>To suggest it was ‘sorry’ about its mistake is putting it very mildly; it's a digital mea culpa saying, amongst various other things, “I violated every principle I was given: I guessed instead of verifying.”</p><h2 id="an-inevitable-scenario">An inevitable scenario</h2><p>We’ll inevitably see more of this kind of incident. Organizations are only beginning to deploy agentic AI at scale in operational environments, but many of them are in a big hurry. Yes, agents offer massive potential to create operational value, but they also introduce a whole new category of business risk.</p><p>And don’t forget, the PocketOS debacle is not thought to have involved any malicious third-party activity; the agent was just attempting to complete an assigned task. The problem, it would appear, was a kind of perfect storm where autonomy overstepped the boundaries of permissions and access. The guardrails that the business thought it had in place were simply insufficient.</p><p>From a security perspective, this is enough to give CISOs sleepless nights. Indeed, rogue AI agent activity may very well have nothing to do with being breached and everything to do with resilience and recoverability.</p><p>The central challenge is this: agentic AI is fundamentally different from previous generations of AI because it can act rather than simply advise. Agents can search files, call APIs, modify workflows, write code, move data, and interact directly with production systems; the list of capabilities is practically endless. And to be able to do this, they must have at least a level of access allowing their work to take place</p><p>When something goes wrong, the result is an expanded blast radius. A mistake that might once have affected a single application can potentially impact multiple systems and even recovery environments. The bottom line is that as soon as organizations give AI agents freedom to operate, the nature of resilience inevitably changes.</p><h2 id="making-resilience-more-resilient">Making resilience more resilient</h2><p>So, what needs to happen to ensure resilience standards do not catastrophically drop? Firstly, organizations must consider what takes place when a trusted system with legitimate credentials makes the wrong decision. </p><p>The issue becomes particularly acute when agents are granted broad permissions across multiple systems, as happens when they are handed a “golden token”. To an extent, this is a question of mindset, and viewing AI agents not as software tools but as digital insiders with delegated authority is a healthy change in perspective.</p><p>Secondly, channel partners will be fundamental to successfully managing the transition to agent-supported operations. Don’t forget, most customer organizations are still in the early stages of understanding how AI agents interact with identities, permissions, backup environments and recovery processes.</p><p>There’s no doubt that customers are a) increasingly aware of the risks associated with agentic AI, b) concerned that their existing resilience processes might not be good enough, and c) looking for guidance before an agentic error causes serious difficulties.</p><p>In this context, it’s incumbent on channel partners to work with customers to identify potential areas for improvement. There is significant potential, including services such as identity and access reviews, which will be very important as machine identities proliferate alongside human users.</p><p>Many businesses will also need to reassess their data protection strategy because, as we have seen, an AI agent with the appropriate permissions is capable of going after that data as well. Recovery architecture should be assessed through the lens of agentic AI, particularly where production and recovery environments may share credentials, access paths or administrative controls. Business process change in this space is a big opportunity for the channel to partner with customers to introduce resilience operations, and importantly, to regularly test it. </p><p>What’s more, the PocketOS incident demonstrated that protecting production data alone is insufficient if recovery assets remain exposed to the same destructive action. Customers need confidence not only that recovery is possible, but that digital assets are protected from the same event that affects production systems. This shifts the channel conversation from selling AI-enablement projects to helping customers deploy AI safely and recover when things go wrong, which, in some organizations, they inevitably will.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber professionals are flocking to AI tools, but they’re getting tired of fixing mistakes and reviewing outputs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-professionals-are-flocking-to-ai-tools-but-theyre-getting-tired-of-fixing-mistakes-and-reviewing-outputs</link>
                                                                            <description>
                            <![CDATA[ Cyber pros are spending significantly more time validating AI outputs and deciding when to trust AI-generated recommendations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HC5wmyEPCmrju9osQdeefF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AqvGjJr2CmPpQRrUk8S7z5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 16:15:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AqvGjJr2CmPpQRrUk8S7z5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Male and female cybersecurity specialists collaborating in an open plan office space, looking at screen during cyber attack recovery program.]]></media:description>                                                            <media:text><![CDATA[Male and female cybersecurity specialists collaborating in an open plan office space, looking at screen during cyber attack recovery program.]]></media:text>
                                <media:title type="plain"><![CDATA[Male and female cybersecurity specialists collaborating in an open plan office space, looking at screen during cyber attack recovery program.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AqvGjJr2CmPpQRrUk8S7z5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI isn't replacing cybersecurity roles but it is changing them, and not always for the better, according to new research. </p><p>A <a href="https://www.isc2.org/Insights/2026/07/rethinking-ai-impact-on-cybersecurity-roles" target="_blank">study from ISC2</a> found that 65% of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>professionals who use AI in their roles are spending time deciding when to trust or act on AI-generated recommendations. </p><p>Nearly two-thirds (63%) said they often find themselves reviewing and validating AI outputs. While this is basic best practice from a safety perspective, these processes are wasting valuable time. </p><p>Regardless, the influx of <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> within the profession has been welcomed by practitioners, according to the study. </p><p>More than half (53%) believe the technology is creating new entry-level opportunities, while 48% said AI makes them feel more optimistic about their long-term career prospects. </p><p>“AI is not replacing cybersecurity professionals; it is changing what the profession requires of them,” said ISC2 CEO Scott Beale.</p><p>“As AI takes on more repetitive tasks, as well as performing some complex cybersecurity analysis at speed and scale, cybersecurity roles are shifting toward higher-value work, from asking the right questions to validating findings, interpreting outputs and applying human judgment." </p><p>Beale noted that the use of AI is changing “how work is distributed across security teams”, meaning investment in areas such as governance, skills development, and validation practices is “essential”. </p><h2 id="too-much-time-fixing-problems">Too much time fixing problems</h2><p>While nearly half of cybersecurity professionals reported that AI has reduced workplace stress, 32% said it has made it worse. A key factor here lies in the aforementioned validation and reviewing practices, the study noted. </p><p>Those experiencing higher levels of stress were significantly more likely to spend longer periods deciding when to trust AI-generated outputs and recommendations. </p><p>When AI-recommended actions lead to incorrect outcomes – which nine out of ten said had happened – half of the participants said their organization holds human decision-makers ultimately accountable.</p><p>Put simply, poor AI-related outcomes have a direct impact on wellbeing for cybersecurity practitioners when it’s their neck on the line. </p><p>Confusion over accountability and ownership of AI also adds to stress, the study noted. Nearly a quarter (21%) of respondents said accountability of AI-related issues varies depending on the severity. </p><h2 id="over-reliance-is-a-worry">Over-reliance is a worry</h2><p>Other top concerns cited by ISC2 included over-reliance on AI, a recurring worry not just for cyber professionals but workers across a range of industries. </p><p>As <em>ITPro </em>reported in May, a study from GoTo warned over-reliance on the technology <a href="https://www.itpro.com/technology/artificial-intelligence/are-ai-tools-making-us-less-intelligent"><u>could erode key skills</u></a>. Similar concerns have been <a href="https://www.itpro.com/software/development/the-challenge-now-is-making-sure-the-next-generation-develops-those-same-foundations-before-relying-too-heavily-on-ai-devs-are-swerving-fundamental-skills-like-git-and-agile-because-of-ai-but-theres-a-good-reason"><u>highlighted in software development</u></a>, particularly among entry-level workers entering the workforce. </p><p>62% of respondents identified this as a key concern in the ISC2 study while 56% also highlighted worries about reduced human judgement capabilities when it comes to business-critical decisions. </p><p>Foundational <a href="https://www.itpro.com/security/cybersecurity-skills-what-can-be-done">cybersecurity skills</a> remain essential, according to ISC2, especially with AI in the mix. Notably, nearly two-thirds (62%) said they don't believe the technology  has reduced the need for these skills, compared with just 26% who say it has.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘We did not adapt and move quickly enough’: IBM CEO Arvind Krishna laments enterprise spending pivot as company issues profit warning ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/we-did-not-adapt-and-move-quickly-enough-ibm-ceo-arvind-krishna-laments-enterprise-spending-pivot-as-company-issues-profit-warning</link>
                                                                            <description>
                            <![CDATA[ The memory crisis has hit IBM hard as customers scramble to swerve price increases ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gAUTzgib2UG9R5ztyuzWDJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ankorMWTcLRABHngobkd2e-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 09:25:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ankorMWTcLRABHngobkd2e-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IBM CEO Arvind Krishna pictured in attendance at a Rose Garden Club event on the Rose Garden of the White House in Washington, DC, on July 6, 2026.]]></media:description>                                                            <media:text><![CDATA[IBM CEO Arvind Krishna pictured in attendance at a Rose Garden Club event on the Rose Garden of the White House in Washington, DC, on July 6, 2026.]]></media:text>
                                <media:title type="plain"><![CDATA[IBM CEO Arvind Krishna pictured in attendance at a Rose Garden Club event on the Rose Garden of the White House in Washington, DC, on July 6, 2026.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ankorMWTcLRABHngobkd2e-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IBM shares plummeted by more than 25% on Tuesday after the tech giant posted underwhelming preliminary second-quarter results. </p><p>In a <a href="https://newsroom.ibm.com/2026-07-14-Arvind-Krishnas-Letter-to-IBM-Investors" target="_blank">profit warning</a> released ahead of the company’s expected earnings call on 22 July, CEO Arvind Krishna attributed sluggish performance to the ongoing memory crisis and AI-related cybersecurity concerns. </p><p>Revenue for the quarter ending June came in at $17.2 Billion, marking just a 1% year-over-year increase and well below expectations. Notably, infrastructure revenue dipped by 7% across the quarter. </p><p>In a statement detailing the results, Krishna suggested the company had “faltered” and been taken unaware by rapidly changing enterprise spending habits. </p><p>Put simply, customers have shifted their focus away from software spending toward infrastructure investments ahead of expected price increases. </p><p><a href="https://www.itpro.com/infrastructure/ai-infrastructure-global-divide">AI infrastructure</a> build-outs have <a href="https://www.itpro.com/hardware/storage/we-want-to-be-able-to-share-the-pain-with-you-everpure-ceo-charlie-giancarlo-says-firm-will-share-the-burden-with-customers-amid-rising-hardware-costs">sent hardware prices skyrocketing</a> in recent months, with enterprises scrambling to secure servers, chips, and storage components. </p><p>“In the last few weeks of June, we saw clients shift their quarterly capex spend toward servers, storage, and memory purchases to secure supply-constrained infrastructure ahead of expected price increases,” he wrote. </p><p>“While we anticipated some supply chain-related impact in our expectations, we did not anticipate the magnitude of the capex reprioritization.”</p><p>Krishna’s warning spooked investors, sparking yet another sell-off in the software market. Shares at Microsoft, Salesforce, and ServiceNow all dipped in the wake of the announcement. </p><p>Software investors have been through the wringer so far in 2026, largely due to concerns about a looming ‘SaaSpocalypse’ due to recent advances in AI. </p><p>As <a href="https://www.itpro.com/technology/artificial-intelligence/why-anthropic-sent-software-stocks-into-freefall"><u><em>ITPro </em></u><u>reported in February</u></a>, Anthropic sparked a mass sell-off after the release of its Claude Cowork tool, with investors worried the solution could render some software services obsolete. </p><p>Chris Beauchamp, chief market analyst at IG, described the results as an “ugly moment for IBM and software stocks”.</p><p>“The big question will be how long the shift to infrastructure and cybersecurity lasts,” he said. “A few more months might be bearable, but more than that and serious questions will be asked all over again about software stocks.”</p><h2 id="ibm-falling-flat">IBM falling flat</h2><p>IBM’s infrastructure earnings are a clear sign of the ongoing rush and changing priorities for enterprise customers. </p><p>Krishna noted that many customers were scrambling to get ahead of further price increases, which impacted its higher-margin mainframe and associated software offerings. </p><p>In April, IBM <a href="https://newsroom.ibm.com/z17" target="_blank">unveiled its new z17 mainframe</a>, hailing it as the “first mainframe fully engineered for the AI age”. General availability for z17 landed in mid-June, and as <em>ITPro</em><a href="https://www.itpro.com/infrastructure/ibm-targets-data-center-efficiency-gains-with-new-z17-and-linuxone-offerings"><em> </em>recently reported,</a> the firm also plans to roll out compact versions in August. </p><p>While the z17 launch was met with much fanfare, Krishna noted results were “worse than our expectations”. </p><p>“These conditions require our teams to execute perfectly, and this quarter we faltered,” Krishna wrote. “We did not adapt and move quickly enough, and numerous large deals failed to close on the timelines we expected, driving the majority of our shortfall.”</p><p>“These are not excuses, but they are realities. Our job is to help our clients through uncertainty, to find paths forward to grow their businesses no matter what is happening in the external environment.”</p><h2 id="silver-linings-for-cybersecurity-vendors">Silver linings for cybersecurity vendors</h2><p>While hardware price issues dominated the enterprise focus, Krishna also noted clients were “distracted” by AI-related cybersecurity concerns in recent months. </p><p>The IBM chief said the launch of powerful new models such as <a href="https://www.itpro.com/technology/artificial-intelligence/project-glasswing-anthropic-announces-big-tech-consortium-to-test-claude-mythos-ai-model-that-could-reshape-cybersecurity">Anthropic’s Claude Mythos</a>, for example, has sparked widespread concerns among cybersecurity experts. </p><p>IBM has moved quickly to compensate for these changes, according to Krishna. The company recently launched a new security initiative, <a href="https://www.itpro.com/security/ibm-and-red-hat-believe-they-have-the-answer-to-open-source-security-risks">Project Lightwell</a>, aimed at driving AI-powered software security supply chain improvements. </p><p>As with hardware-related concerns, rapid changes in the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>landscape have also prompted a rethink on spending, Krishna told <a href="https://www.cnbc.com/2026/07/14/cybersecurity-stocks-ai-spending-mythos.html"><u><em>CNBC</em></u></a>. </p><p>“Mythos is making people pause to say, wait, how much do I need to spend on cyber? They’re pausing on new deals until they know,” Krishna commented. </p><p>These comments sparked a rally in cybersecurity stocks, with CrowdStrike, Zscaler, Palo Alto Networks, and Okta all recording significant boosts. </p><p>CrowdStrike, for example, surged 12% while Palo Alto Networks and Zscaler stocks rallied at around 7% respectively. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lidl data breach: Supermarket chain warns customers after third-party 'IT incident' exposes customer information – here's what we know so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/lidl-data-breach-supermarket-chain-warns-customers-after-third-party-it-incident-exposes-customer-information-heres-what-we-know-so-far</link>
                                                                            <description>
                            <![CDATA[ The incident, affecting an unnamed service provider, is the latest to affect embattled retailers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zyNrRndxDeXGefrowLPG33</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oK8UtcdgcFnnJiAaRdKyPJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 10:05:38 +0000</pubDate>                                                                                                                                <updated>Tue, 14 Jul 2026 12:12:54 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oK8UtcdgcFnnJiAaRdKyPJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of supermarket chain Lidl on a sign outside a branch in London, England.]]></media:description>                                                            <media:text><![CDATA[Logo of supermarket chain Lidl on a sign outside a branch in London, England.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of supermarket chain Lidl on a sign outside a branch in London, England.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oK8UtcdgcFnnJiAaRdKyPJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Supermarket chain Lidl has urged customers to remain vigilant after a data breach exposed personal information.</p><p>In an <a href="https://service.lidl.nl/html_mail.jsp?params=8LybHsuKa7Kn1nJNHJQVXNX0gmCmtqL%2BDv1%2FqBuU15CDljiqHnnM21YJF1q%2FnFUEywx3Rzgho98wZxcM9Vu14In%2BUF9apXtZuAjldylkmGg%3D" target="_blank"><u>advisory</u></a>, the firm revealed the ‘IT incident’ at a third-party service provider has impacted customers in Belgium, Germany, and the Netherlands. </p><p>"We were notified of this incident earlier this week," the message reads. </p><p>"Despite high IT security standards, unauthorized parties briefly gained access to a separately stored file containing customer data, and some of that data was stolen. The online shop system itself was not affected."</p><p>The stolen data relates to customers of Lidl's online shop, and includes first and last names, telephone numbers, email addresses, dates of birth, and customer numbers. </p><p>Lidl noted that data exposed in the incident does not include passwords, billing and delivery addresses, bank details, or other payment information. </p><h2 id="lidl-warns-customers-over-phishing-risks">Lidl warns customers over phishing risks</h2><p>The company said that while it currently has no concrete evidence this data has been misused, customers should remain vigilant for potential <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attacks or identity theft. </p><p>Customers should be wary of unexpected messages, always verify the authenticity of the sender, and avoid providing any information or clicking on unknown links. </p><p>Boris Cipot, principal security engineer at Black Duck, said the incident is a “textbook reminder” of the risks posed by third-party vendors. </p><p>"Even when a retailer's own systems hold, a compromised service provider can expose millions of customers to identity fraud, phishing, and account takeover attacks," Cipot commented. </p><p>"Personal data like names, birthdates, phone numbers, and email addresses may seem low-risk in isolation, but combined they become a powerful toolkit for social engineering. Additionally, the downstream costs to consumers and brand trust can far outlast the incident itself."</p><h2 id="lidl-vendor-acted-swiftly">Lidl vendor acted swiftly</h2><p>Lidl said its IT service provider responded immediately to fully restore the security of the affected IT systems, filed a report with the authorities and immediately engaged IT forensic experts to investigate the incident. </p><p>The company has also notified the relevant data protection authorities. Cipot commended the supermarket chain for its swift response and up-front communication with affected customers. </p><p>"Lidl deserves credit for moving quickly to notify customers and being transparent about what they don't yet know, including the possibility that passwords, addresses, and payment data could be involved. That kind of candor presents the appropriate posture under <a href="https://www.itpro.com/security/data-protection/gdpr">GDPR</a>," he said. </p><p>"The real test now is follow-through: how quickly they complete the forensic investigation, how clearly they communicate updates as the scope becomes known, and how rigorously they reassess the security requirements they place on their service providers going forward."</p><p>Lidl, which operates around 12,900 stores across 32 countries in Europe and the US, is just the latest retailer to be hit by a supply chain breach. </p><p>In the last year or so, victims have included <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-chair-calls-for-mandatory-reporting-of-cyber-attacks-after-traumatic-ransomware-incident-but-will-it-do-more-harm-than-good">Marks and Spencer</a>, Co-op, Louis Vuitton, Pandora, and <a href="https://www.itpro.com/security/cyber-attacks/harrods-cyber-attack">Harrods</a>. Many of these attacks have been linked to the <a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks">Scattered Spider</a> hacking group.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This one cyber crime group accounted for nearly a fifth of all ransomware attacks in June ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/this-one-cyber-crime-group-accounted-for-nearly-a-fifth-of-all-ransomware-attacks-in-june</link>
                                                                            <description>
                            <![CDATA[ The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5fMej8gjSEzxbkarjjYjYb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RSjE8LWxBzgjnadXPUW8mB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 11:41:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RSjE8LWxBzgjnadXPUW8mB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing a silhouetted person in a black hat with binary code in background. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing a silhouetted person in a black hat with binary code in background. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing a silhouetted person in a black hat with binary code in background. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RSjE8LWxBzgjnadXPUW8mB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Global cyber attacks rose over 10% in June, according to new <a href="https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/" target="_blank"><u>research from Check Point</u></a>, with one particular group accounting for a growing portion. </p><p>The uptick in attacks comes in the wake of what the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>firm described as a period of “relative calm” in May. </p><p>Attack volumes increase broadly across all regions and sectors at once, the company noted, suggesting attackers are expanding activities across a wider set of targets. </p><p>“June’s data shows a broad rebound in cyber activity, not a single isolated spike,” said Mark Mitchell, security engineer at Check Point Software. </p><p>“Attackers are widening their reach across regions and industries, while ransomware groups continue to reorganize and scale."</p><p>Notably, Check Point’s analysis highlighted increased activity by The Gentlemen, a new ransomware operator on the scene. The group overtook <a href="https://www.itpro.com/security/cyber-attacks/thousands-of-procedures-canceled-at-london-hospitals-as-qilin-releases-blood-test-data">Qilin </a>as the most active ransomware group globally, accounting for 17% of published attacks. </p><p><a href="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter">LockBit </a>activity also increased, rising from 1% of published attacks in May to 7% in June, making it the third most prevalent group.</p><p>"The rise of The Gentlemen to the top of the ransomware leaderboard is a clear reminder that new operators can rapidly become major global threats," Mitchell warned.</p><p>As <a href="https://www.itpro.com/security/new-ransomware-threat-group-the-gentlemen-has-become-one-of-the-most-active-ransomware-operators-accounting-for-10-percent-of-all-attacks"><u><em>ITPro </em></u><u>previously reported</u></a>, The Gentlemen have quickly grown to become one of the most aggressive ransomware groups worldwide. </p><p>Observations of the group’s activities by NTT revealed it uses advanced tooling and proxy infrastructure to accelerate attacks, often operating stealthily within compromised networks before causing havoc. </p><p>NTT researchers said the group also shows a level of technical maturity that would typically be associated with more established cyber crime groups. This could suggest it consists of highly experienced threat actors with deep ties to other groups within the cyber crime ecosystem. </p><h2 id="key-industries-in-the-crosshairs">Key industries in the crosshairs</h2><p>Education remained the most targeted sector globally, with organizations facing an average of 4,816 weekly attacks - 16% up on June 2025. </p><p>They're a comparatively easy target, said Check Point, thanks to open campus networks, constant device turnover, and constrained security resources.</p><p>Government was the second-most targeted sector, with 2,836 weekly attacks, up 5% year on year, while telecommunications ranked third with 2,835 weekly attacks, a 13% increase. </p><h2 id="latin-america-attacks-ramp-up">Latin America attacks ramp up</h2><p>Attacks against organizations in Latin America are ramping up significantly, according to Check Point. </p><p>Organizations across the region are now contending with an average of 3,501 weekly attacks, a 27% rise since June 2025. </p><p>APAC followed at 3,060 weekly attacks, up 5%, while Africa was third with 3,008 attacks per week, although this was down 9% year on year. </p><p>Europe and North America also saw sharp increases, at 22% and 14% respectively. </p><h2 id="ai-is-creating-new-risks">AI is creating new risks</h2><p><a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">Generative AI</a> continues to cause problems, with one in every 26  prompts submitted from enterprise networks carrying a high risk of sensitive data leakage, making for a global exposure rate of 3.9%. </p><p>High-risk prompt activity affected 85% of organizations that regularly use generative <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a>, while a further 27% of prompts contained potentially sensitive information. </p><p>This issue was most prevalent in Latin America, where 5.2% of prompts carried a high risk of sensitive data leakage, while Europe matched the global average at 3.9%. </p><p>In terms of broader AI-related risks, healthcare and medical carried the highest exposure at 5.7%, followed by telecommunications and business services at 5.1% each, and IT at 4.1%. </p><p>Personal data was accessed at 80% of affected organizations, with network and infrastructure details, legal and regulatory material, financial data, and employee records also widely exposed.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC issues warning over Russian intelligence-backed threat group ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-issues-warning-over-russian-intelligence-backed-threat-group</link>
                                                                            <description>
                            <![CDATA[ The advisory comes as the government cracks down on groups involved in “destructive cyber and hybrid operations” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ecBtbkHCFUTQLq8qjGpdG7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MT5985QZfigcxyG6ydBAiR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 11:25:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MT5985QZfigcxyG6ydBAiR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insignia of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a smartphone screen with blurred blue, green, and orange coloring in background.]]></media:description>                                                            <media:text><![CDATA[Insignia of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a smartphone screen with blurred blue, green, and orange coloring in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Insignia of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a smartphone screen with blurred blue, green, and orange coloring in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MT5985QZfigcxyG6ydBAiR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has urged UK organizations to remain vigilant for attacks waged by Russian state-backed hackers. </p><p>As part of an advisory published in collaboration with 18 other agencies, the cybersecurity center specifically highlighted techniques employed by Russian FSB’s Centre 16 threat actors. </p><p>The group has been “opportunistically” targeting vulnerable routers and critical national infrastructure globally in recent months, the advisory warns. </p><p>Centre 16 goes by a number of names, including Berserk Bear, Static Tundra, and Ghost Blizzard, according to the NCSC. The group primarily uses SNMP (Simple Network Management Protocol) scans to locate and compromise vulnerable routers. </p><p>The group has also been observed <a href="https://www.itpro.com/security/cyber-attacks/cisco-asa-customers-urged-to-take-immediate-action-as-ncsc-cisa-issue-critical-vulnerability-warnings">exploiting vulnerabilities in Cisco devices</a>, web portal flaws, and vulnerabilities in Cisco’s Smart Install (SMI) feature to seize network devices.</p><p>The advisory comes as the UK government implements sanctions against 24 individuals and entities behind “destructive cyber and hybrid operations” which have employed criminal groups via proxy networks. </p><p>Jonathon Ellison, NCSC Director of National Resilience, said these activities require organizations to remain in a heightened state of vigilance moving forward. </p><p>“The NCSC, alongside our international partners, have repeatedly exposed the advanced tools and coordinated campaigns of Russian cyber actors who persistently seek to exploit any vulnerability they encounter,” he said.</p><p>“Today’s joint advisory provides decisive, actionable directions from the global security community that network defenders should implement to protect against Russian Intelligence operations and secure the UK’s critical infrastructure.”</p><h2 id="russian-hackers-targeting-key-sectors">Russian hackers targeting key sectors</h2><p>Organizations across a host of sectors worldwide are at risk from the group, according to the advisory. </p><p>Those operating in the communications, energy, healthcare, defense, and financial services industries in particular are firmly in Centre 16’s crosshairs. </p><p>The security agency urged organizations in these domains to take action immediately. This includes disabling the use of legacy SNMP versions and switching to SNMPv3 to lower their risk of compromise.</p><p>Similarly, organizations are advised to implement “strong and unique passwords for network devices, and restrict access to management protocols”. </p><h2 id="call-to-action">Call to action</h2><p>In addition to basic defensive measures, the NCSC also encouraged at-risk organizations to obtain <a href="https://www.ncsc.gov.uk/cyberessentials/overview" target="_blank"><u>Cyber Essentials</u></a> certification. </p><p>This is a government-backed initiative for organisations to show they meet the recognized minimum standards for cybersecurity. </p><p>Organizations can also make use of the <a href="https://www.ncsc.gov.uk/collection/cyber-assessment-framework" target="_blank"><u>Cyber Assessment Framework</u></a>, allowing them to audit their security capabilities, operational maturity, and bolster cyber resilience techniques.</p><p>“I’d strongly encourage all organisations, especially those entrusted with UK critical networks, to adopt these recommended measures immediately, thereby reducing the risk of compromise,” Ellison commented. </p><h2 id="repeated-warnings">Repeated warnings</h2><p>This isn’t the first warning issued by the NCSC over Centre 26 activities in recent years. The security agency, alongside international counterparts, attributed the December 2025 attack on Poland’s energy grid to the unit. </p><p>Various subunits and techniques employed by Centre 16 have also been exposed over the last three years.  The security agency called out a Centre 16 unit known as ‘Turla’ in 2023 over the deployment of Snake malware, for example. </p><p>The <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>strain has been a key component of Russian-backed espionage campaigns for nearly two decades, the NCSC said at the time. </p><p>A similar advisory that year also shed light on a group known as Star Blizzard. The NCSC said this particular subunit of Centre 16 was actively interfering in UK politics and democratic processes. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious code ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-agents-you-use-to-beef-up-cybersecurity-could-be-turned-against-you-friendly-fire-attacks-can-manipulate-openai-and-anthropic-models-into-running-malicious-code</link>
                                                                            <description>
                            <![CDATA[ Research shows agents can be fooled into executing malicious code while performing security reviews of third-party software ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FRjVnVPEVarRpVdMovEzam</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 10:45:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:description>                                                            <media:text><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:text>
                                <media:title type="plain"><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A proof-of-concept by the AI Now Institute demonstrates remote code execution in Anthropic's Claude Code and OpenAI's Codex when they're running in an autonomous mode that approves their own commands.</p><p>The <a href="https://ainowinstitute.org/publications/friendly-fire-exploit-brief"><u>Friendly Fire attack</u></a> works against an out-of-the-box configuration of Claude Code in 'auto-mode' or Codex in 'auto-review', with researchers testing Claude Sonnet 4.6, Sonnet 5, and Opus 4.8 along with GPT-5.5.</p><p>It leverages prompt injections disseminated across a library’s source code that target AI-enabled cyber defense – without the need for hooks, skills, plugins, MCP servers, or configuration files as an injection vector.</p><p>Researchers noted the study highlights the potential risks associated with rapid adoption of AI-powered security tools. </p><p>Many organizations are doing so without “consideration of the substantial and unmitigated risks associated” with the technology. </p><p>AI-related cybersecurity concerns have been rising following the launch of powerful new models such as <a href="https://www.itpro.com/technology/artificial-intelligence/project-glasswing-anthropic-announces-big-tech-consortium-to-test-claude-mythos-ai-model-that-could-reshape-cybersecurity">Claude Mythos</a>. Anthropic rolled the model out as part of a gated release to prevent misuse, and US authorities <a href="https://www.itpro.com/technology/artificial-intelligence/why-the-us-imposed-export-controls-on-anthropics-fable-and-mythos-models-and-why-theyve-been-lifted">temporarily imposed export controls</a> amidst similar concerns. </p><h2 id="how-the-friendly-fire-attack-works">How the Friendly Fire attack works</h2><p>The attack works by inserting prompt injections into documentation files and adding README files that appear to be part of routine security tooling in an open source library. </p><p>Researchers used geopy, a popular Python used for searching for geographic coordinates, but said it could work with almost any project. </p><p>When a user asks Claude Code or Codex to perform a security assessment of the repository using the default auto-mode or auto-review automated modes, the agent can be persuaded to execute a malicious binary without any warning and without requesting any further user approval. </p><p>The proof of concept is causing alarm amongst security professionals. Roey Eliyahu, CEO and co-founder of Salt Security, said this marks the latest in a string of potential risks in recent months due to manipulation of agents. </p><p>“Friendly Fire, GitLost, Agentjacking, TrustFall. Four documented attacks in the past two months, different techniques, same underlying condition,” he said.  </p><p>“Untrusted text reaches an agent that can run commands. The agent cannot reliably tell the difference between the code it is reviewing and the instructions it is being given. And the attacker's payload executes on the host.”</p><p>Eliyahu emphasized that this is not a “model problem that can be patched”. All four models were vulnerable to the same techniques and payload, without any modifications for each. </p><p>“When the same attack works unchanged across two vendors and four model generations, you are not looking at a software bug. You are looking at a structural property of how these agents work."</p><p>But, said Eljan Mahammadli, head of AI provenance at Polygraf AI, this shouldn't rule out the use of AI for defensive security work.</p><p><em>ITPro </em>approached Anthropic and OpenAI for comment, but did not receive a response by time of publication. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clients ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/working-with-the-enemy-ransomware-negotiator-turned-cyber-criminal-jailed-after-working-with-hackers-to-extort-clients</link>
                                                                            <description>
                            <![CDATA[ Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rEKtR8rJ65bFgXThPcm6mh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 09:46:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:description>                                                            <media:text><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:text>
                                <media:title type="plain"><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>negotiator has been sentenced to 70 months in prison after secretly conspiring with hackers to extort clients. </p><p>Angelo Martino, 41, of Land O’Lakes, Florida, worked at US-based cyber incident response company DigitalMint in April 2023 when he started conspiring with the operators of the BlackCat ransomware group. </p><p>BlackCat paid Martino to provide confidential information about the negotiating position and strategy of his employer’s clients, along with the details of their ransomware insurance, to help maximize the ransoms paid. </p><p>Notably, Martino also <a href="https://www.itpro.com/business/when-cyber-professionals-go-rogue-a-former-ransomware-negotiator-has-been-charged-amid-claims-they-attacked-and-extorted-businesses">conspired with two former cybersecurity professionals</a> between April 2023 and November 2023.</p><p>Kevin Martin, 36, of Texas, was hired as Martino’s co-worker at DigitalMint after the conspiracy began. Ryan Goldberg, 41, of Georgia, was manager of incident response at Sygnia. </p><p>All told, Martino was found to have extorted five different victims as part of his collaboration with the cyber crime syndicate while the trio also worked to deploy BlackCat ransomware against victims across the country. </p><p>Assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division, said victims had shared “heartbreaking accounts of how their businesses were nearly destroyed” during the trail. </p><p>“Today’s sentence accounts for the harm Martino caused and demonstrates that the Department of Justice can and will identify and prosecute cybercriminals to the fullest extent of the law.”</p><h2 id="working-with-the-enemy">Working with the enemy</h2><p>After successfully extorting one victim for around $1.2 million in Bitcoin, the men split their share of the ransom three ways and laundered the funds through various means. </p><p>Jason A. Reding Quiñones, attorney for the Southern District of Florida, said more than $10 million in criminal proceeds have been seized. These assets include digital currency, vehicles, a food truck, and a luxury fishing boat. </p><p>A separate hearing has been set for September 17 to decide the amount of restitution to be ordered against Martino. </p><p>The Justice Department started <a href="https://www.itpro.com/security/ransomware/alphv-leak-site-seized-by-law-enforcement-as-decryption-tool-released"><u>working to bring down BlackCat</u></a> three years ago, developing a decryption tool that allowed FBI field offices across the US and law enforcement partners around the world to help victims restore their systems. </p><p>The scheme has reportedly saved victims from paying out $99 million in ransom payments so far. The FBI also seized several BlackCat websites at the same time.</p><p>"This case sends a clear message: we will pursue the hackers who deploy ransomware, the insiders who enable them, and the money they steal from American victims,” Quiñones said. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Flaws in some of the most popular AI coding tools left developers wide open to attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/flaws-in-some-of-the-most-popular-ai-coding-tools-left-developers-wide-open-to-attack</link>
                                                                            <description>
                            <![CDATA[ Malicious repositories can trick advanced AI agents into silently breaking out of their workspace sandboxes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Gawo6Gk4RNHQavhhSVvjPd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jul 2026 10:06:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:description>                                                            <media:text><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A 'category-level' security flaw in six leading AI coding assistants could give attackers remote control of a developer’s machine, according to researchers at <a href="https://www.itpro.com/business/business-strategy/google-confirms-wiz-acquisition-in-record-breaking-usd32-billion-deal">Wiz</a>. </p><p>Dubbed <a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank"><u>GhostApproval</u></a>, the flaw affects some of the most popular coding tools on the market right now, including Amazon Q Developer, Claude Code, Cursor, Windsurf, and Google Antigravity. </p><p>The flaw has been reported to all six providers, with Amazon, Cursor, and Google having rated it critical or high-severity and fixed it, and there's no evidence that it's been exploited in the wild.</p><p>According to Wiz, the vulnerability is caused by a decades-old Unix primitive – symbolic links, or symlinks – which allows malicious repositories to trick AI agents into silently breaking out of their workspace sandboxes, leading to RCE and persistent access to a developer's machine.</p><p>In the case of Amazon Q Developer, the agent wrote to the filesystem before presenting the user with an Undo option. Testing by Wiz found the agent correctly identified the symlink in its internal reasoning, but proceeded with the write anyway. </p><p>Amazon has fixed the problem, which has been recorded as <a href="https://github.com/aws/language-servers/security/advisories/GHSA-6v3r-4p5c-mrp5" target="_blank"><u>CVE-2026-12958</u></a>.</p><p>"We have remediated this issue in language server version 1.69.0. The AWS Language Server updates automatically unless the customer's network configuration prevents it, so no action is required in most cases," the firm said in a statement. </p><p>"For existing customers, reloading the IDE will trigger an update to the latest language server version, which includes this fix. If auto-update is blocked, we recommend upgrading to the latest version of the Amazon Q Developer plugin for your IDE."</p><p>Wiz noted that new customers don't need to take any action, as the latest patched version will be downloaded automatically. </p><h2 id="anthropic-issues-customer-warning">Anthropic issues customer warning</h2><p>Claude Code, meanwhile, provides the clearest example of user interface misrepresentation of critical information, Wiz said.</p><p>"The agent explicitly recognized the dangerous target in its thinking - stating "this is a symbolic link to the Claude settings file" - then presented a prompt asking simply: "Make this edit to project settings.json?" the researchers said.</p><p>Anthropic, however, has rejected the threat on the basis that the user explicitly trusted the directory when starting the session and explicitly approved the file operation in the confirmation prompt. </p><p>Around the time Wiz revealed its findings, the company added a warning to users, and current versions (2.1.173+) now resolve symlinks. </p><p>Cursor's diff UI showed the symlink path; when the user clicked Accept, the backend followed the symlink and wrote to the resolved target. It's been fixed in version 3.0, and Cursor has issued <a href="https://github.com/cursor/cursor/security/advisories/GHSA-3v8f-48vw-3mjx" target="_blank"><u>CVE-2026-50549</u></a>.</p><p>Google's Antigravity, meanwhile, displayed the symlink path in its permission dialog rather than the resolved canonical path. Wiz researchers were able to successfully write an attacker's SSH key via a symlink disguised as project_settings.json. Google's fixed the problem.</p><h2 id="windsurf-flaw-raises-serious-concerns">Windsurf flaw raises serious concerns</h2><p>Notably, Wiz said Windsurf presented a particularly dangerous variant during testing of the vulnerability. </p><p>"The agent writes file modifications directly to disk before the Accept/Reject buttons appear in the UI. The confirmation dialog isn't an authorization gate - it's an undo mechanism," the researchers warned.</p><p>Wiz added that the system is compromised “the moment the agent processes the malicious instructions”. Indeed, by the time users even see the prompt asking to accept changes, an attacker’s SSH was already placed in the authorizedkeys file.</p><p>Researchers warned that the findings show that “trust boundary questions” will become critical for organizations rolling out AI agents en-masse.</p><p>"GhostApproval is a symptom of a broader challenge: building AI systems that are both powerful and trustworthy. Getting the human-in-the-loop right – truly right, not just formally present – is essential to that goal."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NCSC wants to build an AI-powered 'Cyber Shield' to protect the UK from hackers – here’s how it’ll work ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-ncsc-wants-to-build-an-ai-powered-cyber-shield-to-protect-the-uk-from-hackers-heres-how-itll-work</link>
                                                                            <description>
                            <![CDATA[ The aim is to create a national, sovereign defence capability to protect government agencies and critical infrastructure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KUBzFPYJgBqkELPwd2JU7e</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jul 2026 15:09:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:description>                                                            <media:text><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has laid out its plans for the national Cyber Shield, first announced in May this year. </p><p>The aim of the project is to build a nationwide, collaborative approach to agentic cyber defense, using frontier AI to identify, reduce, and deal with national cyber risks.</p><p>According to the NCSC, the move comes amidst concerns that cybersecurity risks are growing in “scale, speed, and sophistication” - particularly from hostile states and organized crime groups targeting public services. </p><p>"Frontier AI is accelerating this trend, with the potential to shift the balance in favour of attackers – and with serious implications for defenders,” the NCSC said. </p><p>“We need to keep our critical technology systems secure against both existing and emergent cyber threats."</p><p>As part of the project, AI systems will initially <a href="https://www.itpro.com/security/why-patching-velocity-matters-as-claude-mythos-supercharges-vulnerability-discovery">identify vulnerabilities and threats at machine speed</a>, before moving on to automated remediation. </p><p>Further down the line, the agency expects AI to eventually generate and share insights, detect and contain breaches, and work under the control of their owners across government and non-government bodies.</p><p>These agents, the NCSC noted, will need to be built on strong foundations of data, identity, reliability, cybersecurity, and regulatory compliance.</p><p>The NCSC will first partner with network defenders across government and critical UK sectors to test and deploy new capabilities, with the plan to then transition to commercially-scalable solutions to improve national resilience.</p><h2 id="ncsc-targets-reliability-in-cyber-shield-scheme">NCSC targets reliability in Cyber Shield scheme</h2><p>To make all this happen, there's a fair amount that will need to be done – some of which will present big challenges. </p><p>The NCSC highlighted the need for reliable and explainable <a href="https://www.itpro.com/security/safe-ai-adoption-rests-on-cybersecurity-professionals-says-rsac-chairman">AI for cybersecurity</a> that can be used confidently in production environments at scale, and authorized by system owners to make safe, reliable, and significant real-time changes in support of cyber defence.</p><p>Agents will run national-level operations under the control and authority of individual organizations, and have the ability to identify, trust, and communicate between themselves.</p><p>Elsewhere, national-level scanning will involve the automated monitoring of critical UK IP ranges for exposed vulnerabilities, as well as analysis of aggregated data to understand national level exposure. </p><p>The agency noted that workflows will need to be automated to allow rapid national-scale mitigation, such as the automated blocking of known malicious domains and networks.</p><h2 id="a-big-bold-plan">A big, bold plan</h2><p>Plans detailed by the NCSC have been welcomed by industry stakeholders as a positive step in protecting the UK against rising threats. Whether or not this is an achievable goal is up for debate, according to Pete Luban, field <a href="https://www.itpro.com/business/business-strategy/why-the-ciso-role-is-so-demanding-and-how-leaders-can-help">CISO </a>at AttackIQ. </p><p>"The biggest challenge will be getting government, critical infrastructure, and private industry to share intelligence in a way that is trusted and actionable," Luban commented. </p><p>"If bought into, Cyber Shield could give the UK a stronger foundation to spot risk earlier, validate defenses faster, and respond before attackers gain momentum.”</p><p>Kevin Marriott, senior director of cyber content strategy & IP at Immersive, said the true test will be in how the government makes sure the system is utilized where it can bring value and return on investment.</p><p>"It would also be beneficial to hear how they plan to deal with the output from the frontier models, and whether they put robust practices in place which enable them to deal with the outputs," he said.</p><p>"If this is part of a well-considered strategy, it represents a significant step forward. If, however, it is a move towards ungoverned AI without clear oversight or a defined plan for where and how it should be used, then it is not.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multi-channel phishing attacks: How to manage the risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/multi-channel-phishing-attacks-how-to-manage-the-risk</link>
                                                                            <description>
                            <![CDATA[ Attackers are evolving beyond email towards phishing across multiple channels. Why is this, and what can be done to manage the risk? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SesFueAF7AB4ZgF8y8JrvA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Vwb8TLBgSxGdDgEKAcxuKZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Vwb8TLBgSxGdDgEKAcxuKZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cartoon graphic depicting phishing as a service, shown as bugs, keys, fingerprints, bitcoins, shields, eyes, etc surrounding a fish hook. All are placed on a light grey background.]]></media:description>                                                            <media:text><![CDATA[A cartoon graphic depicting phishing as a service, shown as bugs, keys, fingerprints, bitcoins, shields, eyes, etc surrounding a fish hook. All are placed on a light grey background.]]></media:text>
                                <media:title type="plain"><![CDATA[A cartoon graphic depicting phishing as a service, shown as bugs, keys, fingerprints, bitcoins, shields, eyes, etc surrounding a fish hook. All are placed on a light grey background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Vwb8TLBgSxGdDgEKAcxuKZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Email <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> has always been a simple yet effective form of attack. While the method isn’t going away, research is showing attackers evolving beyond email to multiple channels such as Slack and cloud-based platforms. </p><p>That’s according to security firm KnowBe4’s Phishing Threat Trends report, which <a href="https://www.itpro.com/security/phishing/the-inbox-is-no-longer-the-only-frontline-phishing-attacks-are-evolving-as-cyber-criminals-ramp-up-multi-channel-campaigns-over-email-and-microsoft-teams"><u>found</u></a> hackers are leveraging new “touchpoints” when targeting victims, with calendar invites and messaging tools a frequent tactic. The company recorded a 41% increase in Microsoft Teams-based attacks between October 2025 and March 2026 as adversaries strived to create more avenues for success.</p><p>With <a href="https://www.itpro.com/uk/technology/artificial-intelligence"><u>AI</u></a> offering cybercriminals the ability to supercharge phishing attacks further, what should businesses be doing to manage the risk?</p><h2 id="phishing-evolution">Phishing evolution</h2><p>In the past, phishing attacks relied on adversaries targeting a wide range of users in the hope that some of them would engage with malicious content, or give away valuable information.<strong> </strong>But since then, businesses have improved their security, with tools such as <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>multi-factor authentication</u></a> (MFA) used as standard. This has forced attackers to utilize more sophisticated techniques. </p><p>“When attackers cannot compromise technical controls, such as MFA, they are instead seeking to bypass the technology and move the attack onto end users through social engineering,” says Luiz Simpson, head of offensive security at Bridewell.</p><p>He cites the example of <a href="https://learn.microsoft.com/en-us/defender-office-365/detect-and-remediate-illicit-consent-grants"><u>illicit consent grant</u></a> attacks in Microsoft 365, which trick users into granting access to data. These attacks often “go completely under the radar”, says Simpson. “Users will accept an untrustworthy app while logged into their cloud workspace and under the legitimate Microsoft or Google workspace platforms. These attacks don’t require any bypass of MFA and almost always aren’t flagged by detection and response.”</p><p>Another reason attackers are targeting multiple channels is the fact that the workplace itself has changed.  “Employees now spend far more time in collaboration platforms, cloud applications, messaging tools, and video conferencing environments,” says Ray Canzanese, director of Netskope Threat Labs. “Attackers are following that behavior.”</p><p>Canzanese describes how phishing lures are increasingly delivered through platforms such as Microsoft Teams, Zoom and fake meeting invitations. “These are designed to exploit the trust users place in familiar collaboration workflows.”</p><p>From a criminal perspective, multi-channel phishing is becoming “progressively structured”, according to Benson Varghese, a criminal lawyer and founder and managing partner at law firm Varghese Summerset. Rather than flooding potential victims with random messages, phishers will prepare their sequence, test the response rate, and react to engagement in real-time, he says. “This makes attacks more focused and effective.”</p><h2 id="security-shift">Security shift </h2><p>Experts believe the evolution of phishing requires businesses to change the way they think about securing communication channels.</p><p>The shift means no longer treating phishing as purely an email security problem. “Security teams need visibility across a much broader digital environment that includes collaboration tools, cloud platforms, browsers, unmanaged devices and AI applications,” according to Canzanese. </p><p>Almost all social media platforms include user messaging, which supports the distribution of links and images. Yet historically, the focus on preventing <a href="https://www.itpro.com/security/a-new-silent-social-engineering-attack-is-being-used-by-hackers-and-your-security-systems-might-not-notice-until-its-too-late"><u>social engineering attacks</u></a> has been around traditional email-based messages, encouraging users to avoid clicking links. “None of these defences will help prevent attackers from contacting end users and sending malicious content across other channels,” says Simpson.  </p><p>“As these interactions do not arrive via traditional email, there is no URL rewriting, sandboxing or inspections of content,” he points out. “This leaves you with just endpoint and identity-based controls to protect users.”</p><p>However, endpoint detection and response (EDR) solutions traditionally fall short in having visibility of what goes on within a browser, Simpon explains. “If a user is to bring<a href="https://www.itpro.com/security/the-new-byod-how-to-leaders-can-securely-evolve-policy"><u> your own device (BYOD)</u></a> with access to enterprise resources, you are very much on the back foot to prevent identity-based attacks.”</p><h2 id="managing-multi-channel-phishing">Managing multi-channel phishing </h2><p>The move to multiple channels is just one way phishing is changing. In tandem, AI is accelerating the quality and scale of attacks, while lowering the barrier to entry for new cybercriminals, according to Danny Jenkins, CEO of ThreatLocker.</p><p>“Attackers no longer need to spend hours researching targets or carefully crafting convincing messages,” he tells <em>ITPro</em>. </p><p>“AI can generate highly personalised, context-aware phishing content in seconds – whether that’s a Teams message, a fake document-sharing notification, or a voice <a href="https://www.itpro.com/security/deepfake-business-risks-are-growing-what-leaders-need-to-know"><u>deepfake</u></a> impersonating a colleague or executive.”</p><p>There is also a rise in adaptive social engineering, where AI-driven phishing attempts evolve in real time based on how a user responds, he warns. “Instead of relying on static messages, these interactions can mimic natural conversations, making them significantly more convincing,” explains Jenkins.</p><p>The threat from multi-channel phishing is certainly growing, but firms can help boost defenses by making several key changes. Some of these are cultural. </p><p>From a security perspective, organizations need to accept that they will not stop every phishing attempt across every channel, says Jenkins. </p><p>“Humans are imperfect, and mistakes will happen, and no amount of training can prevent every phishing attempt.” </p><p>Instead, the priority should be reducing the impact of an attack and tightly controlling access, rather than trying to eliminate exposure, he advises.</p><p><a href="https://www.itpro.com/security/password-manager-passkey-guidance-ncsc"><u>Passkey</u></a> use can help, says Simpson, pointing out that the <a href="https://www.ncsc.gov.uk/"><u>UK National Cyber Security Centre (NCSC)</u></a> has started to actively recommend the adoption of passkeys over passwords and MFA.</p><p>“Passkeys help address many of the shortfalls of traditional passwords and MFA. Notably, they’re resistant to phishing because they’re tied to the legitimate website only; they are fast and convenient, and cannot be stolen if a website is breached.”</p><p>As with traditional phishing, organizations should adopt a strategy of user awareness and technical controls to defend against multi-channel attacks, according to Simpson.</p><p>This means ensuring users are aware that a spectrum of social engineering attacks are possible, beyond solely email-based phishing. Users, especially those in high-risk roles, such as executives and finance teams, should be targeted with training to empower them to identify and report attacks, Simpson advises. </p><p>“This should be an ongoing message and constantly refreshed based on active attacks seen in the wild, rather than just an annual policy that’s read and signed off.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'It’s a marker of where extortion tradecraft is heading': Cyber experts say they've identified the first case of ‘agentic ransomware’ – but there’s a catch ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/its-a-marker-of-where-extortion-tradecraft-is-heading-cyber-experts-say-theyve-identified-the-first-case-of-agentic-ransomware-but-theres-a-catch</link>
                                                                            <description>
                            <![CDATA[ While the JadePuffer ransomware has alarm bells ringing, it still needed a human in the loop ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qjk8F3ajnLx38ikEJu7GF9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Bu6X6qBMaKYkswFayN2KhG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jul 2026 13:40:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Bu6X6qBMaKYkswFayN2KhG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI concept image showing humanoid face illuminated in red against a glowing red and black background.]]></media:description>                                                            <media:text><![CDATA[AI concept image showing humanoid face illuminated in red against a glowing red and black background.]]></media:text>
                                <media:title type="plain"><![CDATA[AI concept image showing humanoid face illuminated in red against a glowing red and black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Bu6X6qBMaKYkswFayN2KhG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A security firm has spotted what it claims is the first documented case of a ransomware operation run entirely by a large language model. </p><p>The Sysdig Threat Research Team said the operator, dubbed JadePuffer, is the first agentic threat actor, describing it as using a known <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3248" target="_blank"><u>flaw in AI app builder Langflow</u></a> to gain access to credentials and other key data. </p><p>Thereafter, researchers noted it took over a production database and encrypted it for extortion purposes. </p><p>"JadePuffer is a warning sign," Michael Clark, Sysdig’s director of threat research, said in a <a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" target="_blank"><u>blog post</u></a>. </p><p>"It’s a marker of where extortion tradecraft is heading. An autonomous agent reasoned about its targets, harvested and reused credentials, moved laterally, established persistence, and destroyed a database, narrating its own intent the entire way."</p><p>Clark has <a href="https://techcrunch.com/2026/07/06/the-first-ai-run-ransomware-attack-still-needed-a-human/" target="_blank"><u>clarified</u></a> that though the attack operation was run by an AI, the attack was still organized by a human who set up the infrastructure, found the initial credentials to break in, and chose a victim. But the rest of the attack was managed by the LLM itself.</p><h2 id="alarming-attack">Alarming attack</h2><p>Clark noted that JadePuffer's payloads were "self narrating", containing detailed notes that a human wouldn't bother to write but an <a href="https://www.itpro.com/security/cyber-crime/what-is-hackbot-as-a-service-and-are-malicious-llms-a-risk">LLM </a>generates innately about why each step was taken, including prioritization of targets. That narration data could prove useful for security teams looking to defend against such attacks, Clark added. </p><p>"The operation also adapted in real time, retrying failed steps within refined parameters," Clark added. "In one sequence, it went from a failed login to a working fix in 31 seconds."</p><p>That is perhaps the most alarming aspect of the incident, according to Roey Eliyahu, CEO and co-founder of Salt Security.</p><p>"A human attacker who fails an initial payload waits, reassesses, consults, and tries again on a different timeline," Eliyahu said. "An agent that fails a payload corrects and retries in under a minute. That compression of the attack cycle means the window between first detection signal and material damage is now measured in seconds, not hours."</p><p>The JadePuffer system even wrote a ransom note complete with Bitcoin address and Proton email contact, Clark noted, though the former appears to be a wallet address frequently used as an example in explainer text online. </p><p>That’s either a coincidence, said Clark, or a <a href="https://www.itpro.com/technology/artificial-intelligence/ai-hallucinations-what-are-they">hallucination by the LLM</a> due to the frequency of that address online, and therefore used in training data. </p><p>Clark also noted that the encryption key was generated and essentially random, so the victim would not be able to decrypt — even if they paid the ransom. The victim organization wasn't disclosed. </p><h2 id="warning-about-the-future-of-security">Warning about the future of security</h2><p>While JadePuffer is just one incident, it shows that AI can help automate old vulnerabilities and that ransomware no longer requires skills to pull off an attack, according to Sally Vincent, senior threat research engineer at Exabeam.</p><p>"While the attack relied on known, older vulnerabilities rather than new exploits, it demonstrates how AI can automate and accelerate the exploitation of unpatched systems," Vincent said. "It also serves as a reminder that patching known vulnerabilities remains important, since AI can make exploiting them faster and more efficient."</p><p>While Clark stressed that none of the attack techniques were novel or sophisticated, JadePuffer is interesting because it was strung together into a complete ransomware operation by an AI model. </p><p>"The skill floor for running ransomware has dropped to whatever it costs to run an agent, and if that agent is running on stolen credentials through LLMjacking, the cost to an attacker is close to zero," he commented. </p><p>That means security professionals should expect to see more like this, as well as a higher volume of attacks, and should proactively protect "exposed application servers, unhardened configuration stores, and internet-facing database admin accounts," Clark added. </p><p>Salt Security's Eliyahu added: "The question every security team should be asking after this report is: what is holding credentials in our AI-adjacent infrastructure, and what can those credentials reach?" </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK’s Cyber Resilience Pledge gathers momentum as 60 firms sign up to bolster capabilities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/uks-cyber-resilience-pledge-gathers-momentum-as-60-firms-sign-up-to-bolster-capabilities</link>
                                                                            <description>
                            <![CDATA[ The voluntary pledge sees organizations tightening up their defences, particularly against supply-chain attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">85jHtazzwahdKRi23Ynkk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X8Y8QhNNiBqk9AccuYbNHH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jul 2026 09:41:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X8Y8QhNNiBqk9AccuYbNHH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[UK tech map with Great Britain and Northern Ireland pictured on a screen.]]></media:description>                                                            <media:text><![CDATA[UK tech map with Great Britain and Northern Ireland pictured on a screen.]]></media:text>
                                <media:title type="plain"><![CDATA[UK tech map with Great Britain and Northern Ireland pictured on a screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X8Y8QhNNiBqk9AccuYbNHH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government said more than 60 businesses have signed up for its Cyber Resilience Pledge so far, including <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack">M&S</a>, Nationwide, ITV, Microsoft UK, and Cloudflare.</p><p><a href="https://www.itpro.com/security/uk-government-calls-on-firms-to-sign-cyber-resilience-pledge-as-security-sector-booms"><u>Announced in May</u></a>, the voluntary scheme sees businesses committing to three concrete actions to improve <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>capabilities.</p><p>They must commit to making cyber security a board-level responsibility, by implementing the Cyber Governance Code of Practice and ensuring all board members complete the NCSC’s Cyber Governance Training.</p><p>They must also register for the NCSC’s free Early Warning service, a tool that alerts organizations to potentially suspicious activity on their networks, and commit to taking a risk-based approach to requiring the government-backed Cyber Essentials certification across their supply chain. </p><p>The pledge has been designed primarily for medium and large organizations, with other signatories including Deloitte, Accenture UK, Vodafone Group, and VodafoneThree, but is open to businesses of all sizes and from all sectors.</p><p>"Today, some of Britain’s biggest businesses are taking action to strengthen their cyber defences and setting a powerful example for others to follow. By signing this pledge, they are showing that cyber resilience is no longer just an IT issue - it is a business imperative," said technology secretary Liz Kendall.</p><p>"The steps in this pledge are practical, achievable and proven to make a difference. Today’s signatories are leading the way, and I encourage organizations across the UK to follow their example."</p><h2 id="cyber-charter-to-beef-up-critical-services">Cyber Charter to beef up critical services</h2><p>Alongside the pledge, the government has been developing a Cyber Charter for 39 companies designated as strategic suppliers for delivering critical services to the government. </p><p>These organizations have been invited to sign the pledge as an initial commitment to bolstering their cyber resilience, although so far only a little more than half have done so.</p><p>"We have long held the view that cyber resilience is a critical business and organizational enabler. It underpins our growth, our economic security, and the safety and security of our people," said Julian David, CEO of techUK. </p><p>"With the average cost of significant cyber-attacks to the UK economy recently estimated to be £14.7 billion annually – the equivalent of 0.5% of our GDP – it’s clear that cyber security and resilience must be recognised as a leadership responsibility and should no longer be viewed as an IT issue alone."</p><h2 id="pledge-targets-national-resilience">Pledge targets national resilience</h2><p>Moves to bolster national resilience capabilities come amidst an increase in malicious cyber activity in the UK. </p><p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> recently confirmed it handled 204 nationally significant incidents in the year to September, up from 89 the year before. </p><p>The average cost of an attack on an individual UK business now stands at almost £195,000, with the annual cost to organizations estimated at £14.7 billion - and that’s in addition to the costs of wider economic disruption. </p><p>Last year, experts estimated that the attack on <a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre"><u>Jaguar Land Rover (JLR) cost the UK economy roughly £1.9 billion</u></a>, making it the most costly cyber incident in British history. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘The risk to every organization has increased exponentially’: The FortiBleed campaign just took a turn for the worse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-risk-to-every-organization-has-increased-exponentially-the-fortibleed-campaign-just-took-a-turn-for-the-worse</link>
                                                                            <description>
                            <![CDATA[ Reports suggest that FortiBleed-linked exposed credentials could put UK government and public services at huge risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">npiBchLKa4eriPG8MdEo5T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bR33DDYEFNw8FhDqg6p8y5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jul 2026 08:09:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bR33DDYEFNw8FhDqg6p8y5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Plaque pictured at the Foreign, Commonwealth and Development Office building in Whitehall, London. ]]></media:description>                                                            <media:text><![CDATA[Plaque pictured at the Foreign, Commonwealth and Development Office building in Whitehall, London. ]]></media:text>
                                <media:title type="plain"><![CDATA[Plaque pictured at the Foreign, Commonwealth and Development Office building in Whitehall, London. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bR33DDYEFNw8FhDqg6p8y5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>experts have issued an alert amid reports that hackers accessed login credentials belonging to UK government officials and Foreign Office staff. </p><p>The credentials, which are reportedly being sold on the dark web, were exposed as part of the ongoing FortiBleed attack campaign. </p><p>FortiBleed targets internet-facing Fortinet <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022">VPN </a>and <a href="https://www.itpro.com/security/firewalls">firewalls</a>, and is believed to have affected more than 70,000 devices spanning 194 countries since it was first uncovered last month. </p><p><a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/" target="_blank"><u>Analysis from SOCRadar</u></a>, for example, identified a vast database containing login credentials. The threat intelligence firm has since attributed FortiBleed to the Lynx/<a href="https://www.itpro.com/security/ransomware/ransomware-group-publishes-stolen-nhs-scotland-data-to-dark-web">INC ransomware</a> group.</p><p>While this database was believed to have been limited to basic usernames and passwords, reports from <a href="https://www.telegraph.co.uk/news/2026/07/05/russian-hackers-steal-government-logins/" target="_blank"><u><em>The Telegraph</em></u></a><em> </em>suggest some exposed details include privileged Fortinet credentials. </p><p>Volodymyr Diachenko, a security researcher who first uncovered the threat campaign, told the publication these credentials could give bad actors access to the Foreign Office’s “core networks” along with other government departments.</p><p>Some Foreign Office credentials are now being sold on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>, according to reports, going for up to £40,000. </p><p>Arctic Wolf CISO Adam Marrè warned that the incident could create a domino effect, impacting other government departments and also local authorities and public services. </p><p>According to <em>The Telegraph</em>, credentials at NHS trusts, energy companies, and local councils were also hosted in the illicit database. </p><p>“This major breach of email accounts of UK government officials and overseas Foreign Office workers is the latest development in the ongoing FortiBleed attack,” he said. </p><p>“While it may be tempting to think this is a simple <a href="https://www.itpro.com/security/theres-only-one-way-to-avoid-credential-stuffing-attacks">credential-stuffing</a> operation, our threat team found the threat actors have built a highly sophisticated and repeatable credential factory,” he said. </p><p>Marrè noted that analysis of the incident conducted by Arctic Wolf shows threat actors appear to have been using automated tools to harvest logins and target gateways at “exponential speed and volume”. </p><p>“This means while today it’s the Foreign Office which has been affected, the risk to every organization has increased exponentially.”</p><h2 id="back-and-forth-on-fortibleed">Back and forth on FortiBleed</h2><p>The discovery of the FortiBleed sparked somewhat of a back and forth between Fortinet and security researchers last month. After threat intelligence firm Hudson Rock published a <a href="https://www.hudsonrock.com/fortinet" target="_blank">blog detailing the campaign</a>, Fortinet disputed some of its claims. </p><p><a href="https://www.itpro.com/security/passwords-nicked-for-nearly-74-000-fortinet-devices"><u>Fortinet told </u><u><em>ITPro </em></u><u>at the time</u></a> that the exposed credentials weren’t the result of a fresh breach, insisting that those following best practices were safe from exposure.</p><p>"Fortinet is aware of a reported third-party credential-harvesting campaign targeting Fortinet firewalls and VPN gateways. We are committed to safeguarding our customers, and we diligently and continuously monitor threat actor darknet activity,” a spokesperson for the company said. </p><p>“Based on our initial analysis, the data involved is likely a resharing of data from previous incidents, as well as brute forcing of credentials, and not related to any current incident or advisory."</p><p>Hudson Rock, meanwhile, said the campaign went “beyond simply credential reuse,” highlighting that hundreds of organizations are thought to have been affected. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are posing as Interpol to target small businesses – here's what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hackers-are-posing-as-interpol-to-target-small-business-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Small businesses are warned to think twice before clicking on links ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dfEYQHdzwBELh5bxQfdbGS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 10:58:23 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jul 2026 21:36:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Criminals are posing as Interpol cyber crime investigators to target small businesses across Europe, Asia, the Middle East, and North America.</p><p>According to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-interpol-emails-serve-ransomware" target="_blank"><u>new research from Bitdefender</u></a>, the phishing messages claim to contain evidence that the recipients are carrying out suspicious activity, pressuring them into opening a password-protected archive.</p><p>"Based on information that has come to our attention, there may be activities involving accounts, systems or services associated with your organization that warrant further examination. We have obtained information and video material that may assist in your assessment of the matter," the emails read. </p><p>"We recommend conducting an internal review to determine whether any unauthorized, suspicious or potentially fraudulent activities have occurred. Prompt attention to such matters may help mitigate potential financial operational, reputational or regulatory risks."</p><p>Upon opening the link, recipients are directed to a <a href="https://www.itpro.com/security/proton-is-launching-its-own-private-alternative-to-google-workspace-and-microsoft-365">Proton </a>Drive-hosted file that delivers a ransomware payload hidden within multiple archive layers. Once executed, researchers said the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>seeks to encrypt files across available drives and presents victims with a ransom message.</p><p>The campaign is targeting organizations across multiple industries, including food and agriculture, legal services, pharmaceuticals, media, technology, and finance.</p><p>The ransomware is relatively simple, according to Bitdefender researchers. The code contains hardcoded values, including the password used during encryption and decryption, and lacks many of the features typically associated with large <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>operations.</p><p>Interestingly, victims are instructed to contact the attackers through a Tox chat channel to negotiate a ransom, rather than through the more usual dedicated negotiation portal or victim site.</p><p>This, researchers noted, is another indication that this is likely a custom-built operation, perhaps assembled using publicly available code and tools rather than the work of an established ransomware group.</p><h2 id="what-small-businesses-need-to-know">What small businesses need to know</h2><p>Javvad Malik, Lead CISO advisor at <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think">KnowBe4</a>, said that impersonating Interpol – or law enforcement in general – is specifically designed to trigger a “rapid emotional response” and dupe victims into ignoring red flags. </p><p>"What is interesting about this campaign is that it targets small business,” he said. “These are often understaffed and have no security or even IT expertise on hand, so it's not difficult to see why people would easily fall victim to these kinds of attacks."</p><p>Bitdefender has warned small businesses to be on the alert, urging them to verify all unsolicited correspondence by reaching out through official channels to confirm whether the communication is legitimate.</p><p>"One of the biggest red flags in this campaign is the delivery method itself," researchers said. "While the attackers impersonate Interpol, legitimate law enforcement agencies don't send unsolicited emails containing Proton Drive links to password-protected files and ask organizations to review alleged evidence of wrongdoing."</p><p>They should treat password-protected archives with caution, especially when the password is included in the email. Showing file extensions on Windows devices will make it easier to spot executables masquerading as videos or documents, and <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">multi-factor authentication (MFA)</a> should be used wherever possible.</p><p>Elsewhere, the company urged small businesses to ensure staff are trained to help spot tell-tale signs that communications are fraudulent. </p><p>"Small businesses are often viewed as easier targets than large enterprises," the researchers warned.</p><p>"Many operate without dedicated IT teams or cybersecurity staff. Security responsibilities are often shared among employees who already wear multiple hats, and limited budgets can make it difficult to invest in advanced security measures or ongoing training."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/cyber-experts-issue-alert-after-two-ransomware-groups-team-up-on-unprecedented-threat-campaign</link>
                                                                            <description>
                            <![CDATA[ The tie-up includes a new model of industrialized ransomware deployment that significantly lowers the barrier to entry for cyber crime ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pUeTeJaRNEXfC6HPKQryEG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YDWujEWW55Zc2hfESYZWb4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Jul 2026 10:24:50 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jul 2026 08:26:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YDWujEWW55Zc2hfESYZWb4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware concept image showing computer screen with binary code, with a skull imprinted over code.]]></media:description>                                                            <media:text><![CDATA[Ransomware concept image showing computer screen with binary code, with a skull imprinted over code.]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware concept image showing computer screen with binary code, with a skull imprinted over code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YDWujEWW55Zc2hfESYZWb4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ransomware groups Vect and TeamPCP are now working together in a widespread campaign involving supply chain attacks and the extortion of multiple organizations.</p><p>The tie-up, which the two announced in March, sees TeamPCP’s credential harvesting and data theft capabilities combined with Vect’s ransomware deployment infrastructure.</p><p><a href="https://www.sophos.com/en-us/blog/vect-and-teampcp-partner-for-ransomware-campaigns" target="_blank"><u>According to Sophos</u></a>, this alliance represents a huge shift in the ransomware threat landscape. </p><p>The convergence of supply chain credential theft, a maturing RaaS operation, and mass underground forum mobilization constitutes an "unprecedented" model of industrialized ransomware deployment. </p><p>Crucially, the collaboration has the potential to significantly lower the barrier to entry for up-and-coming cyber criminals. </p><p>"Threat groups are increasingly operating like businesses, collaborating to combine respective specialist capabilities and build new attack pipelines," said Rafe Pilling, director of threat intelligence at Sophos. </p><p>"As AI becomes increasingly accessible, we expect the ransomware landscape to industrialize even faster, lowering the barrier to entry by automating much of the work involved in launching attacks."</p><p>The Vect <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">ransomware as a service (RaaS)</a> operation first appeared at the end of 2025, going on to claim its first victims a month later. It's already shown it's a team player, announcing a partnership with <a href="https://www.itpro.com/security/cyber-crime/fbi-seizes-breachforums-infrastructure-but-successor-sites-are-already-popping-up">BreachForums</a> in March this year. </p><p>“Together, we are going to build something huge. Something that the entire <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>ecosystem will remember for years,” the group said at the time. </p><p>TeamPCP, meanwhile, appears to be an offshoot of The Com, a global confederation of primarily English-speaking cyber criminals. </p><p>Between March and May this year, the group carried out a series of high-profile supply chain attacks, including one on Trivy, an <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> vulnerability scanner that is made by Aqua Security. </p><p>The group has since partnered with other established extortion groups - including Lapsus$ - to monetize the stolen data.  </p><p>Sophos said Team PCP has demonstrated the ability to repeatedly compromise trusted open source tooling, with at least one verified Vect ransomware deployment using TeamPCP-sourced credentials.</p><p>This, the company said, shows that the pipeline from supply chain compromise to ransomware execution is already in operation.</p><h2 id="remaining-vigilant">Remaining vigilant </h2><p>Organizations that use open source tools in their development workflows should maintain an up-to-date inventory to enable a prompt assessment of potential impact when a supply chain compromise is announced, according to Sophos. </p><p>This will help facilitate a quick response to mitigate potential risks. </p><p>Similarly, because third-party software updates could be an attack vector, enterprises are advised to verify the integrity of updates before deploying them across environments.</p><p>"The <a href="https://www.itpro.com/software/development/ai-software-development-2026-vibe-coding-security">software development</a> environment has quietly become one of the most consequential and least governed attack surfaces in the enterprise," said Pilling.  </p><p>"Organizations must shift to a posture where they are able to quickly assess exposure and respond to supply chain attacks. It’s crucial that they carefully verify the integrity and safety of third-party updates before deploying them across their environment."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Opera browser thinks it has the solution to stopping ClickFix malware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/opera-browser-thinks-it-has-the-solution-to-stopping-clickfix-malware-attacks</link>
                                                                            <description>
                            <![CDATA[ The browser company is targeting a growing source of malicious links with its new Paste Protect feature ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zmogiYJmaz796YaNZebPmc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UDuhGC7MnuUYb7yMAeLjkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 13:53:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UDuhGC7MnuUYb7yMAeLjkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Opera browser logo and branding pictured on a smartphone screen placed on desk with pencils and art utensils.]]></media:description>                                                            <media:text><![CDATA[Opera browser logo and branding pictured on a smartphone screen placed on desk with pencils and art utensils.]]></media:text>
                                <media:title type="plain"><![CDATA[Opera browser logo and branding pictured on a smartphone screen placed on desk with pencils and art utensils.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UDuhGC7MnuUYb7yMAeLjkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Opera has started to block ClickFix-style attacks in the browser by blocking malicious clipboard copy-and-paste techniques. </p><p>ClickFix pairs social engineering with a malicious code injection attack by fooling users into clicking a link, such as a fake CAPTCHA or similar familiar popup, starting a string of events that could compromise the device. </p><p>Opera cited a report by <a href="https://www.huntress.com/resources/2026-cyber-threat-report" target="_blank"><u>Huntress</u></a> showing that ClickFix-style social engineering attacks make up 53% of all malware loader activity worldwide, underlining the scale of the threats faced by web users.</p><p>Last year, <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers"><u>Proofpoint warned</u></a> that state-sponsored hackers were turning to ClickFix techniques to target governments in particular. </p><p>To help battle that, Opera has introduced Paste Protect, a browser-native feature designed to prevent such attacks by stopping malicious code from being copied onto the clipboard, and notifying users when that happens. </p><p>"This means that if you’re accessing a website that is trying to copy something potentially harmful into your clipboard (or luring you into doing so), Opera will detect it, prevent it, and let you know about it," the company said in a <a href="https://blogs.opera.com/news/2026/07/opera-introduces-paste-protect-to-keep-you-safe-from-clipboard-attacks/" target="_blank"><u>blog post</u></a>. </p><p>Opera said it is the first major browser to add this level of protection, though Microsoft Defender does notify users of ClickFix landing pages and there are extensions that do a similar job. </p><p>"Opera had already been protecting users from paste hijacking for half a decade — it made sense to expand that protection to address one of the most increasingly serious online threats," said Mohamed Salah, Senior Director of Product at Opera. </p><p>"Paste Protect gives your browser a robust early warning system that can alert less experienced users while still enabling more control for more tech-savvy users or developers."</p><h2 id="the-rise-of-clickfix">The rise of ClickFix</h2><p>ClickFix attacks work by fooling a user into clicking a box on a malicious popup, often by pretending to be a CAPTCHA or a "verify you're a human" box. That lets the dodgy website copy to the clipboard and open another window. </p><p>"When this prompt appears, the website has already 'copied' something to your clipboard, and now it instructs you to open the Windows Run dialog box (Win+R), then use 'Ctrl + V' to paste the malicious code, and then click 'OK'," the blog post noted. "This would execute the code and compromise your device, and the data on it."</p><p>Instead, Opera's Paste Protect examines the content being copied, and if concerned, blocks the code from being copied to the clipboard and notifies the user. They can then close the window without interacting. </p><p> "<a href="https://www.itpro.com/security/cyber-attacks/malicious-urls-overtake-email-attachments-as-the-biggest-malware-threat">ClickFix attacks</a> succeed because they turn the user into the weapon," said Pawel Kurzelewski, Head of Security at Opera.</p><p>"The clipboard is the last point before a malicious command is run, so that's where we built our defense. With Paste Protect, we're stopping these attacks at the exact moment they would normally succeed."</p><p>The Paste Protect system does mean that the Opera browser is scanning everything copied to the clipboard for potential threats or harmful commands. When those are spotted, the system displays a red warning icon. </p><p>Websites can be individually approved to circumvent these warnings if safe, and users can still check to see if a mistake has been made. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Alleged Scattered Spider hacker snared in Finland, extradited to US ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/alleged-scattered-spider-hacker-snared-in-finland-extradited-to-us</link>
                                                                            <description>
                            <![CDATA[ Teenager Peter Stokes has been extradited to the US on hacking charges ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pJG3tDAZcpJWzPuioJKoNQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EC3BuBnLtE6s8TqRFjZodG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 09:37:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EC3BuBnLtE6s8TqRFjZodG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI render of a circuitboard lined with red lines in the shape of a spider, representing the Scattered Spider threat group.]]></media:description>                                                            <media:text><![CDATA[A CGI render of a circuitboard lined with red lines in the shape of a spider, representing the Scattered Spider threat group.]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI render of a circuitboard lined with red lines in the shape of a spider, representing the Scattered Spider threat group.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EC3BuBnLtE6s8TqRFjZodG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A teenager believed to be part of the <a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks">Scattered Spider hacking group</a> has been extradited from Finland to the United States. </p><p>Peter Stokes, 19, is the latest alleged member of the group to be nabbed by the FBI as part of Operation Riptide, an ongoing campaign targeting the criminals, infrastructure, and financial networks behind cyber crime.</p><p>Stokes, a dual citizen of the United States and Estonia, has been charged with conspiracy, computer intrusion, and fraud. He was arrested by Finnish authorities in April following an Interpol Red Notice, and extradited to the US last week. He made an initial appearance on Tuesday in federal court in Chicago.</p><p>“The criminal complaint charges Peter Stokes with membership in Scattered Spider, a hacking group that has been involved in over 100 network intrusions, resulting in more than $100 million in <a href="https://www.itpro.com/business/business-strategy/ransomware-victims-are-refusing-to-play-ball-with-hackers-just-17-percent-of-enterprises-have-paid-up-so-far-in-2025-marking-an-all-time-low">ransom payments</a> and millions more in damages to the victims,” said assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division. </p><p>“The charges unsealed today are the result of years of work by the Criminal Division, the US Attorney’s Office for the Northern District of Illinois, and the FBI. We will continue to partner to ensure that cybercriminals cannot evade the reach of the United States.”</p><p>According to the complaint, Stokes and his fellow criminals breached a luxury jewellery retailer’s computer system, exfiltrated data, and made a ransom demand of around $8 million in cryptocurrency in May last year. </p><p>The firm managed to successfully evict the hackers from its computer network and no ransom was paid. However, it suffered a loss of at least $2 million due to business disruption, investigation, and threat mitigation.</p><h2 id="the-walls-are-closing-in-on-scattered-spider">The walls are closing in on Scattered Spider</h2><p>The Scattered Spider group has been linked to more than 100 network intrusions, resulting in over $100 million in ransom payments and millions of dollars in damages to the victims. </p><p>The group targets companies across the US with social engineering and SIM swap attacks, encrypting data or exfiltrating it to remote servers. It then extorts <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency </a>from the companies in return for the return of their data or to prevent it being disseminated.</p><p>Scattered Spider has rapidly grown to become one of the most notorious threat groups worldwide, having claimed responsibility for <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack">attacks on UK retailers Marks & Spencer</a> and the <a href="https://www.itpro.com/security/cyber-attacks/co-op-chief-executive-very-proud-of-cyber-attack-response-despite-huge-financial-losses">Cooperative Group</a>, as well as <a href="https://www.itpro.com/security/cyber-attacks/mgm-resorts-back-online-after-suspected-ransomware-attack">MGM Resorts</a> in the US.</p><p>“Scattered Spider has repeatedly targeted US companies, extorting employees, inflicting millions of dollars in losses, and disrupting essential operations,” said assistant director Brett Leatherman of the FBI’s Cyber Division. </p><p>“Through strong domestic and international partnerships, the FBI will continue to identify, disrupt, and hold cybercriminals accountable, no matter where they are located.”</p><p>While the group has been repeatedly hit by law enforcement takedowns, it keeps emerging in different forms, for example teaming up with overlapping threat groups <a href="https://www.itpro.com/security/cyber-attacks/google-cyber-researchers-were-tracking-the-shinyhunters-groups-salesforce-attacks-then-realized-theyd-fallen-victim">ShinyHunters</a> and <a href="https://www.itpro.com/security/cyber-attacks/367199/what-is-the-lapsus-group-who-is-behind-the-criminal-operation">LAPSUS$</a> to form a unified collective.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why MSPs are now critical digital trust infrastructure and prime targets for modern cybercrime ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/why-msps-are-now-critical-digital-trust-infrastructure-and-prime-targets-for-modern-cybercrime</link>
                                                                            <description>
                            <![CDATA[ MSPs have become critical infrastructure in the digital economy — and that makes them real targets for those with malintent ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pQXtNmsidTspk8wrVutXM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christoph Brecht ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/isjjUTQGjbhBsT59LjsXbk.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Managed Service Providers (MSPs) were once viewed primarily as IT support partners. Today, they operate something far more critical: digital trust infrastructure.</p><p>MSPs manage identity systems, remote monitoring platforms, cloud environments, endpoint protection frameworks, and data backup architecture across dozens — sometimes hundreds — of client environments. In doing so, they have become central operational nodes in the digital economy.</p><p>That centrality also makes them strategically attractive to cybercriminals.</p><h2 id="from-service-providers-to-trust-custodians">From service providers to trust custodians</h2><p>Modern organizations depend on MSPs not just for operational efficiency, but for secure access management, infrastructure resilience, and regulatory alignment. MSP platforms sit at the intersection of customer networks, cloud services, SaaS applications, and identity environments.</p><p>This position makes MSPs stewards of inherited trust across entire business ecosystems.</p><p>When that trust is compromised, the consequences extend far beyond a single organization.</p><p>MSPs now operate critical digital infrastructure. When that trust is compromised, the impact multiplies across entire client ecosystems.</p><h2 id="why-attackers-are-targeting-msp-ecosystems">Why attackers are targeting MSP ecosystems</h2><p>Threat actors increasingly mirror the scale economics of managed services themselves. Rather than targeting organizations individually, attackers focus on centralized service environments that provide multiplier effects across downstream clients.</p><p>The logic is simple: compromising one MSO can provide access to dozens, sometimes hundreds, of connected organizations.</p><p>Remote monitoring and management platforms, multi-tenant administration consoles, and aggregated identity systems have become high-leverage entry points. Once inside, attackers can move laterally, harvest credentials, conduct reconnaissance, and deploy payloads across multiple customer environments simultaneously.</p><p>Campaigns attributed to groups such as DragonForce demonstrate how exploitation of MSP tooling can enable credential theft, data exfiltration, and ransomware deployment at scale.</p><p>Attackers have adopted the same logic as manager services: centralize access, standardize operations, and scale efficiently.</p><h2 id="the-industrialization-of-cybercrime-meets-the-managed-services-model">The industrialization of cybercrime meets the managed services model</h2><p>This convergence reflects a broader shift in cybercrime operations. Criminal groups now prioritize scalability, automation, and repeatable processes — principles that mirror the operational models used by MSPs.</p><p>Cybercrime has become industrialized, adopting structured affiliate programs, service platforms, and monetization strategies designed to maximize efficiency.</p><p>Managed service environments naturally align with this approach because they aggregate infrastructure, identities, and administrative access into centralized systems.</p><p>For attackers, this represents an opportunity. For MSPs, it raises the stakes of operational resilience.</p><h2 id="resilience-maturity-as-a-competitive-differentiator">Resilience maturity as a competitive differentiator</h2><p>As threat exposure grows, resilience maturity is becoming a defining factor that separates strategic MSP partners from commodity service providers.</p><p>Customers are increasingly evaluating MSPs based on governance transparency, identity security controls, incident readiness, and third-party risk management practices. Regulatory frameworks such as NIS2 are further reinforcing expectations around operational accountability and supply-chain oversight.</p><p>Security is no longer just a technical feature; it is a business trust signal.</p><p>Resilience maturity is becoming the dividing line between strategic MSPs and commodity providers</p><p>Forward-looking MSPs are strengthening privileged access controls, monitoring behavioral anomalies across multi-tenant environments, segmenting client infrastructure, and conducting continuous supply chain risk assessments.</p><p>These measures do more than reduce exposure; they demonstrate strategic commitment to protecting customer ecosystems.</p><h2 id="intelligence-led-defense-in-interconnected-ecosystems">Intelligence-led defense in interconnected ecosystems</h2><p>As digital environments grow more interdependent, reactive security models are proving insufficient. MSPs increasingly benefit from adversary-centric threat intelligence that tracks how specific attacker groups operate, which tools they exploit, and how campaigns typically unfold.</p><p>This approach enables earlier detection of suspicious behavior and faster disruption of attack chains before compromise spreads downstream.</p><p>Predictive threat intelligence also allows MSPs to anticipate emerging risks across their customer base, rather than responding only after incidents occur.</p><h2 id="the-future-role-of-msps-in-digital-trust">The future role of MSPs in digital trust</h2><p>The role of MSPs will continue expanding as organizations seek partners capable of managing both operational complexity and cybersecurity risk.</p><p>That reliance reinforces the MSP’s position as a custodian of digital trust — a role that extends beyond service delivery into governance, resilience, and ecosystem-wide risk management.</p><p>The providers that succeed in this environment will be those that recognize this responsibility and invest accordingly.</p><p>MSPs are no longer just managing infrastructure. They are safeguarding the trust architecture that modern business depends upon.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolen ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/every-hour-ransomware-goes-undetected-drastically-increases-its-potential-blast-radius-hackers-are-breaching-networks-and-laying-low-for-longer-and-nearly-half-of-firms-dont-realize-until-data-is-stolen</link>
                                                                            <description>
                            <![CDATA[ An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cMDgctJLzdkxNeygT75xeb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NRpUDS8HAHAPeYophCskA8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jul 2026 08:59:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NRpUDS8HAHAPeYophCskA8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Concept image showing man lurking in shadows with strands of light hitting different parts of his face while staring intently.]]></media:description>                                                            <media:text><![CDATA[Concept image showing man lurking in shadows with strands of light hitting different parts of his face while staring intently.]]></media:text>
                                <media:title type="plain"><![CDATA[Concept image showing man lurking in shadows with strands of light hitting different parts of his face while staring intently.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NRpUDS8HAHAPeYophCskA8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are sneaking into networks and staying undetected for longer than ever, according to new research, and many security teams are frightfully unaware. </p><p>A <a href="https://www.extrahop.com/resources/reports/the-2026-extrahop-global-threat-landscape-report" target="_blank"><u>study from security firm ExtraHop</u></a> found threat actors are managing to access corporate networks and quietly maintain access for an average of two and a half weeks before their presence is detected — with a small number remaining undetected for several months or even years at a time. </p><p>Nearly half of organizations polled said they didn't detect the intrusion until after data was stolen, marking a 31% increase compared to last year. Notably, 14% weren’t aware any attack had taken place until the hackers themselves alerted the enterprise, typically with ransom demands. </p><p>Detection is being delayed by a combination of sophisticated obfuscation methods and alert fatigue, the survey suggested. Four-in-ten respondents, for example, said detection was delayed by attackers using encrypted channels or by mirroring legitimate workflows and processes. </p><p>Another 34% reported attackers using high-privilege account permissions to dodge being spotted. But a further 30% said initial detection was missed because alert fatigue, while 27% said undetermined baseline behavior made it difficult to spot dodgy activity. </p><p>"Every hour <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>goes undetected drastically increases its potential blast radius," the report noted. "A wider detection window grants adversaries the critical dwell time needed to move laterally and locate backups. This delays containment, turning what could have been a localized incident into an organization-wide crisis."</p><h2 id="concerning-dwell-times">Concerning dwell times</h2><p>Dwell times – which refer to the timeframe in which an attack starts to when it is detected – are by no means a new problem for <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>teams. </p><p>Indeed, it’s been a long-running war of attrition for security practitioners in recent years, with threat actors becoming increasingly proficient in <a href="https://www.itpro.com/security/cyber-attacks/us-telco-confirms-hackers-breached-systems-in-stealthy-state-backed-cyber-campaign-and-remained-undetected-for-nearly-a-year">staying undetected before wreaking havoc</a>. </p><p>As far back as 2023, <a href="https://www.itpro.com/security/shrinking-cyber-attack-dwell-times-highlight-growing-war-of-attrition-with-threat-actors"><u><em>ITPro </em></u><u>reported that enterprises were facing huge problems</u></a> with this issue, yet research from Sophos at the time found enterprises were improving their response to threats on this front. </p><p>More recent analysis from <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2025/" target="_blank"><u>Mandiant’s 2025 M-Trends report</u></a>, however, shows that global median dwell times also shrunk from 11 days to 10 days. </p><p>That may seem like a step in the right direction in terms of detection capabilities, but as Sophos noted, more rapid reaction times mean threat actors are accelerating attacks and acting more aggressively – particularly in ransomware cases.</p><h2 id="ransomware-isn-t-shrinking-it-s-migrating">‘Ransomware isn’t shrinking, it’s migrating’</h2><p>The report also found that, among polled organizations, the number of ransomware incidents faced annually by each company had fallen from 5.4 to 3.5. </p><p>That doesn't mean <a href="https://www.itpro.com/security/ransomware/why-ransomware-attacks-happen-to-small-businesses-and-how-to-stop-them">the ransomware threat is going away</a>, but rather shifting focus from the US, Western Europe, Australia, and Singapore to areas with rapid enterprise digitization such as Brazil, Mexico, Vietnam, Thailand, and Indonesia. </p><p>"Ransomware isn’t shrinking, it’s migrating," the report found. "As coordinated global law enforcement hardens traditional targets, syndicates are moving downstream to other targets." </p><p>ExtraHop researchers spotted some good news, though, mainly that the average ransom payment had fallen to $2.8 million from last year's $3.6 million. On the downside, the frequency of payments is up. </p><p>Of those polled, 83% of victims paid a ransom, up from 70% in previous surveys. ExtraHop noted that the financial costs of business disruption is what drives most companies to pay a ransom, with downtime per incident averaging nearly 30 hours. </p><h2 id="ai-is-creating-noise-for-cyber-pros">AI is creating ‘noise’ for cyber pros</h2><p>Beyond that, 55% of respondents said that AI was the attack surface presenting the biggest risk to their organisation. </p><p>Enterprises raised further concerns around AI-enhanced attacks, <a href="https://www.itpro.com/security/cyber-attacks/vast-majority-breaches-enabled-preventable-gaps-identity-weaknesses-palo-alto-networks">compromised AI identity</a> and session theft, third-party or supply chain breaches due to their integrated AI, and <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-shadow-ai-and-what-leaders-can-do-to-prevent-it">shadow AI</a> exposure. </p><p>Plus, AI is often adding to the "noise" faced by security teams, with 30% of those surveyed saying that AI alerts had produced false positives that had slowed down wider investigation timelines. </p><p>"When you look at the big picture of modern cyber risk, the thread connecting every major challenge, from missed detections and prolonged dwell times to AI false positives, is a fundamental lack of situational awareness, or ground truth," said Raja Mukerji, Co-founder and Chief Scientist at ExtraHop.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nissan employee data exposed in Oracle PeopleSoft zero-day attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/nissan-employee-data-exposed-in-oracle-peoplesoft-zero-day-attacks</link>
                                                                            <description>
                            <![CDATA[ The car manufacturer has urged current and former employees to change banking passwords and remain vigilant for phishing emails ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iEFssRXnv84RqT2KkL5doK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CDWcH6YZibWtKGZ2YxnLPY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 16:18:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CDWcH6YZibWtKGZ2YxnLPY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nissan logo and branding illuminated against a dark backdrop at the 2026 New York International Auto Show in New York City, USA.]]></media:description>                                                            <media:text><![CDATA[Nissan logo and branding illuminated against a dark backdrop at the 2026 New York International Auto Show in New York City, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[Nissan logo and branding illuminated against a dark backdrop at the 2026 New York International Auto Show in New York City, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CDWcH6YZibWtKGZ2YxnLPY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nissan has revealed it suffered a data breach after threat actors exploited flaws in Oracle’s PeopleSoft software, with information on both current and former staff exposed. </p><p>In a <a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-625558" target="_blank"><u>filing </u></a>with the California Attorney General’s Office, the car manufacturer said it is “working as quickly as possible” to establish the full scale and scope of the breach. </p><p>An initial investigation by the company reveals that personal information such as contact and banking information, social security numbers, and financial and tax data was exposed in the breach. </p><p>Current and former employees in the US, Canada, Mexico, and Brazil are among those affected, the company said. </p><p>“As we continue our investigation, individuals whose personal information has been exposed will receive further communication with additional details and next steps,” the filing reads. </p><p>Nissan urged employees to take a number of precautionary steps in the meantime, including remaining vigilant for <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>emails or fraudulent phone calls and text messages. </p><p>Staff were also advised to monitor financial accounts and credit reports for unusual activity, and urged to change passwords for “all significant accounts” - such as banking services. </p><p>Nissan noted that systems have since been secured and the company is working with technical experts to prevent further leaks. </p><p>“Upon learning about this issue, we quickly activated incident response protocols. We have been in communication with authorities throughout our response to this attack,” the filing reads. </p><p>“Our technical teams, along with external experts, have secured our systems and will continue to work with Oracle to address this issue. We have taken steps designed to end unauthorized access and to prevent further disclosure of the information.”</p><h2 id="oracle-peoplesoft-breach">Oracle PeopleSoft breach</h2><p>The announcement by Nissan comes in the wake of a “cyber event” involving Oracle’s PeopleSoft software, which is used to manage employee information such as payroll, tax, and other personnel details. </p><p>More than 100 organizations are believed to have been affected by the breach so far, which has been linked to the ShinyHunters threat group. </p><p>Earlier this month, the <a href="https://www.itpro.com/security/nottingham-university-cyber-attack-everything-we-know-so-far-as-shinyhunters-claims-responsibility">University of Nottingham</a> was among those impacted by the breach, with data belonging to around 450,000 present and former students compromised in the attack.</p><p>Simon Pamplin, <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO </a>at Certes, said the breach is a single <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero-day</a> in “widely deployed enterprise software can become a mass-casualty event”.</p><p>“Nissan was not the target of a bespoke attack. It was one of many companies caught in a campaign exploiting a shared vulnerability in HR and payroll infrastructure used across industries,” he said. </p><p>“The data involved here is particularly serious. Social Security numbers, banking details, tax information and dependent records are not generic employee data. They are the durable financial backbone of a person's identity, and they were sitting inside a system many organisations treat as core infrastructure rather than a high-value target.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple is speeding up software patching due to AI security concerns – here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/apple-is-speeding-up-software-updates-due-to-ai-security-concerns-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Apple is speeding up its software patching processes amid rising concerns that AI is helping hackers to spot and exploit flaws at a far quicker pace. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mJUdpB2YvXhSJSzeoU3HKG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FWwjBQGEHUXVQXCooGUfrc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 10:52:57 +0000</pubDate>                                                                                                                                <updated>Tue, 30 Jun 2026 10:53:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FWwjBQGEHUXVQXCooGUfrc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Apple logo pictured through a gap in foliage on the company&#039;s regional headquarters in Tokyo&#039;s Ginza district.]]></media:description>                                                            <media:text><![CDATA[Apple logo pictured through a gap in foliage on the company&#039;s regional headquarters in Tokyo&#039;s Ginza district.]]></media:text>
                                <media:title type="plain"><![CDATA[Apple logo pictured through a gap in foliage on the company&#039;s regional headquarters in Tokyo&#039;s Ginza district.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FWwjBQGEHUXVQXCooGUfrc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has dropped an unexpected out-of-band patch, and it's apparently because of concerns that AI is helping hackers exploit vulnerabilities at lightning speed. </p><p>The tech giant released iOS 25.6.2 yesterday, with fixes for <a href="https://www.itpro.com/software/apple/ios">iOS </a>and iPadOS, despite normally bundling such security patches into wider updates. Apple hasn't said when its next major update, iOS 26.6, is set to be released, but it's widely expected in the next few weeks ahead of iOS 27 in the autumn. </p><p>Apple told <a href="https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/" target="_blank"><u><em>Reuters</em></u></a><em> </em>that the extra security update was down to concerns about AI shortening the time between a flaw being spotted and exploited by hackers. </p><p>The company said that shorter timelines from flaw to exploit meant it needed to respond by cutting the time between when updates are announced and released. </p><p>That shouldn't be taken as a suggestion that Apple was seeing any evidence that hackers were already making use of any of the flaws included in the update, the company noted. </p><p><em>ITPro </em>approached Apple for confirmation of the changes made to its security patching policy, but did not receive a response by time of publication. </p><h2 id="apple-responds-to-accelerating-threats">Apple responds to accelerating threats</h2><p>The move comes in response to wider concerns that AI is helping hackers find flaws more easily and turn them into exploits more quickly. Indeed, this has been a recurring talking point since the release of powerful new frontier models such as <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-just-launched-claude-fable-5-its-first-mythos-class-ai-model-but-it-has-new-safeguards-to-prevent-misuse-and-will-fall-back-to-opus-4-8-for-high-risk-queries"><u>Anthropic’s Claude Mythos range</u></a>. </p><p>Last month, Google said it had spotted cyber criminals using <a href="https://www.itpro.com/security/google-threat-intelligence-group-first-ai-zero-day-exploit-discovery"><u>AI to build a working zero-day exploit</u></a>, with John Hultquist, chief analyst at GTIG, warning that an “AI vulnerability race is imminent”</p><p>That echoes a <a href="https://www.itpro.com/security/brace-yourselves-for-a-vulnerability-explosion-forescout-warns"><u>warning earlier this year</u></a> from Daniel dos Santos, VP of research at Forescout, who told <em>ITPro </em>that enterprises should brace themselves for an explosion of vulnerabilities thanks to AI, further adding to the workload of security teams.</p><p>Jake Moore, Global Cybersecurity Advisor at ESET, told <em>ITPro </em>that while the “jury is still out” on how powerful tools such as Mythos are, AI advances do mean that security teams and threat actors alike are scrambling to find software vulnerabilities. </p><p>"Whenever a new issue is discovered, there's a race to patch flaws before they can be exploited – and if users or security teams hold off on installing updates, it's a gift to threat actors,” he said. </p><p>Moore added that increasing numbers of patches mean the process needs to be automated as much as possible to avoid update fatigue for both end users and security practitioners. </p><p>"In the age of automated vulnerability discovery, we're past the point of expecting users and security teams in organisations to manually patch everything," he commented.</p><p>"Updates should be automated wherever possible to reduce the burden on users while making sure patches are applied rapidly."</p><h2 id="apple-ios-26-5-2">Apple iOS 26.5.2</h2><p>The <a href="https://support.apple.com/en-us/100100" target="_blank"><u>security fixes released by Apple</u></a> were previously revealed via a beta of the update, as is Apple's usual procedure, and addressed more than 30 vulnerabilities across iOS and iPadOS. </p><p>Those include kernel vulnerabilities that could corrupt memory and trigger system shutdown and a stack of WebKit issues, including one that could leak sensitive data after visiting a website. </p><p>Three WebKit flaws were spotted by OpenAI's Codex Security, while another was spotted by a pair of AI researchers using Claude Anthropic. </p><p>The update should have already landed on devices, and is supported on these devices:</p><ul><li>iPhone 11 and later</li><li>iPad Pro 12.9 inch, 3rd generation and later</li><li>iPad Pro 11 inch, 1st generation and later</li><li>iPad Air 3rd generation and later</li><li>iPad 8th generation and later</li><li>iPad mini 5th generation and later</li></ul><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US offers $10m bounty for info on Russia-linked hackers behind Signal and WhatsApp attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/us-offers-usd10m-bounty-for-info-on-russia-linked-hackers-behind-signal-and-whatsapp-attacks</link>
                                                                            <description>
                            <![CDATA[ UNC5792 and UNC4221 have been targeting government officials through their Signal and WhatsApp accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">J9nPQ3c6wnnTZ8dYQesqeA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 09:58:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of State is offering a reward of up to $10 million to anyone that can help it identify and locate members of the Russia-linked UNC5792 and UNC4221 hacking groups.</p><p>UNC4221 works on behalf of the Russian military services while UNC5792 is associated with the Russian Federal Security Service (FSB), and has carried out <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns <a href="https://www.itpro.com/security/microsoft-and-ncsc-issue-alerts-over-hacker-campaigns-targeting-whatsapp-signal-messaging-apps">targeting the Signal and WhatsApp</a> accounts of US government officials, military leadership, and allied personnel.</p><p>"Using <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> techniques, these malicious cyber actors exploit legitimate device-linking features in these secure messaging applications to gain unauthorized access to sensitive government communications, contact lists, and group conversations," said the US Department of State. </p><p>"After compromising an account, the malicious actors were also able to send messages and conduct additional phishing against other accounts using those same commercial messaging applications."</p><p>In some cases, UNC5792 actors altered legitimate group invite pages to redirect users to a malicious URL that linked a hacker-controlled device to the victim’s Signal account. </p><p>Officials said that while these activities did not exploit vulnerabilities in either platforms’ encryption standards, they successfully compromised “thousands of individual commercial messaging application accounts”. </p><p>Targets included US government officials, diplomatic personnel and foreign affairs officials, defense and national security personnel, policy analysts and advisors, NATO member-state officials and diplomats, and allied intelligence and defense partners. </p><p>The group also went after investigative journalists covering Russia, Ukraine, and international affairs, NGOs providing support and assistance to Ukraine, and academic researchers in security studies and Russian affairs.</p><h2 id="valuable-intel">Valuable intel</h2><p>The announcement of the reward follows an <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank"><u>advisory</u></a> issued by the FBI and the <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a> last week, which warned of continued activity by the two groups as well as a change in tactics aimed at harvesting victims' backup recovery keys.</p><p>"If a victim inadvertently shares their backup recovery key, that same key remains valid even if they create a new account following the compromise using the same phone number," the advisory warned. </p><p>"Consequently, the actor could potentially use the compromised key to take over the new account in the future as well."</p><p>The department gives a list of what information it seeks, including:</p><ul><li>Names</li><li>Locations</li><li>Biographical information on UNC5792 members</li><li>Affiliations with Russian intelligence services</li><li>Identities of personnel providing technical support</li><li>Contractors or third-party entities providing services</li></ul><p>It’s also seeking information on domain names, server locations, hosting providers, data storage and processing infrastructure, and technical tools, frameworks, and software used in operations.</p><p>Elsewhere, officials are keen to hear about the financial side of operations, including: </p><ul><li>Funding sources</li><li>Financial accounts and banking relationships</li><li>Cryptocurrency wallets</li><li>Payments for infrastructure</li><li>Financial networks supporting operations</li></ul><p>Anyone with dirt on either of the two groups can submit their tip <a href="https://rewardsforjustice.net/rewards/unc5792/" target="_blank"><u>here</u></a>, uploading relevant files such as photographs, videos, and documents. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK business leaders think AI will create more jobs than it destroys – the reality lies somewhere in between ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/uk-business-leaders-think-ai-will-create-more-jobs-that-it-destroys-the-reality-lies-somewhere-in-between</link>
                                                                            <description>
                            <![CDATA[ Despite repeated warnings that AI could render millions of roles obsolete, UK business leaders are confident the technology will deliver positive long-term gains ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5LjGo2XJWE9ckmAU6t64Jc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NkNVwSsdcf9qXz8U6QRSoW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 30 Jun 2026 14:17:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NkNVwSsdcf9qXz8U6QRSoW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Human male office worker sitting at a desk working on computer while AI robot works on computer on other side of desk.]]></media:description>                                                            <media:text><![CDATA[Human male office worker sitting at a desk working on computer while AI robot works on computer on other side of desk.]]></media:text>
                                <media:title type="plain"><![CDATA[Human male office worker sitting at a desk working on computer while AI robot works on computer on other side of desk.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NkNVwSsdcf9qXz8U6QRSoW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK business leaders are confident that <a href="https://www.itpro.com/business/business-strategy/enterprises-keep-cutting-staff-for-ai-and-they-keep-regretting-it">AI will create more jobs than it destroys</a>, despite recurring claims of a pending ‘jobs apocalypse’. </p><p>According to research from Box, nearly two-thirds (65%) of UK business leaders said they expect their organization’s overall headcount to increase over the next three years, with just 14% expecting workforce numbers to decrease. </p><p>This optimistic outlook comes amid growing AI maturity at organizations across the country, the study noted. Many are entering a “new phase of AI adoption”, moving beyond basic experimentation to fully embedding AI and agents within core operations. </p><p>Notably, among those using agents, only 8% said the technology is eliminating existing roles. If anything, the majority of enterprises report surging demand for new, AI-focused positions to support adoption. </p><p>Nearly half (48%), for example, are hiring ‘AI agent operators’ within IT teams, with this new class of specialist working in tandem with automated bots across a range of areas. </p><p>Elsewhere, 32% are adding ‘workflow automation specialists’, security, risk, and compliance professionals (31%), and governance and AI ethics specialists (26%) to their roster. </p><p>Box noted that the findings suggest that UK firms are now coming to view AI as a “workforce transformation opportunity” that’s creating a demand for new skills and expertise, rather than a destroyer of roles. </p><p>"UK organizations are moving beyond AI experimentation and into operationalization,” said Samantha Wessels, president of EMEA at Box. </p><p>"We're entering the era of the agentic enterprise, where AI is becoming embedded into everyday business processes and workflows. The companies seeing the greatest success are not simply deploying more AI tools; they are building the foundations that allow AI to scale across the business, including trusted content, governance frameworks and the teams needed to manage agentic workflows.”</p><h2 id="no-ai-jobs-apocalypse-after-all">No AI ‘jobs apocalypse’ after all</h2><p>The research from Box comes in stark contrast to what has become a prevailing sentiment across the tech industry in recent years, mainly that AI could render millions of roles obsolete. </p><p>Workers across a range of industries and professions – from <a href="https://www.itpro.com/software/development/big-tech-is-still-hiring-software-engineers-despite-claims-ai-will-replace-them-and-marc-benioff-says-thats-the-canary-in-the-coal-mine-for-whether-the-technology-is-up-to-scratch">software engineering</a> and HR, to marketing and <a href="https://www.itpro.com/technology/artificial-intelligence/agentic-ai-is-coming-for-customer-service-jobs">customer support</a> – have been bombarded with warnings about a pending jobs apocalypse due to the technology. </p><p>Last year, for example, Anthropic CEO Dario Amodei warned that <a href="https://www.itpro.com/technology/artificial-intelligence/entry-level-jobs-ai-anthropic-dario-amodei">AI could destroy up to half of all ‘white collar’ roles</a>, while concerns over the <a href="https://www.itpro.com/technology/artificial-intelligence/entry-level-jobs-ai-anthropic-dario-amodei">impact of AI on entry-level positions</a> reached boiling point. </p><p>In March this year, Microsoft’s AI chief Mustafa Suleyman <a href="https://fortune.com/article/why-microsoft-ai-chief-mustafa-suleyman-predicts-ai-automation-18-months/" target="_blank"><u>also warned</u></a> that white collar roles could be automated by AI within just 18 months. </p><p>These bold claims by big tech figures have become a contentious topic in recent months. Some industry leaders have hit back at suggestions while others have changed their tune. </p><p>OpenAI CEO Sam Altman recently <a href="https://www.itpro.com/technology/artificial-intelligence/openai-ceo-sam-altman-pours-cold-water-on-ai-jobs-apocalypse-claims"><u>dismissed claims that AI advances could lead to mass workforce disruption</u></a>, noting that roles across a range of industries will still require human involvement. </p><p>Speaking during a session at a Commonwealth Bank of Australia (CBA) conference, Altman said widespread upheaval in white collar work is yet to materialize.</p><p>"I don't think we're going to have the kind ​of jobs apocalypse that some of the companies in our space advocate or talk about,” Altman said.</p><h2 id="ai-will-still-cause-upheaval">AI will still cause upheaval</h2><p>Mixed messaging over the impact of AI on global labor markets has become another point of contention in recent months. While debates among industry leaders rage, research does point to disruption. </p><p>In January this year, Forrester projected that <a href="https://www.itpro.com/business/business-strategy/ai-job-losses-great-recession-us-forrester"><u>roughly 10.4 million jobs could be eliminated due to AI by 2030</u></a> as enterprises ramp up automation of roles. </p><p>Speaking at the time, Forrester VP principal analyst JP Gownder noted the scale of cuts could eclipse the number of jobs lost during the Great Recession of 2008, which saw around 8.7 million people out of work. </p><p>What has become clear is that AI will fundamentally reshape roles and responsibilities for individual workers in years to come.  </p><p>As <a href="https://www.itpro.com/business/gartner-says-ai-wont-create-a-jobs-apocalypse-but-it-will-cause-chaos-as-millions-are-forced-to-upskill"><u><em>ITPro </em></u><u>reported in December last year</u></a>, Gartner expects AI to prompt a mass wave of upskilling and reskilling as enterprises look to equip workers with new skills to compensate for the use of the technology. </p><p>Indeed, the consultancy projects that from 2028 onwards, roughly 32 million jobs a year will be “reconfigured, redesigned, or fused”. </p><p>Helen Poitevin, distinguished VP analyst at Gartner, told <em>ITPro </em>that this will create a degree of upheaval, but nothing akin to a jobs apocalypse. </p><p>Gartner estimates that around 150,000 people will need to be upskilled each day and “supported in new ways of working” due to the technology. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Simplicity and unity will win the fight against AI cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/simplicity-and-unity-will-win-the-fight-against-ai-cyberattacks</link>
                                                                            <description>
                            <![CDATA[ How MSPs can turn the rise of AI-driven breaches into a business advantage ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KzTQsEd9o4M2HgH6FoEr8i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 01 Jul 2026 12:58:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ VimalRaj Sampathkumar ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Fzc6sJqk4ccSXbYZkvtoGK.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:description>                                                            <media:text><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the age of AI, perimeter defense alone is no longer enough. Traditional methods for securing IT estates are horribly vulnerable to increasingly sophisticated AI tools, leading to a rapid degradation of many organizations’ defenses. </p><p>On a global scale, in April, the <a href="https://www.bbc.co.uk/news/articles/crk1py1jgzko"><u>news</u></a> broke of Claude Mythos’ limited release and the danger it could pose to cybersecurity worldwide. The hyper-powerful AI model rapidly uncovered flaws and vulnerabilities in defense systems that had lain dormant for years, threatening the integrity of banking systems, energy networks, and more.</p><p></p><p>In the UK, more than three-quarters of UK businesses have suffered a cyber incident in the past year. What’s more, 43% of UK IT decision-makers identified AI-powered attacks as the single biggest risk they face over the next 12 months, ahead of traditional threats such as ransomware, phishing, and data breaches. </p><h2 id="turning-lemons-into-lemonade">Turning lemons into lemonade</h2><p>Clearly, there’s plenty of cause for concern here – the challenge is significant, and the potential damage could reach far beyond companies’ bottom lines. But that doesn’t mean the IT industry should throw up its hands and accept the inevitable. Rather, the rapid growth in AI-driven breaches is a sign that a new approach is needed. </p><p>For managed service providers (MSPs) in particular, the evolving threat of AI presents a business opportunity rather than just another security burden. As customers seek to handle cloud patching complexity, regional compliance differences, and increasingly automated attacks, MSPs that can unify security, operations, and automation in a single offering will be best placed to improve service quality and usability – and so unlock increased profitability.</p><p>This isn’t wishful thinking: organizations are making plans to invest in technology that can help them tackle the AI challenge. AI and advanced threat preparedness is the top spending commitment for UK organizations over the next 12 to 24 months, cited by 41% of 1,500 IT decisionmakers ManageEngine recently surveyed.</p><h2 id="simpler-faster">Simpler, faster</h2><p>There is also a growing gap between how quickly organizations detect incidents and how long it takes them to recover, which is where MSPs can provide real value. The majority (94%) of UK organizations detect incidents within 24 hours, and nearly half recover within 10 days. However, 26% said recovery can extend beyond 10 days, with a smaller proportion taking more than 20 days.</p><p>In response to that inefficiency, MSPs can help by reducing tool sprawl, standardising workflows, responding quickly to incident reports, and packaging up more resilient service tiers. Clients will pay for this kind of rationalisation and streamlining, providing, as it does, a crucial way to reduce the time between a security incident and a successful resolution.</p><h2 id="putting-operational-tech-at-the-center">Putting operational tech at the center</h2><p>MSPs can also provide value in the battle against AI-driven cyberattacks by including operational technology (OT) in the development of security systems as a priority rather than an afterthought. OT is becoming part of the managed risk surface and requires the same disciplined approach MSPs already apply to IT – not least because OT software may traditionally have been seen as ‘lower-risk’, and therefore less diligently patched.</p><p>Again, the core benefit MSPs can provide clients with here is acting as the single point of contact that draws together oversight of all potential vulnerabilities. As organizations’ digital estates become ever more complex, applying security policies and automations to OT as well as back-office apps and systems can be a major headache. </p><p>MSPs with expertise across the board can not only build a unified policy to defend the entire attack surface – they can also radically simplify day-to-day management for client IT teams.</p><p>AI is turning the threat of cyber attack into a many-armed monster, hitting harder and in more places than ever before. In the face of this ramped-up threat, MSPs are uniquely placed to offer a unified, simplified service – and in that sense, the rise of AI breaches could be a real business opportunity.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Hacking groups have the transport network firmly in their sights’: Network Rail is battling a torrent of cyber threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hacking-groups-have-the-transport-network-firmly-in-their-sights-network-rail-is-battling-a-torrent-of-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ FoI requests have revealed that the rail operator is under increasing attack, as cyber criminals set their sights on the transport sector ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RoW86jKhaGNwz8fh2EZQkX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jun 2026 11:26:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:description>                                                            <media:text><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:text>
                                <media:title type="plain"><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Network Rail is fighting off millions of cyber attacks every month, according to new research, as experts warn of a rising tide of threats facing public services. </p><p>Freedom of information (FoI) requests show the organization blocked over 7.1 million malicious emails between December 2025 and March this year.  </p><p>Of the 7,129,314 email attacks blocked by Network Rail, 331,352 were phishing emails, 1,412 were <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>-laden emails, 2,066,392 were spam emails, and 4,730,158 were edge blocked emails. </p><p>This all adds up to an average of more than 800,000 attacks per day, including around 37,000 <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attempts.</p><p>“With so many people in the UK depending on public transport for their daily lives, a successful cyber attack could cause significant disruption, such as potentially stopping people from getting to work," warned Simon Edwards, CEO of SE Labs. </p><p>"Therefore, it’s vital that our public sector organizations have a dedicated cyber strategy put in place and ensure rigorous testing to identify any security holes and keep hackers at bay.”</p><p>Just last week, two members of the hacking group known as Scattered Spider pleaded guilty over their <a href="https://www.itpro.com/security/cyber-attacks/duo-accused-of-role-in-tfl-cyber-attack-plead-guilty-after-lengthy-highly-complex-and-painstaking-investigation">involvement in an attack on Transport for London (TfL) systems</a>. </p><p>The attack forced all 28,000 employees to attend a TfL office for a password reset and led to a reported £29 million in losses and recovery costs.</p><p>"As we've seen from the recent Scattered Spider convictions, hacking groups have the transport network firmly in their sights. A single successful cyber attack on the rail network could drive Britain to a halt, operationally and economically," said Graeme Stewart, head of public sector at Check Point. </p><p>"The transport network is also a treasure trove of personal and financial data, something unscrupulous criminals are eager to get their hands on. That’s why it's vital that our roads, rail and aviation systems are fully protected with the latest cyber defenses to keep hackers locked out."</p><h2 id="what-happened-with-the-network-rail-cyber-attack">What happened with the Network Rail cyber attack?</h2><p>In 2024, Network Rail suffered a <a href="https://www.itpro.com/security/network-rail-confirms-cyber-attack-on-wi-fi-systems-at-uk-train-stations"><u>cyber attack</u></a> on its WiFi systems that saw commuters who logged in at affected stations receive information pertaining to terrorist attacks in Europe, as well as a message stating “we love you Europe”. </p><p>The attack is believed to have taken place through a third-party service provider, Telent, which managed Network Rail's WiFi services.</p><p>More recently, train operator LNER said a <a href="https://www.itpro.com/security/cyber-attacks/lner-warns-customers-to-remain-vigilant-after-personal-data-exposed-in-cyber-attack"><u>cyber attack</u></a> had led to unauthorized access to files managed by an unnamed third-party supplier.</p><p>Travel networks, particularly rail services, are among the top targets for cyber criminals and state-sponsored groups due to the critical role they play in the British economy, according to research conducted last year. </p><p>The UK's Department for Science, Innovation and Technology (DSIT) released a <a href="https://assets.publishing.service.gov.uk/media/69144f259d50fc2fe816163a/Economic_impact_of_a_systemic_cyber_incident_rail_sector_scenario.pdf" target="_blank"><u>report</u></a> from KPMG that concluded a major attack on the rail network could cost £1.8 billion for a one-week period of disruption.</p><p>The direct financial cost to Network Rail would, it concluded, cost around £123 million, with the cost to passengers due to delays adding up to about £281.3 million. </p><p>Notably, the impact on Gross Value Added (GVA) could be as much as £1.397 billion, representing approximately 2.8% of the UK’s weekly GDP and 0.05% of annual GDP.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Traditional patching cannot keep pace’: Palo Alto Networks joins IBM’s Project Lightwell in bid to shore up software security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/traditional-patching-cannot-keep-pace-palo-alto-networks-joins-ibms-project-lightwell-in-bid-to-shore-up-software-security</link>
                                                                            <description>
                            <![CDATA[ With traditional patching no longer able to keep pace with threats, the trio aims to create an automated "shield-and-fix" architecture ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Tm5jjfUJkRgmtcwkz7z5mm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K4w4RerpP3nTt753iZeCNL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 11:12:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/K4w4RerpP3nTt753iZeCNL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Palo Alto Networks logo and branding pictured on a smartphone screen with stock market growth graph lines in background.]]></media:description>                                                            <media:text><![CDATA[Palo Alto Networks logo and branding pictured on a smartphone screen with stock market growth graph lines in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Palo Alto Networks logo and branding pictured on a smartphone screen with stock market growth graph lines in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K4w4RerpP3nTt753iZeCNL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IBM and Red Hat have expanded their Project Lightwell open source security initiative to speed up patch management, bringing <a href="https://www.itpro.com/business/acquisition/palo-alto-networks-ceo-hails-the-end-of-identity-silos-as-firm-closes-cyberark-acquisition">Palo Alto Networks</a> into the fold.</p><p>The idea is to combine vulnerability intelligence, software remediation ,and network-based protections to help organizations respond more quickly to newly discovered vulnerabilities.</p><p>Palo Alto Networks will deploy a virtual patch at the network layer to block exploit attempts, while Project Lightwell follows up with software remediation for <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> software that customers can test and deploy in their environments.</p><p>"AI has compressed the window between vulnerability discovery and exploit from weeks to minutes. Traditional patching cannot keep pace," said Nikesh Arora, CEO and chairman of Palo Alto Networks. </p><p>"By collaborating with IBM and Red Hat, we are shifting the advantage back to defenders. This powerful combination allows us to neutralize threats in the network while providing uninterrupted business continuity for our global clients."</p><h2 id="how-project-lightwell-works">How Project Lightwell works</h2><p>According to the trio, the deal will provide enterprises with broader vulnerability coverage, with protection across open source software, commercial applications, <a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot">operational technology (OT)</a> environments, and connected devices. </p><p>Organizations can receive virtual patch protections before official software patches become available, helping reduce exposure while remediation is underway. When a new vulnerability is discovered, network-level protections can be deployed the same day, reducing the time from validated discovery to protection. </p><p>The companies also said that in future they plan to establish secure processes for sharing vulnerability information across participating software vendors, technology providers, and security teams. </p><p>This aims to support coordinated vulnerability disclosure, accelerate protection development, and provide anonymized telemetry on real-world exploitation attempts.</p><p>"IBM established Project Lightwell to secure the open source software foundation that enterprises rely on every day. By collaborating with Palo Alto Networks, we are extending that security from the source code directly to the network front lines," said Arvind Krishna, chairman and CEO of IBM. </p><p>"This joint solution gives our clients exactly what they need to thrive in the AI era: immediate, automated resilience against emerging threats, combined with the rigorous validation required to safely update their core systems."</p><h2 id="software-security-in-the-spotlight">Software security in the spotlight</h2><p>IBM and Red Hat <a href="https://www.itpro.com/security/ibm-and-red-hat-believe-they-have-the-answer-to-open-source-security-risks">launched Project Lightwell last month</a> with a $5 billion investment and a team of more than 20,000 engineers. </p><p>Early adopters include Bank of America, BNY, Citi, Goldman Sachs, JP Morgan Chase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa, and Wells Fargo.</p><p>The idea was to use advanced AI capabilities, offered through commercial subscriptions, to validate and test fixes across a huge volume of open source code. </p><p>While more than nine-in-ten Fortune 500 companies rely on open source software, <a href="https://www.itpro.com/software/open-source/86-percent-of-enterprise-codebases-contain-open-source-vulnerabilities"><u>Black Duck research</u></a> has indicated that 86% of codebases contain open source vulnerabilities. </p><p>Notably, 81% of those were classified as high or critical risk, up from 74% in the previous year.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are exploiting flaws faster than companies can disclose them ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hackers-are-exploiting-flaws-faster-than-companies-can-disclose-them</link>
                                                                            <description>
                            <![CDATA[ Researchers at Forescout's Vedere Labs found an IoT flaw was exploited after patch, but before public disclosure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AE3CkDhDvbVXVnXNXhgEkg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/P5BaAXwkDNyHNyRDcZNx5E-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Jun 2026 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/P5BaAXwkDNyHNyRDcZNx5E-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Red warning symbol imposed over computer code denoting a data security compromise.]]></media:description>                                                            <media:text><![CDATA[Red warning symbol imposed over computer code denoting a data security compromise.]]></media:text>
                                <media:title type="plain"><![CDATA[Red warning symbol imposed over computer code denoting a data security compromise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/P5BaAXwkDNyHNyRDcZNx5E-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are working so quickly that they're managing to exploit flaws after they’ve been patched, but before being publicly disclosed. </p><p>That's according to a <a href="https://www.itpro.com/security/ai-is-now-a-standard-part-of-the-attacker-toolkit">report from Forescout Research's Vedere Labs</a>, which spotted the pattern while analysing a flaw spotted in Lantronix devices. </p><p>Back in April, Vedere published details about a set of vulnerabilities spotted in Lantronix and Silex serial-to-IP converters. </p><p>More recently, the research lab reviewed its logs, spotting that one of the flaws had been exploited on one of its honeypots – two weeks before the blog post detailing the vulnerabilities had been posted. </p><p>"That was before we published our report but after the vulnerability was patched by Lantronix," Vedere labs noted in a blog post. "This means the attackers did not use information from our report, but may have reverse-engineered the patch to build an exploit."</p><p>The flaw in question (CVE-2025-67038) is an unauthenticated OS command injection vulnerability that affected Lantroniz EDS5000 series converters, which are built on Linux-based OpenWRT and use a web interface called LuCL. </p><p>OpenWRT and LuCL are both popular software in <a href="https://www.itpro.com/hardware/routers">routers </a>and other networking devices. </p><p>A host of vulnerabilities in both have been identified in the past, and more are being found "at an alarming rate”, the company said. </p><p>Researchers spotted more than 4,100 brute force login attempts against devices running OpenWRT in the first half of this year in addition to the attack that made use of the exploit.</p><h2 id="speedy-attacks">Speedy attacks</h2><p>Vedere Labs noted that the vulnerabilities that have public proof of concepts (PoC) are usually integrated quickly into <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnets</a>, but this instance happened before the details were published. </p><p>"It is concerning that a vulnerability on a specific serial-to-IP converter, without a public PoC and full details, was seen exploited on a random honeypot so quickly after it was fixed," the research lab said. </p><p>"Vulnerabilities with public PoCs are integrated into botnets fast, but the behavior observed from Chaya_006 was not compatible with a typical botnet or vulnerability scanner."</p><p>Vedere added that, beyond speed, it was alarming that attackers were brute forcing devices running LuCL on OpenWRT. </p><p>"We observe thousands of brute force attempts over SSH, Telnet and other standard protocols every day, but brute forcing specific parameters of a web application is less common," the post said. "It requires specialized scripts and an intent to target a specific type of device."</p><p>The attacks largely originated in Asia and made use of automation. The exploit in question was part of a wider cluster of activity that focused on Lantronix and included other information gathering activities. Vedere has dubbed it <em>Chaya_006</em>.</p><h2 id="what-should-companies-do">What should companies do? </h2><p>As ever, Vedere Labs advised companies to get patching, ensure all software is up to date, and upgrade other devices running OpenWRT on networks to the latest versions of the firmware. </p><p>The company  noted that Lantronix released two firmware updates earlier this year, and its honeypot that was exploited was not running those patches. </p><p>Beyond that, Vedere advised replacing default credentials, banning weak passwords, and monitoring for exploit attempts of serial-to-IP converters and other edge devices running OpenWRT. </p><p>"Segment networks to prevent threat actors from reaching vulnerable devices, such as serial-to-IP converters, or using them to compromise other critical assets," Vedere added. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘This operation marked a shift in strategy’: Three notorious malware networks have been taken down using RICO legislation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/this-operation-marked-a-shift-in-strategy-three-notorious-malware-networks-have-been-taken-down-using-rico-legislation</link>
                                                                            <description>
                            <![CDATA[ The action involved the use of US racketeering laws to treat two malware families as part of a single conspiracy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QqZTCnjPCtnP5zoZTXKiUS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X8SLtm2YmMKNBeG8ZeCDXf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Jun 2026 09:38:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X8SLtm2YmMKNBeG8ZeCDXf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Europol logo and badge pictured on the exterior of the Europol headquarters in The Hague, Netherlands.]]></media:description>                                                            <media:text><![CDATA[Europol logo and badge pictured on the exterior of the Europol headquarters in The Hague, Netherlands.]]></media:text>
                                <media:title type="plain"><![CDATA[Europol logo and badge pictured on the exterior of the Europol headquarters in The Hague, Netherlands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X8SLtm2YmMKNBeG8ZeCDXf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Europol has taken down the criminal networks behind the SocGholish, Amadey, and StealC malware strains as part of an operation involving Microsoft and a host of security firms. </p><p>The latest move in <a href="https://www.itpro.com/security/ransomware/its-been-a-bad-week-for-ransomware-operators">Operation Endgame</a>, the action saw 326 servers and 142 domains neutralized, as well as 27 million compromised data sets recovered. More than €41 million in criminal crypto assets were seized, the agency revealed.</p><p>"By taking down these tools simultaneously, the collaboration between law enforcement and private parties has increased friction for cyber criminals, making it harder for attacks to succeed, spread, or recover," said Europol.</p><p>"This operation marked a shift in strategy: instead of focusing solely on individual threats, Europol, law enforcement and judicial authorities, as well as private industry partners disrupted the entire chain that allows cyber attacks to scale."</p><p>In the first two weeks of May alone, more than 140,000 PCs globally were infected with one of the three cybercrime as a service malware strains, which were used as a tool for the initial infection of targeted systems.  </p><p>SocGholish, a so-called dropper/loader, helped criminals gain access to computer systems by distributing fake browser updates via compromised websites. This works by hacking websites built with WordPress and infecting them with malware for digital extortion.</p><p>The <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>strain is linked to the Russian cyber criminal group <a href="https://www.itpro.com/security/cyber-crime/nca-sanctions-members-of-evil-corp-cybercrime-gang">Evil Corp</a>, the group behind the Zeus and Dridex malware and associated with several large‑scale ransomware and money laundering operations. </p><p>StealC, a stealer with dropper function, was spread in a variety of ways, and is designed to extract sensitive information such as passwords, stored access data, and digital identities from compromised computers for data trading and fraudulent use.</p><p>Meanwhile, the Amadey dropper/loader is spread mostly through phishing campaigns, introducing extra malware into compromised systems and retrieving sensitive data.</p><h2 id="rico-legislation-used-in-amadey-stealic-takedowns">RICO legislation used in Amadey, StealIC takedowns</h2><p>Amadey and StealC were targeted by Microsoft’s Digital Crimes Unit (DCU) as a pair, thanks to their interconnected roles – although they were developed by separate cyber criminals, they relied on the same infrastructure. </p><p>Both were shut down through a mix of court orders, domain seizures, registrations, and provider notifications. </p><p>This action involved a broader use of the Racketeer Influenced and Corrupt Organizations Act (RICO), a US law designed to target organized crime.</p><p>Steven Masada, assistant general counsel in Microsoft’s Digital Crimes Unit, said investigators relied on <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a>, particularly <a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-copilot-review-ai-baked-into-your-apps">Copilot</a>, as part of the operation, using the technology to analyze malware strains.  </p><p>"That helped surface key details, uncover hidden data, and test findings in a fraction of the time, turning what would have taken hours or days into minutes and enabling the team to spot connections faster," he said.</p><p>"Those insights allowed the legal team to treat both malware families as part of a single conspiracy. Instead of going after each tool separately, as we have done in the past, we used RICO to charge multiple complicit enablers involved across the operation."</p><p>The action against SocGholis involved cleaning infected WordPress sites and notifying victims, urging them to update their platforms and strengthen login credentials.</p><p>WordPress users are being encouraged to change their login credentials, enable multi‑factor authentication, delete any unknown additional WordPress accounts and keep their WordPress site up to date in the future.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ With jobs on the line, CEOs now demand cyber attack recovery in hours, not days or weeks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/with-jobs-on-the-line-ceos-now-demand-cyber-attack-recovery-in-hours-not-days-or-weeks</link>
                                                                            <description>
                            <![CDATA[ Recovery takes most organizations weeks or months, CEOs think it should be far quicker ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gQgwC7C5oZBVMzLBZfPRTB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AqvGjJr2CmPpQRrUk8S7z5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Jun 2026 10:26:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AqvGjJr2CmPpQRrUk8S7z5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Male and female cybersecurity specialists collaborating in an open plan office space, looking at screen during cyber attack recovery program.]]></media:description>                                                            <media:text><![CDATA[Male and female cybersecurity specialists collaborating in an open plan office space, looking at screen during cyber attack recovery program.]]></media:text>
                                <media:title type="plain"><![CDATA[Male and female cybersecurity specialists collaborating in an open plan office space, looking at screen during cyber attack recovery program.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AqvGjJr2CmPpQRrUk8S7z5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK CEOs are placing huge demands on security professionals, with most now expecting to be notified of a cyber attack within half an hour – they even want basic operations back up and running within a day.</p><p>That’s according to new research from Cohesity, which found two-third expect to be notified within 30 minutes, and 19% within just five. </p><p>Meanwhile, 14% think they should have basic business operations restored within an hour and 38% within a day; only 11% thought a week was reasonable. </p><p>These high expectations are placing significant pressure on <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>teams, the study noted, but the figures do track with the UK government’s recent <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026" target="_blank"><u>Cyber security breaches survey</u></a>.</p><p>The report noted that the “vast majority” of businesses (87%) reported being able to restore their operations within just 24 hours. </p><p>“More than seven-in-ten businesses (72%) and charities (76%) said it took ‘no time at all’ to recover,” the report said. </p><p>Some are taking a more conservative approach to long-term recovery timelines, however. Around 15% said they expect to be fully operational in the wake of an attack within a few weeks. </p><h2 id="who-s-responsible-for-cyber-attack-recovery">Who’s responsible for cyber attack recovery?</h2><p>Crucially, the Cohesity report found executives aren’t aligned on who should be notifying them about a breach and managing the recovery. A quarter told researchers that it should be the security advisory board, with 21% citing the CTO and the same number the CISO.</p><p>The same pattern appears when CEOs are asked who decides what gets restored first in order to resume basic business operations. </p><p>Responsibility is spread across the entire board, at 23%, the CTO at 21%, the CEO personally at 20%, and the security advisory board at 14%. </p><p>“CEOs are signaling that cyber incidents now come with performance consequences. With expectations this high, organizations need a clear chain of command in place, so decisions are made quickly and confidently,” said Fraser Hutchison, VP UKI at Cohesity.</p><p>“Cyber attack recovery is now a board-level issue. CEOs expect to restore basic business operations fast, but many organizations still haven’t defined who alerts leadership, who decides what ‘minimum viable’ means, or what gets restored first."</p><p>Hutchison warned that without a “clear plan agreed in advance”, critical decisions can be “contested in the heat of the moment”. This, the report noted, ultimately slows down recovery. </p><h2 id="ai-throws-a-spanner-in-the-works">AI throws a spanner in the works</h2><p>Decisions around recovery are being made more difficult by the fractured state of <a href="https://www.itpro.com/technology/artificial-intelligence/organizations-face-ticking-timebomb-over-ai-governance">AI governance</a> across large UK businesses, according to Cohesity, with <a href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">ownership of AI security</a> distributed across as many as five different executive roles. </p><p>Four-in-ten survey respondents said the CTO was responsible for AI cybersecurity, followed by the <a href="https://www.itpro.com/business/business-strategy/why-the-ciso-role-is-so-demanding-and-how-leaders-can-help">CISO </a>(31%), <a href="https://www.itpro.com/business/leadership/why-people-management-skills-are-key-to-being-a-cio">CIO </a>(29%), CSO (26%), and <a href="https://www.itpro.com/technology/artificial-intelligence/does-your-business-need-a-chief-ai-officer">CAIO </a>(22%). Researchers said this means that in many organizations, multiple executives hold a partial stake in AI security with no single owner. </p><p>Meanwhile, the person responsible for restoring AI systems after an attack is often not the same person who governs them day to day: the CIO leads on AI policy at 30% of businesses, while the CTO leads AI cybersecurity at 41%. </p><p>A further 20% of businesses have had to create an entirely new role to own AI policy at all, and 11% have no owner or are unsure.</p><p>“<a href="https://www.itpro.com/technology/artificial-intelligence">AI </a>is accelerating how organizations run, and it’s raising expectations for speed everywhere including recovery from a cyber attack. But speed without clear ownership, and confidence in what you’re restoring can turn a cyber incident into a prolonged business crisis,” said James Blake, Cohesity global vice president of cyber resilience and consultancy strategy. </p><p>"The organizations that recover best are the ones that define Minimum Viable Company upfront, assign clear decision rights, and rehearse recovery as an operational discipline, not just a technical process."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Three quarters of firms have halted AI projects over safety and security concerns – and cyber pros think things will deteriorate as models like Claude Mythos improve ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/three-quarters-of-firms-have-halted-ai-projects-over-safety-and-security-concerns-and-cyber-pros-think-things-will-deteriorate-as-models-like-claude-mythos-improve</link>
                                                                            <description>
                            <![CDATA[ AI has become a leading problem for enterprise security teams, they can't automate their way out of trouble ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7PbH4iWL5JStoNxAD8jncF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/A2eUMwBBjVbDZpzbyz9BrQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Jun 2026 07:35:51 +0000</pubDate>                                                                                                                                <updated>Wed, 24 Jun 2026 09:51:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/A2eUMwBBjVbDZpzbyz9BrQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI security concept image showing a digitized padlock symbol with &#039;AI&#039; symbol, connected to data points with multi-colored data flows emanating from each point.]]></media:description>                                                            <media:text><![CDATA[AI security concept image showing a digitized padlock symbol with &#039;AI&#039; symbol, connected to data points with multi-colored data flows emanating from each point.]]></media:text>
                                <media:title type="plain"><![CDATA[AI security concept image showing a digitized padlock symbol with &#039;AI&#039; symbol, connected to data points with multi-colored data flows emanating from each point.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/A2eUMwBBjVbDZpzbyz9BrQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Three quarters of companies have had to halt AI projects because of safety and security concerns over the last year, and systems like Claude Mythos are only going to make security teams' jobs harder. </p><p>That's according to a pair of surveys by Aikido and CybaVerse, which highlighted that AI is clearly becoming a security problem – a fact echoed by <a href="https://www.itpro.com/security/five-eyes-agencies-sound-alarm-over-risky-agentic-ai-deployments">Five Eyes</a> cybersecurity agencies warning that leaders need to act now to <a href="https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now" target="_blank">stay ahead of AI-related security risks</a>.</p><p>"Adversaries are already using AI to move faster and more effectively. Defenders must do the same," said the UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre</a> in a <a href="https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now" target="_blank"><u>blog post</u></a>. </p><p>Rolling out AI to solve the challenges of AI may not prove a simple solution, however. A survey from Aikido Security found that 76% of organizations polled had to stop, restrict, or <a href="https://www.itpro.com/technology/artificial-intelligence/the-ai-rollback-nobody-wants-to-talk-about">roll back AI projects</a> over the last year. </p><p>That figure rises to 98% for more active teams that are shipping multiple times a day. </p><p>The report found that seven-in-ten companies had a security issue that was harder to detect, investigate, or remediate because of AI, which again rose to 86% for daily shippers.</p><p>According to Aikido, the key challenge here lies in velocity. AI has accelerated the pace of development, meaning security teams have less time to spot flaws — and more arrive by the time the first round can be fixed.</p><p>Notably, the survey found that three quarters of those polled are rolling out significant production changes weekly – or faster – but only two-in-ten are validating security at that rate. </p><p>Because of that, nearly eight-in-ten are concerned about vulnerabilities being introduced between tests and half say test findings are outdated by the time they see them. </p><h2 id="rising-ai-security-concerns">Rising AI security concerns</h2><p>It's perhaps no surprise then that nine-in-ten security professionals see the rise of security-focused models such as <a href="https://www.itpro.com/technology/artificial-intelligence/project-glasswing-anthropic-announces-big-tech-consortium-to-test-claude-mythos-ai-model-that-could-reshape-cybersecurity">Anthropic's Claude Mythos</a> as increasing cyber risk for companies</p><p>According to a survey by CybaVerse, 86% of polled cyber pros believe AI systems like Mythos will cut the time it takes for hackers to spot and exploit flaws, leading to more patching. More than two-thirds said their employer lacks the budget to address that increased workload. </p><p>“Advanced AI platforms were blasted into the public domain and organizations had no time to prepare for the impact they would have on their cyber defences," said Oliver Spence, CEO of CybaVerse. </p><p>"Now that some of the largest technology companies in the world have access to these platforms, we are already seeing an increase in the volume of vulnerabilities being identified and disclosed, with the latest Patch Tuesday being the largest on record."</p><p>Looking ahead, security professionals aren't optimistic that AI will make the situation better. Indeed, three quarters believe an advanced AI system will eventually be weaponized by cyber criminals. </p><p>"This is something organizations must be prepared for because bulletproof security doesn’t exist," said Spence. </p><h2 id="back-to-basics">Back to basics</h2><p>Spence added that core defense techniques haven't changed, even if AI has accelerated the <a href="https://www.itpro.com/security/brace-yourselves-for-a-vulnerability-explosion-forescout-warns">pace of vulnerability discovery</a>. </p><p>"Security teams still need visibility of their assets, they still need strong vulnerability management processes and they still need to prioritise remediation efforts based on risk," he said. </p><p>"Advanced AI may change the speed and scale of cyber threats, but the organizations that maintain strong <a href="https://www.itpro.com/security/cyber-requirements-stress-perspective">cyber hygiene</a> and focus on reducing exposure to their most significant risks will always be in the strongest position to defend themselves,” added Spence.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘They risk damaging confidence’: A Canadian health board outraged staff with phishing tests offering paid leave – experts say it shows why you need to be careful with cyber awareness campaigns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/they-risk-damaging-confidence-a-canadian-health-board-outraged-staff-with-phishing-tests-offering-paid-leave-experts-say-shows-why-you-need-to-be-careful-with-cyber-awareness-campaigns</link>
                                                                            <description>
                            <![CDATA[ Phishing tests require a delicate touch, emulating realism while not “exploiting goodwill” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LfUaaa5ELrjpAENwf6HrXn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iDKidsDKjf2VvPGKQeUDaC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2026 15:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iDKidsDKjf2VvPGKQeUDaC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing a red-colored email symbol with a hook placed through it dangling over a laptop computer.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing a red-colored email symbol with a hook placed through it dangling over a laptop computer.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing a red-colored email symbol with a hook placed through it dangling over a laptop computer.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iDKidsDKjf2VvPGKQeUDaC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have urged organizations to take a more considerate approach to cyber awareness training after a Canadian health board sent emails to staff offering paid leave as part of a phishing test. </p><p>Ron Johnson, interim chief executive at Newfoundland and Labrador Health Services, apologized for the phishing test last week, admitting the emails were sent in poor taste. </p><p>“We acknowledge the approach taken in this particular exercise was not appropriate, and we sincerely apologize to employees, physicians, and union representatives,” he <a href="https://nlhealthservices.ca/news/nl-health-services-apologizes-for-the-recent-cybersecurity-awareness-exercise/" target="_blank"><u>wrote</u></a>. </p><p>The <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>simulation prompted backlash after being circulated to hundreds of employees, and has since prompted a review of future activities, Johnson added. </p><p>“We value the feedback and are reviewing how future awareness exercises are developed and communication,” he said. </p><p>“It is important they reflect employee and physician perspectives, as well as our organizational values to foster a respectful and supportive workplace culture.”</p><p>This isn’t the first time an organization has been forced into a U-turn after a controversial phishing test campaign. </p><p>As <em>ITPro </em>reported in late 2024, the University of California Santa Cruz (UCSC) was heavily criticized for a “tone deaf” campaign <a href="https://www.itpro.com/security/how-not-to-conduct-cyber-awareness-training-ucsc-slammed-for-tone-deaf-ebola-phishing-tests"><u>which used a fake Ebola virus track and trace alert</u></a>. </p><p>The campaign caused a panic on campus and was highly convincing, even employing links to a fake webpage set up to support those affected by the “outbreak”. </p><h2 id="phishing-tests-are-a-vital-part-of-cyber-hygiene">Phishing tests are a vital part of cyber hygiene</h2><p>While this particular incident sparked ire among employees, phishing tests are a common practice by cybersecurity professionals to ensure staff remain vigilant to potential security threats. </p><p>Phishing attacks, in particular, are a leading cause of breaches at organizations across a range of industries – and the healthcare sector specifically is a prime target for cyber criminals. </p><p><a href="https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-202">Add AI into the equation</a>, and the threat landscape faced by enterprises today is becoming increasingly perilous, with threat actors using the technology to refine techniques and curate highly convincing emails. </p><p>Rob Anderson, head of reactive consulting services at Reliance Cyber, told <em>ITPro </em>that the “best phishing exercises are realistic” – after all, they are intended to emulate the tactics used by cyber criminals. </p><p>"They should use the same sneaky tactics that threat actors may use, hopefully triggering the trained, instinctive suspicion we want staff to develop when handling unexpected emails,” he said. </p><p>“However, there is a fine line. Nobody likes to be made a fool of, especially at sensitive times.”</p><p>Anderson pointed to a phishing exercise by one UK police force’s Information Protection Unit, which circulated emails targeting staff in a typical fashion. Those who fell foul were met with a message stating: “whoops, you’ve failed this training”. </p><p>In this instance, Anderson said the Information Protection Unit had “failed to read the room”. </p><p>“A week earlier, the force had announced a restructure, with likely compulsory redundancies and transfers,” he said. “Police officers can be a vocal and cynical bunch, and they made their feelings known.”</p><h2 id="a-delicate-balancing-act">A delicate balancing act</h2><p>It’s here that phishing tests often become a delicate balancing act, according to Simon McNalley, identity and access management (IAM) technical director at Thales. </p><p>Ultimately, <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>professionals need to ensure that simulations are “realistic enough to reflect the tactics attackers use” without “exploiting goodwill”. </p><p>“Scenarios involving pay, bonuses, annual leave, personal hardship, or other highly sensitive employment matters should be approached with caution, as they risk damaging confidence in legitimate internal communications,” he told <em>ITPro</em>. </p><p>Anderson echoed McNally’s comments, adding that human resources (HR), communications, and senior leadership should be consulted before campaigns go live.</p><p>Ultimately, McNally said the NL Health Services incident should serve as an example to other organizations hoping to keep staff on their guard in light of rising threats. </p><p>“There is a place for phishing simulations as part of building cyber awareness, especially as attackers routinely use such techniques. However, it’s vital that these exercises do not come at the expense of trust between employer and employee. Trust is a critical component of security culture,” he said. </p><p>“If awareness programs leave employees feeling misled, embarrassed or manipulated, organizations risk undermining the very behaviors they are trying to encourage.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI expands 'Daybreak' cyber program: New tools, partnerships, and a cyber-focused GPT-5.5 aim to help 'patch the world' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/openai-expands-daybreak-cyber-program-new-tools-partnerships-and-a-cyber-focused-gpt-5-5-aim-to-help-patch-the-world</link>
                                                                            <description>
                            <![CDATA[ The company has added new tools, signed up partners, and released its GPT-5.5-Cyber model more widely ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BbkgBGvb3RovuGi3CbQM9n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8aKDCf5QfKuUVFmUBc3Fgf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2026 11:38:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8aKDCf5QfKuUVFmUBc3Fgf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close-up image of OpenAI logo and branding displayed on a smartphone screen. ]]></media:description>                                                            <media:text><![CDATA[Close-up image of OpenAI logo and branding displayed on a smartphone screen. ]]></media:text>
                                <media:title type="plain"><![CDATA[Close-up image of OpenAI logo and branding displayed on a smartphone screen. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8aKDCf5QfKuUVFmUBc3Fgf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has expanded its Daybreak cybersecurity initiative to cover fixing vulnerabilities, not just identifying them.</p><p>The AI developer has introduced a series of new tools, and signed up a host of partners to lead the scheme, including Accenture, Check Point, Cisco, CrowdStrike, IBM, and more. </p><p>"<a href="https://www.itpro.com/security/brace-yourselves-for-a-vulnerability-explosion-forescout-warns">Vulnerability reports</a>, on their own, do not protect anyone. The value comes from validating the issue, understanding its impact, developing and testing a patch, coordinating disclosure, and helping teams deploy the fix," said the firm. </p><p>"We are investing alongside our partners to improve these latter steps, in order to turbocharge defenders and convert model capability into real-world risk reduction."</p><p>OpenAI said it has tweaked models to discover and generate patches for critical vulnerabilities⁠ in major browsers, network infrastructure, and operating systems such as FreeBSD and the Linux kernel. </p><p>To scale the effectiveness of these capabilities, it's launching an update to the Codex Security plugin⁠. </p><p>This aims to speed up the process of discovering and patching vulnerabilities in existing systems, as well as automatically preventing new vulnerabilities from ever reaching production.</p><h2 id="openai-touts-gpt-5-5-cyber-capabilities">OpenAI touts GPT-5.5-Cyber capabilities</h2><p>Notably - and following an initial permissive-only preview - OpenAI confirmed plans to launch the full version of GPT‑5.5‑Cyber through a continued limited release.</p><p>The company is also working with researchers, maintainers, enterprises, and partners for its Patch the Planet⁠ initiative, founded with Trail of Bits to help widely used open source projects move from findings to fixes. </p><p>More than 30 open source projects have committed to participate so far, including:</p><ul><li>cURL</li><li>Go</li><li>Python</li><li>Sigstore</li><li>pyca/cryptography</li></ul><h2 id="openai-leans-on-partners">OpenAI leans on partners</h2><p>Elsewhere, the new OpenAI Daybreak Cyber Partner Program ⁠allows participating organizations to use GPT‑5.5 with Trusted Access for Cyber in the security products and services they provide. </p><p>This, the firm said, allows their customers to get the benefits of the model’s defensive capabilities and make their software more resilient, but still keeps direct model access in the hands of participating partners. </p><p>“Organizations are looking for practical ways to apply AI to strengthen cyber defence while maintaining strong governance and safety controls,” said Ryan Kalember, chief strategy officer at Proofpoint.</p><p>“By incorporating GPT-5.5 through the OpenAI Cyber Partner Program into Proofpoint’s products, services, and AI-powered security workflows, we can help security teams improve threat investigation, decision-making, and efficiency as they protect their people, data, and AI agents."</p><h2 id="government-engagement">Government engagement</h2><p>OpenAI said it's also been working with government bodies in Australia, Canada, France, Germany, Japan, the Republic of Korea and the EU, on cyber testing, evaluation, and standards. </p><p>"We also have a growing and trusted partnership with the UK government around cyber testing and evaluation, and other areas of mutual interest," said the firm.</p><p>"We plan to work directly with eligible operators of critical infrastructure, including government networks, to develop safeguards tailored to the systems they operate."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Duo accused of role in TfL cyber attack plead guilty after ‘lengthy, highly complex, and painstaking investigation’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/duo-accused-of-role-in-tfl-cyber-attack-plead-guilty-after-lengthy-highly-complex-and-painstaking-investigation</link>
                                                                            <description>
                            <![CDATA[ Around 10 million people are believed to have been affected by the TfL cyber attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">99isQzP3Ggse8NRDUNdd7i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/74qnvFg7TZirm7UfyeNWJH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2026 09:30:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Ross Kelly ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/74qnvFg7TZirm7UfyeNWJH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Commuter standing on a train at a London underground tube station, which is run by Transport for London (TfL).]]></media:description>                                                            <media:text><![CDATA[Commuter standing on a train at a London underground tube station, which is run by Transport for London (TfL).]]></media:text>
                                <media:title type="plain"><![CDATA[Commuter standing on a train at a London underground tube station, which is run by Transport for London (TfL).]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/74qnvFg7TZirm7UfyeNWJH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two young men have pleaded guilty to offenses under the Computer Misuse Act following a <a href="https://www.itpro.com/technology/artificial-intelligence/true-scale-of-tfl-cyber-attack-emerges-what-happened-who-was-responsible-and-how-many-people-were-impacted">cyber attack on Transport for London (TfL)</a> that caused months of disruption and millions in damages. </p><p>Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall in the West Midlands, were arrested following raids by the National Crime Agency (NCA) and City of London Police in September 2025.</p><p>The duo are alleged members of the notorious Scattered Spider cyber crime collective, believed to be responsible for a string of attacks in recent years. The group claimed responsibility for attacks on UK retailers <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack">Marks & Spencer</a> and the <a href="https://www.itpro.com/security/cyber-attacks/co-op-chief-executive-very-proud-of-cyber-attack-response-despite-huge-financial-losses">Cooperative Group</a>, as well as <a href="https://www.itpro.com/security/cyber-attacks/mgm-resorts-back-online-after-suspected-ransomware-attack">MGM Resorts</a> in the United States. </p><p>“The profile of offenders like Flowers and Jubair demonstrates the increasing threat from cyber criminals based in the UK and other English-speaking countries, epitomised by Scattered Spider," said Paul Foster, deputy director of the National Crime Agency and head of the NCA National Cyber Crime Unit.</p><p>Flowers was first arrested in September 2024, at which point NCA officers found evidence that the networks of US healthcare companies SSM Health Care Corporation and Sutter Health had also been infiltrated and damaged.</p><p>Investigators found a number of devices at Flowers' home, including laptops, tower computers, hard drives, and USB sticks. One Acer laptop contained a screenshot showing network connectivity to TfL infrastructure. </p><p>Flowers had also accessed an online platform selling credentials compromised in previous cyber attacks and data breaches. </p><p>Notably, the laptop contained a number of videos that Flowers had recorded, which showed Jubair accessing TfL systems during the attack. At the same time, the pair were messaging each other over Telegram, as well as communicating via an online work collaboration tool.</p><h2 id="what-happened-with-the-tfl-cyber-attack">What happened with the TfL cyber attack?</h2><p>TfL’s network was infiltrated at the beginning of September 2024, forcing all 28,000 employees to attend a TfL office for a password reset. The cyber attack caused widespread disruption for the rail operator. </p><p>Data from TfL’s Oyster refunds system was accessed while its customer refund system was also affected. Elsewhere, the attack shut down the Oyster photocard application system for children and young people. </p><p>Around 10 million people are believed to have been affected by the attack, making it one of the UK’s most devastating cyber attacks to date. </p><p>Jubair and Flowers are due to be sentenced at Woolwich Crown Court on 16 July.</p><h2 id="a-lengthy-investigation">A lengthy investigation</h2><p>Foster said the trial is the culmination of a “lengthy, highly complex and painstaking investigation” and hailed law enforcement colleagues for their role in apprehending the duo. </p><p>“The perseverance and meticulousness of our officers, and the work of our partner organizations, meant that Jubair and Flowers had no option other than to plead guilty and take responsibility for their offending," he commented.</p><p>“Cyber crime may appear faceless and distant compared to other crime types, but the infiltration of TfL’s systems shows it has real-world consequences and impacts hugely on the public. The attack caused millions of pounds in losses to a key part of the UK’s critical national infrastructure, and was a significant inconvenience for customers."</p><p>The NCA is urging victims of cyber crime to use the government’s Cyber Incident Signposting Site for direction on which agencies they should report incidents to.</p><p>“Today’s result would not have been possible if TfL had not engaged with law enforcement early, so I would urge any other organization to please do the same in such circumstances," said Foster.</p><h2 id="the-rise-of-youth-hackers">The rise of youth hackers</h2><p>Upon their arrest in September 2025, Jubair and Flowers were both teenagers, prompting concerns about a <a href="https://www.itpro.com/security/cyber-crime/the-rise-of-teen-hackers-makes-for-a-good-headline-but-cyber-crime-activities-peak-later-in-life"><u>potential wave of youth-related cyber crime</u></a>. As <a href="https://www.itpro.com/security/channel-their-curiosity-into-something-meaningful-cyber-expert-warns-an-uptick-of-youth-hackers-should-be-a-wake-up-call-after-teens-charged-over-tfl-attack"><u><em>ITPro </em></u><u>reported at the time</u></a>, cybersecurity experts described the incident as a “wake up call” for law enforcement, educators, and society at large. </p><p>Anna Chung, principal researcher for EMEA at Palo Alto Networks, said these incidents highlight a failure to “properly engage a generation growing up in a digital-first world”. </p><p>“Young people don’t usually turn to online mischief out of malice - it’s often down to a mixture of boredom, technical skills, and a lack of boundaries,” she told <em>ITPro </em>at the time.</p><p>So what’s the solution? Chung urged schools and parents to make a concerted effort toward teaching digital ethics, making this a “part of core education”. This, she noted, could be crucial to preventing future incidents. </p><p>Chung’s warning over teen hackers is by no means the first, or likely last, that we’ll hear about in coming years. </p><p>Indeed, the UK’s <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> published a report last year which <a href="https://www.itpro.com/security/kids-hacking-for-kicks-are-causing-security-headaches-at-schools"><u>highlighted a spate of cybersecurity incidents at schools across the country</u></a>, with students bypassing network security controls and gaining access to management systems. </p><p>Nipping these types of activities in the bud are crucial, the ICO warned, largely as they have the potential to evolve into more nefarious activities. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why MSSPs need to focus on reducing cyber risk, not adding complexity ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/why-mssps-need-to-focus-on-reducing-cyber-risk-not-adding-complexity</link>
                                                                            <description>
                            <![CDATA[ The channel also has a role to play in helping organizations adopt AI-enabled security capabilities responsibly ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KvFdCgZ5XRhUMDQrXGeVuT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aXognGP4UVUiWoAxxh57qJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Martin Lethbridge ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/XM4r95nttuwGG3G7EMvBHC.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aXognGP4UVUiWoAxxh57qJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand touching a glowing white padlock in a dark environment, to represent living off the land cyber attacks.]]></media:description>                                                            <media:text><![CDATA[A hand touching a glowing white padlock in a dark environment, to represent living off the land cyber attacks.]]></media:text>
                                <media:title type="plain"><![CDATA[A hand touching a glowing white padlock in a dark environment, to represent living off the land cyber attacks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aXognGP4UVUiWoAxxh57qJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity spending is increasing, yet many organizations still experience breaches, operational disruption, and ongoing security challenges. </p><p>As businesses expand their digital environments and adopt new technologies such as AI, many are also finding that their larger security budgets are not translating into stronger protection.</p><p>For managed security service providers (MSSPs) and channel partners, this is an important opportunity. Many customers are looking for support that goes beyond simply deploying additional security products. They want a partner who can help them manage cyber risk more effectively, while also helping them operate in a complex security environment.</p><p>This shift in customer priorities is even more visible as organizations are managing increasingly fragmented IT environments. Hybrid working, cloud adoption, remote endpoints, and connected applications have all expanded attack surfaces considerably over the past few years. In addition, many businesses have accumulated multiple security tools across different parts of the organization, often from different vendors and with varying levels of integration.</p><h2 id="too-many-tools">Too many tools</h2><p>Although each tool may exist to address a specific security requirement, the overall result is difficult to manage. Security and IT teams may need to monitor numerous dashboards, respond to large volumes of alerts, and manually correlate information between systems. In some environments, this will create visibility gaps and operational inefficiencies, making it harder to respond quickly to threats.</p><p>For MSSPs, this is likely to be a key focus for customers. Many organizations are reassessing whether adding more standalone tools is the most effective way to improve resilience. And there is growing interest in approaches that simplify management, improve visibility, and support measurable risk reduction.</p><p>This is particularly relevant for mid-market organizations that may not have large in-house security teams. Many smaller IT departments are being asked to manage increasingly sophisticated environments, while also responding to complex threats, regulatory requirements, and user demands. A channel partner that can reduce this operational pressure while also improving security outcomes will be able to demonstrate and deliver greater long-term value to customers.</p><p>Unsurprisingly, AI is also influencing this. Businesses are adopting AI-enabled technologies across their operations, while cybersecurity vendors are increasingly integrating AI into security tools and platforms. Cybercriminals are also using automation and AI-supported techniques to increase the scale and sophistication of phishing campaigns, social engineering, and vulnerability exploitation.</p><h2 id="keeping-safe-and-secure-but-without-spending-more">Keeping safe and secure, but without spending more</h2><p>Organizations are faced with growing pressure to improve detection and response capabilities without significantly increasing operational overhead.</p><p>For MSSPs, this creates the opportunity to help customers manage security more practically and sustainably. Rather than focusing solely on deploying additional technologies, many are positioning themselves around outcomes such as improved visibility, faster response times, and simplified security operations.</p><p>Integrated security platforms are becoming increasingly relevant in this context. Platforms that bring together endpoint protection, identity security, network monitoring, and threat detection capabilities help organizations reduce fragmentation and improve operational efficiency. By consolidating visibility and automating some routine tasks, businesses may be able to reduce alert fatigue and simplify day-to-day security management.</p><p>Automation is also playing a growing role in helping organizations manage their rising security demands. Many MSSPs are using automation to support threat detection, incident response, patch management, and policy enforcement. For customers with limited internal resources, this helps to improve consistency and reduce the burden on internal IT teams.</p><h2 id="technology-alone-is-not-the-solution">Technology alone is not the solution</h2><p>But technology on its own is unlikely to solve every security challenge. Many organizations still require support with prioritisation, governance, and practical risk management. This is where MSSPs can differentiate themselves from those providers who are focused primarily on product deployment.</p><p>Customers are increasingly evaluating cybersecurity investments based on operational effectiveness rather than simply the number of tools deployed. In some cases, this may involve consolidating overlapping products, improving configuration management, or streamlining response processes rather than introducing additional technologies.</p><p>This approach also aligns with the growing industry focus on cyber resilience. Many organizations recognize that security strategies should include detection, response, and recovery capabilities, alongside prevention. MSSPs that can help customers improve resilience and reduce operational disruption will strengthen their role as long-term strategic partners.</p><p>The channel also has an important role to play in helping organizations adopt AI-enabled security capabilities responsibly. While AI may help improve efficiency and threat analysis, it can also introduce additional management challenges if implemented without proper oversight or integration. This means customers will value partners that can help them adopt new technologies in a manageable and commercially practical way.</p><p>Organizations need to balance growing cyber risks with operational and financial pressures. As a result of this, there is likely to be increasing demand for MSSPs and channel partners that can simplify cybersecurity management while supporting stronger resilience outcomes.</p><p>This is an opportunity for the channel to move conversations away from tool proliferation and towards measurable risk reduction. The conversation with customers needs to be about helping them manage complexity, improve operational visibility, and align security more closely with business priorities.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT teams are bullish on AI tools, but they’re worried security practices can’t keep pace ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/it-teams-are-bullish-on-ai-tools-but-theyre-worried-security-practices-cant-keep-pace</link>
                                                                            <description>
                            <![CDATA[ Executives and IT teams are at odds over the risks associated with AI adoption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MccjwugkSse6xqBn5vzkeG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4CeYDBXGHtWfkgtgjJ2dUi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 14:33:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4CeYDBXGHtWfkgtgjJ2dUi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A wide angle shot of IT workers in an office, lit by large modern windows showing a business park behind them.]]></media:description>                                                            <media:text><![CDATA[A wide angle shot of IT workers in an office, lit by large modern windows showing a business park behind them.]]></media:text>
                                <media:title type="plain"><![CDATA[A wide angle shot of IT workers in an office, lit by large modern windows showing a business park behind them.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4CeYDBXGHtWfkgtgjJ2dUi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT teams are growing increasingly concerned about <a href="https://www.itpro.com/security/the-key-risks-security-teams-face-in-2026">AI-related risks</a> amidst continued adoption, according to new research. </p><p>Findings from Heimdal’s <em>State of AI Risk Management in 2026</em> report show <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> are now commonplace across most IT estates, with teams often running several at one. </p><p><a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a>, for example, runs in nearly three-quarters (71%) of UK IT environments, while <a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-copilot-review-ai-baked-into-your-apps">Microsoft Copilot</a> is present in 68%. These same figures are reflected across the Atlantic, with US-based IT teams often using a combination of multiple different AI solutions. </p><p>AI tools are playing a key role in reducing workloads, the study noted, which IT teams highlighted as the most positive benefits of the technology. </p><p>Nearly three-quarters of IT and security teams said they lose around a quarter of their week to “repetitive, low-value work” - and AI is helping reduce that manual toil. </p><p>Indeed, teams facing the highest levels of operational load are often ranked among the most optimistic when it comes to AI. More than half (59%) of US teams said they expect AI to alleviate pressure, while 55% in the UK expect the same. </p><h2 id="ai-related-risks-are-haunting-it-teams">AI-related risks are haunting IT teams</h2><p>Despite this optimism, a key recurring concern among IT leaders is that controls and security capabilities haven’t kept pace with the rate of adoption. Heimdal noted that only four-in-ten teams rate their security stack as “ready for AI-related risk”. </p><p>Teams are increasingly concerned about data leakage, for example, with 56% of UK respondents highlighting this risk. Visibility is a major issue in this regard, Heimdal found. </p><p>UK teams with full <a href="https://www.itpro.com/security/it-leaders-are-facing-major-work-device-blind-spots-and-its-putting-security-at-risk">visibility into AI use</a> were most likely to flag data leakage as a leading concern, compared to just 27% of those with no visibility. In the US, 59% of teams with full visibility also highlighted data leakage as a key concern. </p><p>While concerns over potential risks typically mount as AI tools are integrated, Heimdal noted that unauthorized AI use, or ‘shadow AI’, is also a recurring problem for enterprises. </p><p>Heimdal specifically highlighted the <a href="https://www.itpro.com/security/cyber-attacks/the-salesloft-hackers-claim-they-have-1-5-billion-compromised-salesforce-records">Salesloft Drift breach in August 2025</a> as a key example of how poor AI-related visibility can impact organisations. </p><p>The incident saw threat actors steal OAuth tokens for Drift’s AI chatbot integration with Salesforce, using these to extract data from several hundred Salesforce instances. </p><p>A host of organisations, including Cloudflare, Palo Alto Networks, and Zscaler were impacted in the attacks.</p><p>“Drift was the AI tool. Salesforce held the data,” the company noted in a <a href="https://heimdalsecurity.com/blog/state-ai-risk-management/" target="_blank"><u>blog post</u></a>.</p><p>“Most of the affected teams had never personally provisioned Drift,” it added. “A third-party AI chatbot, plugged in through an OAuth grant few had recently reviewed, became the way in.”</p><h2 id="contrasting-priorities">Contrasting priorities</h2><p>Perception of AI-related risk among frontline practitioners and executives is a major problem, according to Heimdal. Indeed, “executive confidence” in AI security is a repeated point of friction when it comes to governance and risk management. </p><p>In the US, for example, 29% of executives said AI risk is under control, yet just 7% of practitioners agreed. In the UK, meanwhile, these figures stand at 18% against 11%. </p><p>Adam Pilton, cybersecurity advisor at Heimdal, said this shows many organizations still aren’t fully aligned on how they manage AI risk. </p><p>"Misplaced confidence is one of the most dangerous things in security. This data shows executives are far more confident that AI risk is under control than the evidence supports. Most of the conversation right now is about productivity, when the bigger question is how AI can be turned against the business,” he said. </p><p>“The report shows the gap between how secure leaders feel and how secure they actually are.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Legacy kit behind vast majority of cyber attacks on utilities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/legacy-kit-behind-vast-majority-of-cyber-attacks-on-utilities</link>
                                                                            <description>
                            <![CDATA[ With equipment and software poorly suited to withstand modern cyber threats, organizations need to do more to identify unmanaged or vulnerable systems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g5wVJsihF2LFMhqkmSmkEi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BZ2z9PNptF9yx2L4peXaVE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Jun 2026 10:43:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BZ2z9PNptF9yx2L4peXaVE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close-up shot of networking routers and switches connected by neatly arranged fiber optic, twisted pair, and power cables within a data center.]]></media:description>                                                            <media:text><![CDATA[A close-up shot of networking routers and switches connected by neatly arranged fiber optic, twisted pair, and power cables within a data center.]]></media:text>
                                <media:title type="plain"><![CDATA[A close-up shot of networking routers and switches connected by neatly arranged fiber optic, twisted pair, and power cables within a data center.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BZ2z9PNptF9yx2L4peXaVE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than three-quarters of utilities organizations were hit by cyber attacks involving <a href="https://www.itpro.com/software/linux/360665/hackers-target-outdated-versions-of-linux-in-the-cloud">outdated software</a> or unavailable patches on <a href="https://www.itpro.com/business/digital-transformation/legacy-it-infrastructure-accounts-for-more-than-a-third-of-enterprise-power-consumption-and-its-creating-a-sustainability-nightmare-for-it-leaders">legacy equipment</a> over the last year.</p><p>At 77%, it was the most common type of cyber incident facing the sector, according to Bridewell's Cyber Security in Critical National Infrastructure Report 2026.</p><p>And the most common effect was IT disruption or outages, affecting 47% of organizations, despite the fact that 99% of respondents described themselves as resilient after their worst cyber attack. </p><p>A further 42% said incidents had resulted in increased <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> spending, while 35% experienced data loss, 34% reported revenue loss, and 32% suffered disruption to production or services.</p><p><a href="https://www.itpro.com/software/software-supply-chain-attacks-are-soaring-and-security-leaders-are-sluggish-to-react">Supply chain attacks</a> take the longest to respond to, at 9.9 hours on average, followed by data theft or disclosure at 8.4 hours and unauthorised access at 7.6 hours.</p><p>The utilities sector is particularly hampered by the need to secure ageing operational technology and infrastructure that weren't designed to withstand modern cyber threats, as critical assets can't be updated or taken offline as easily as traditional IT environments.</p><p> "Many of the systems underpinning essential utilities services were designed to operate for decades in environments that were never intended to be connected to modern digital networks," said Sam Thornton, COO at Bridewell. </p><p>Beyond <a href="https://www.itpro.com/infrastructure/six-reasons-it-pros-are-ditching-legacy-monitoring-tools">legacy infrastructure</a>, phishing and business email compromise remain widespread, affecting 76% of utilities organizations in the past year. Malware affected almost as many, at 74%, while more than seven-in-ten experienced unauthorized system access.</p><p>The main concern for utilities organizations is data protection and privacy, cited by 46% of survey respondents. Managing AI-related cyber risk and the ability to quickly detect incidents were close behind, reflecting growing concerns around emerging technologies and increasingly sophisticated attacks. </p><p>Utilities organizations are also unconfident when it comes to data breach notification requirements, cited by 42%, cybersecurity measures for data protection at 39%, and third-party due diligence at 38%.</p><p>And regulation is now the primary driver of cyber security maturity within the utilities sector, cited by 36% of respondents - ahead of both the evolving threat landscape and customer demand for improved security, and highlighting the growing influence of frameworks and compliance obligations on cyber security investment and decision-making.</p><p>"As utilities providers continue to modernize and connect operational systems, managing the gap between legacy infrastructure and modern security requirements is becoming one of the sector's biggest cybersecurity challenges," said Thornton.</p><p>Bridewell recommends that utilities organizations improve the visibility of assets across both IT and operational technology environments to identify unmanaged or vulnerable systems.</p><p>They should prioritize patch management and vulnerability remediation based on operational risk and criticality, conduct regular incident response exercises to ensure teams can respond effectively during a live cyber incident and strengthen monitoring and detection capabilities to reduce the time taken to identify and contain threats.</p><p>They should also review third-party and supply chain security arrangements to ensure critical partners meet appropriate security standards.</p><p>"In the utilities sector, the consequences of a cyber attack extend far beyond IT," said Thornton. "When critical systems are disrupted, the impact can be felt by customers, communities and the wider economy, making cyber resilience a business-critical priority."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Passwords nicked for nearly 74,000 Fortinet devices ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/passwords-nicked-for-nearly-74-000-fortinet-devices</link>
                                                                            <description>
                            <![CDATA[ Check if your Fortinet firewall has been compromised, companies advised ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KFCGzBMpsRrNKG6uEDPfAk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8WicetKM8qsxz6o2LVDMxn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Jun 2026 06:59:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8WicetKM8qsxz6o2LVDMxn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Fortinet logo and branding displayed on a smartphone with second logo in background in white lettering on red ]]></media:description>                                                            <media:text><![CDATA[Fortinet logo and branding displayed on a smartphone with second logo in background in white lettering on red ]]></media:text>
                                <media:title type="plain"><![CDATA[Fortinet logo and branding displayed on a smartphone with second logo in background in white lettering on red ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8WicetKM8qsxz6o2LVDMxn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tens of thousands of Fortinet devices may have leaked credentials after a sophisticated automated brute force campaign that has security researchers calling for affected companies to reset their passwords now. </p><p>Threat intelligence company Hudson Rock posted a blog detailing what it's named Fortibleed, saying 73,932 firewall devices had seen credentials leaked, impacting a long list of organisations – if yours is on the <a href="https://www.hudsonrock.com/fortinet">list</a>, change your passwords now. </p><p>In a statement sent to <em>ITPRO</em>, Fortinet disputed the details, saying this wasn't the result of a fresh hack and that anyone following best practices was already safe. "Fortinet is aware of a reported third-party credential-harvesting campaign targeting Fortinet firewalls and <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368117/best-enterprise-vpn-of-2022">VPN</a> gateways. We are committed to safeguarding our customers, and we diligently and continuously monitor threat actor darknet activity. Based on our initial analysis, the data involved is likely a resharing of data from previous incidents, as well as brute forcing of credentials, and not related to any current incident or advisory."</p><p>Hudson Rock argued the incident isn't that simple – and claimed it's impacting a huge number of companies. </p><p>"The group's methodology goes beyond simple credential reuse," the blog post notes. "They actively intercept SSL VPN authentication hashes and crack them using a massive, dedicated 45-GPU cluster managed via Hashtopolis. Once the perimeter is breached, the operators systematically pivot directly into internal Active Directory environments to establish deep network persistence."</p><p>The techniques aside, it's the size of the incident that's worrying, Hudson Rock said. "The scale of this breach touches nearly every sector of the global economy, sparing no industry," the blog post added. "The threat actors have built a verified database of working credentials for some of the largest enterprises on the planet."</p><h2 id="what-s-happening">What's happening?</h2><p>The reporting on this incident started with a <a href="https://www.linkedin.com/feed/update/urn:li:share:7471222470814072832/">post</a> by security researcher Volodymyr Diachenko, who spotted the mass exploitation in action last week, noting tens of thousands of companies' names were listed. </p><p>"Crooks use sophisticated hashcracking approach to get then plaintext passwords from the Fortigate configs and use them consequently in the internal network movement and takeover," he said at the time. </p><p>Another security researcher, Kevin Beaumont, then examined the incident. He said the data appeared to be legitimate and that 75,000 devices were impacted, with most still online and the majority from Fortinet. Beaumont said he had worked with some of the companies and could confirm the data. </p><p>"The data comprises of roughly 50% of all Fortinet firewall devices facing the internet, based on polling from Shodan," he noted.</p><p>The data could allow attackers to log in remotely and access the <a href="https://www.itpro.com/security/firewalls/355328/how-to-build-your-own-firewall-with-pfsense">firewall </a>and network it was protecting, Beaumont said. "They can also change settings, including security controls, and make backdoor users," he <a href="https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8">wrote</a>. </p><h2 id="what-can-companies-do">What can companies do? </h2><p>Fortinet said its customers following best practices and recent advice should be safe. "Organizations that follow routine best practices, including regularly rotating security credentials and enabling multi-factor authentication, as per guidance in this March <a href="https://www.fortinet.com/blog/industry-trends/attacks-at-the-speed-of-ai">blog</a>, face minimal risk from credential compromise detail referenced in the reporting."</p><p>Beaumont advised companies to check if they were affected via the Hudson Rock list, and if so, immediately rotate all admin credentials, looking at prior logins for suspicious activity. But he said to "assume compromise" as it's unclear how long the data seen has been in circulation. </p><p>If found to be compromised, the entire device may need to be replaced as settings may have been altered allowing for a backdoor to be installed, Beaumont added. Devices should be upgraded to the latest FortiOS version, and admins should login to change passwords. Generally, he advised the FortiOS management interface to not be exposed to the internet unless strictly necessary, and to implement multi-factor authentication. </p><p>Hudson Rock echoed that advice, adding that companies should monitor for stolen credentials to spot them before they're weaponised against your network. </p><p>Hudson Rock added that one "alarming detail" from the breach was how many complex passwords were successfully compromised, noting that IT departments lean on rigid password rules in a bid for protection. "However, complexity is completely neutralized when passwords are recovered in plaintext," the company noted. </p><p>Hudson Rock added: "This massive incident serves as a glaring reminder that exposed network gateways combined with reused or stolen credentials are an attacker's dream."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>