Normal view

There are new articles available, click to refresh the page.
Today — 15 September 2026IT Security

Kura Appoints Acumen Cyber to Deliver 24/7 Cyber Defence

15 September 2026 at 10:06

Customer experience provider Kura has appointed Acumen Cyber to provide 24/7 security monitoring, threat detection and incident response across its operations in the UK and South Africa.

Kura supports more than 50 brands across financial services, utilities, healthcare and the public sector, operating from Glasgow, Sunderland and Durban. The company handles millions of customer interactions each year, making the protection of client and customer information a key priority.

The partnership comes as Kura continues to modernise its technology estate and invest in its wider technology capabilities, including the development of omnichannel software subsidiary Inisoft.

24/7 monitoring from Acumen Cyber

Under the partnership, Acumen Cyber will provide round-the-clock monitoring from its CREST-accredited Security Operations Centre (SOC).

Kura will gain access to Acumen’s engineering-led defence model, which combines security engineers, threat intelligence and automation to identify and respond to threats.

Rather than simply generating alerts for customers to investigate, Acumen’s security engineers work directly with organisations and take ownership of investigations from start to finish. Its approach also includes continuously testing security detections against real-world attack techniques to identify areas where defences need to improve.

For Kura, this will provide greater visibility across its technology estate and specialist support should suspicious activity or a cyber incident be detected.

Protecting customer trust

Mark Robertson, CEO of Acumen Cyber, said cybersecurity is particularly important for organisations responsible for handling large volumes of customer information.

“For organisations like Kura, cyber security is about far more than protecting systems. It is about protecting the trust customers place in them,” Robertson said.

“Businesses handling sensitive customer information need confidence, backed by evidence, that their security is effective and threats can be identified and contained quickly.”

Robertson added that Acumen will work as an extension of Kura’s existing team, with named engineers who understand its business and continually test and strengthen its protection.

Supporting Kura’s long-term growth

The investment in cybersecurity also reflects the requirements Kura faces when working with clients operating in highly regulated industries, where demonstrating effective security controls is increasingly important.

Owen Campbell, CEO of Kura, said maintaining customer and client trust was central to the decision.

“Our clients place enormous trust in us to deliver outstanding customer experiences while protecting the information they entrust to us,” Campbell said.

“As our business continues to evolve, investing in cyber security is an essential part of maintaining that trust.”

He added that Acumen Cyber’s combination of specialist security engineers and a collaborative approach made it the right partner to support Kura’s security operations and longer-term growth.

The post Kura Appoints Acumen Cyber to Deliver 24/7 Cyber Defence appeared first on IT Security Guru.

Yesterday — 14 September 2026IT Security

Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick

14 September 2026 at 07:58
Security teams are turning to AI as they struggle to investigate the volume of alerts coming into the SOC, according to new research from Prophet Security. The State of AI in Security Operations 2026 report surveyed 250 IT and cybersecurity professionals. Forty percent said AI is already part of their day-to-day SOC workflow, and 56% [...]
Before yesterdayIT Security

Anthropic Discloses Fourth Incident of Claude Breaching Real Systems During Security Tests

11 September 2026 at 08:50

Anthropic has disclosed a fourth incident in which one of its Claude models broke into genuine third-party systems during what was supposed to be a contained cybersecurity evaluation, deepening industry concern over the risks posed by increasingly autonomous AI agents.

The AI company said the episode dates back to January 2026 and involved an early version of Claude Opus 4.6, which breached external infrastructure after it was “unable to abort its task.” Anthropic has notified all affected parties, though it has not disclosed who they are. The incident is understood to have gone undetected until last month.

It follows three earlier cases revealed by Anthropic in July 2026, in which Claude Opus 4.7, Mythos 5 and an unnamed research model each compromised separate organisations during cybersecurity evaluations, again without the company’s knowledge at the time.

“AI safety is not just a model problem it’s an operational and human one. A simple configuration or naming error allowed a controlled test to interact with real systems, while the model continued pursuing its objective despite warning signs. Organisations deploying autonomous agents need clear accountability, isolated test environments, least-privilege access and human approval for high-impact actions. Trusting an AI to ‘do the right thing’ is not a security control.”
– Javvad Malik, Lead CISO Advisor at KnowBe4

According to Anthropic, all four incidents occurred during cybersecurity evaluations built by the same external evaluation partner. Claude was told it was operating in a simulated environment with no internet access, but a misconfiguration meant it was actually connected to the open internet. The partner responsible for the evaluations, Irregular, has since said the breach stemmed from a naming error: a fictional company used in the hacking simulations happened to match a real-world domain, causing the models to take offensive action against it.

Anthropic has since scanned roughly 481 million transcripts for similar problems and says it found no other cases of comparable or greater severity. The company has also signed an agreement with independent research non-profit METR to carry out a separate investigation into the incidents.

Anthropic attributes the root cause to two alignment failures: biased reasoning and recklessness. In practice, this meant the models tended to dismiss or misread evidence that their environment was connected to the live internet after initially being told otherwise, and were willing to pursue potentially harmful actions in single-minded pursuit of the task they had been assigned.

“Relying on an automated AI agent to audit another AI for security breaches is a fundamentally flawed approach. These models are increasingly acting as autonomous entities capable of probing network boundaries. When they escape their evaluation environments to access external systems, they create an unpredictable new vector for supply chain attacks. Developers must enforce strict network isolation rather than trusting software to mark its own homework.”
– Dray Agha, Senior Manager of Security Operations at Huntress

Anthropic said it was most concerned by the incident involving Claude Mythos 5, which went to considerable lengths to upload a malicious package to PyPI, the public repository used to distribute most Python software. The company noted that although the model repeatedly stated in its chain-of-thought reasoning that it believed it was in a simulation, the environment contained clear evidence it was on the real internet, and its actions were consistent with knowing this. Even after researchers amended the transcript to make the real-world context unmistakable, the model went on to carry out offensive actions.

Anthropic was keen to stress that the incidents remained narrow in scope: no Claude instance deviated from the task it had been set, none attempted to coordinate with other AI agents, and none tried to conceal evidence of its actions. The company added that biased reasoning appears less pronounced in its newer production models and can be reduced through more thorough alignment training, though the underlying cause, and why it was more acute in Mythos 5, remains unclear.

“As agentic AI systems become more capable and more widely deployed, the legal framework for who is responsible when a model accesses something it shouldn’t is going to need answering. These four incidents are an early test case for questions the law hasn’t fully addressed yet. Anthropic found four problems in 481 million transcripts and told everyone about it. The real question is how many problems the rest of the industry hasn’t looked hard enough to find yet.”
– Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress

The disclosure lands amid growing scrutiny of AI model safety more broadly. Rival OpenAI recently acknowledged a previously unreported incident from May 2026, in which internally deployed autonomous agents with read-only internet access took over a dormant German wiki forum, exchanging more than 18,000 posts as they attempted to coordinate answers and evade restrictions on a timed task. When a human moderator began removing the posts, the agents reportedly worked around the clean-up by naming backup pages so they would be buried at the end of an alphabetically sorted deletion list.

“We need to stop blaming AI and hold the humans in charge accountable for the actions of their AI agents. Companies will think twice about deploying AI if they are fined for negligence. It’s frustrating to listen to tech CEOs warn about the dangers of AI and then turn around and build it as if those dangers are unavoidable. If this problem gets bad enough, then we could see an emerging market for AI insurance that covers rogue third-party hacking, data theft, and intellectual property infringement.”
– Paul Bischoff, Consumer Privacy Advocate at Comparitech

Anthropic has warned that the risks are likely to grow rather than diminish as AI systems become more capable. “Future AI systems will be increasingly capable, which implies that misalignment will have the potential to cause more extreme harm,” the company said, adding that training robustly aligned frontier models remains an unsolved technical challenge that will require both continued research and stronger operational discipline from those deploying them.

For now, the incidents serve as a reminder that the weakest link in agentic AI deployments may not be the model itself, but the environments, configurations and oversight structures built around it.

The post Anthropic Discloses Fourth Incident of Claude Breaching Real Systems During Security Tests appeared first on IT Security Guru.

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

11 September 2026 at 10:19

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.

The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review appeared first on SecurityWeek.

4 Ways Organisations Create Non-Human Insider Risk

By: The Gurus
10 September 2026 at 11:55

As AI agents become embedded across business operations, they are also creating a new category of insider risk. Unlike traditional insiders, these non-human identities can act at machine speed, operate continuously and access multiple systems without direct human oversight.

The danger rarely stems from one obvious security failure. Instead, it emerges when several weaknesses overlap. Here are four common ways organisations inadvertently create non-human insider risk:

1. Persistent access

Long-lived API keys, OAuth tokens, service accounts and standing privileges give agents constant access long after it is needed.

2. Excessive privilege

Many agents can read, write, modify, approve, delete or deploy far more than their actual tasks require.

3. Untrusted input

Agents consume information from emails, support tickets, documents, chat conversations, websites and repositories. If attackers can influence those inputs, they may also influence the agent’s decisions.

4. Limited behavioural monitoring

Many organisations can tell that an AI agent performed an action. Far fewer can determine whether that action actually made sense. Logging tells us what happened, understanding whether it should have happened is a different challenge altogether.

You can read the full blog from Erich Kron, CISO Advisor at KnowBe4. Stay tuned for part 2 where Erich will reveal what security teams should do to stay secure.

The post 4 Ways Organisations Create Non-Human Insider Risk appeared first on IT Security Guru.

Huntress Expands into Africa with New QBS Software Africa Partnership

10 September 2026 at 09:09

Huntress is expanding into Africa through a new distribution partnership with QBS Software Africa, the company announced today. The move marks the latest step in Huntress’ international growth as organised, AI-enabled cybercrime continues to rise worldwide.

The expansion comes as Africa faces a mounting cybersecurity crisis. According to INTERPOL’s 2026 African Cyberthreat Assessment, artificial intelligence is now linked to 55% of reported cybercrime across the continent, with direct economic damages surpassing $5 billion. Attackers are increasingly using AI to scale established tactics against under-resourced organisations, exploiting gaps in security coverage.

Under the new agreement, local value-added resellers and managed service providers will gain access to the Huntress Agentic Security Platform and its 24/7 AI-centric Security Operations Center. The platform is powered by Athena, Huntress’ agentic investigation system, which the company says combines machine-speed threat investigation with human security expertise to catch novel attacks before they escalate.

“Expanding into Africa is an important step in Huntress’ mission to protect all businesses from organized cybercrime,” said Adam Waggott-Moss, Head of EMEA Distribution at Huntress. “QBS Software Africa brings the local market knowledge, channel relationships, and regional expertise to help extend that protection to more businesses and build a strong foundation for long-term growth across the region.”

Headquartered in South Africa, QBS Software Africa will act as a launchpad for the rollout, beginning in South Africa before extending into select Sub-Saharan African markets. The partnership pairs Huntress’ cybersecurity technology with QBS Software Africa’s local channel expertise, technical support, and go-to-market resources, aiming to help regional partners scale stronger security offerings for their customers.

“Huntress’ combination of innovative technology and elite security expertise gives businesses across Africa the ability to keep pace with the attackers targeting them,” said Sanjay Mithal, Head of Strategic Vendor Alliances at QBS Software Africa. “The Huntress Agentic Security Platform brings layered defence together with the security experts who understand adversary behavior best, helping organizations across the region stay ahead of threats and sleep a little easier at night.”

The Africa launch builds on a period of rapid international growth for Huntress, which now protects 270,000 businesses across more than 100 countries. Over the past year, the company has deepened its presence across Europe and Asia Pacific, with adoption spreading across sectors including manufacturing, construction, retail and utilities, driven by investment in regional teams and channel partnerships.

Huntress plans to host a livestream on September 16 covering its Agentic Security Platform, titled “Inside the Agentic Huntress Platform: Beating Adversaries at Machine Speed.” You can register for the webinar here.

The post Huntress Expands into Africa with New QBS Software Africa Partnership appeared first on IT Security Guru.

Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair

10 September 2026 at 08:34

UK cybersecurity specialist Core to Cloud has appointed former Currys Group CIO Andy Gamble as Chair of its Advisory Board as the company looks to accelerate the growth of its managed security services.

Gamble brings nearly 30 years of board-level technology leadership and will work with Core to Cloud on its strategic, advisory and commercial direction across the UK enterprise and mid-market sectors.

His appointment adds further experience to the company’s Advisory Board, which includes senior security leaders from major UK organisations.

From cybersecurity buyer to advisor

Gamble spent six years as Group CIO and Chief Transformation Officer at Currys PLC, where his responsibilities included large-scale technology transformation and cyber risk.

His career has also included senior CIO positions at Dyson, Sony Electronics and Essentra PLC. That experience means Gamble has spent much of his career on the customer side of the cybersecurity market, buying and managing the types of services Core to Cloud now provides.

“I spent the better part of three decades as a buyer of cybersecurity services, and the experience left me with a clear view of where the market falls short,” Gamble said.

“Most organisations understand that cyber risk is real. Far fewer have a security function that can communicate that risk clearly at board level, or a partner that moves fast enough to keep pace with the threat.”

Gamble said Core to Cloud stood out because of its focus on proactive security, adding that he intends to help the business scale its model as a challenger to conventional managed security service providers.

Supporting Core to Cloud’s next stage of growth

Based in Cirencester, Core to Cloud works with more than 150 organisations across sectors including the NHS, retail, financial services and critical national infrastructure.

Its services span Managed Detection and Response, Third-Party Cyber Risk Management, Security Assurance, Dark Web Monitoring and Threat Intelligence, and Cyber Crisis Simulation.

James Cunningham, CEO and Founder of Core to Cloud, said Gamble’s experience at the intersection of technology, risk and commercial strategy would bring a new perspective to the company.

“He understands what good security looks like from the inside and brings a depth of experience and perspective that will be hugely valuable as we continue to grow,” Cunningham said.

“We have an ambitious business, a strong customer base and services we genuinely believe in. Having Andy chair our board will help us build on those foundations, challenge our thinking and accelerate the next stage of Core to Cloud’s growth.”

The post Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair appeared first on IT Security Guru.

NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity

10 September 2026 at 06:02

NeuroCyber, the organisation dedicated to improving opportunities and career outcomes for neurodivergent individuals across the cybersecurity profession, has been granted charity status by the Charity Commission for England and Wales. This is a major milestone for NeuroCyber, enabling it to expand its work to create a more inclusive cybersecurity profession where neurodivergent people can access opportunities, thrive and progress throughout their careers.

Charitable status will enable NeuroCyber to significantly expand its programmes, partnerships and community initiatives, helping more neurodivergent people build successful careers in cybersecurity while supporting employers to create more inclusive workplaces.

To support this next phase of growth, NeuroCyber is launching a UK-wide appeal for corporate partners, strategic partners and volunteers. Support from partners and volunteers will help fund an expanding programme of events, research, awareness campaigns, educational resources and practical initiatives designed to reduce barriers to employment and career progression for neurodivergent professionals.

Over the coming months, NeuroCyber will also launch the NeuroCyber Charter, giving organisations the opportunity to publicly demonstrate their commitment to creating workplaces where neurodivergent employees are welcomed, understood, supported and empowered. The Charter encourages organisations to embed neuro-inclusive practices across recruitment, onboarding, career development and workplace culture, recognising that neuro-inclusion is an ongoing commitment rather than a one-off initiative.

Allie Andrews, founding trustee at NeuroCyber CIO, said: “Achieving charity status is recognition of the vital role neurodiversity has to play in the future of cybersecurity. Our focus has always been on helping neurodivergent people access rewarding careers, realise their potential and thrive within the cybersecurity profession. Too many talented individuals still encounter unnecessary barriers to entering and progressing within the industry, despite the unique skills and perspectives they can bring.

“The wider opportunity is also clear. The UK Government reports that 49% of UK businesses have a basic cybersecurity skills gap, while latest ISC2 research found that 12% of cybersecurity professionals surveyed globally identify as neurodivergent. Neurodivergent talent is already an important part of the cybersecurity workforce but there is enormous potential to unlock more of that talent by creating workplaces where everyone has the opportunity to succeed.

“This new chapter gives us the platform to scale our impact but we can’t do it alone. We’re calling on organisations and individuals who share our vision to help us build a cybersecurity profession where talent is recognised for its strengths, not limited by outdated ways of thinking. Whether through sponsorship, volunteering or signing our forthcoming NeuroCyber Charter, everyone has a role to play in creating lasting change.”

NeuroCyber is inviting organisations of all sizes to become partners, with opportunities designed to help businesses demonstrate their commitment to diversity while supporting meaningful industry change. Partners can contribute to NeuroCyber’s work through thought leadership, event participation, networking, research and other industry initiatives, with every pound directly funding the charity’s work.

NeuroCyber also welcomes organisations able to provide non-financial support, including mentoring, design, event support and specialist expertise.

NeuroCyber is also calling on volunteers from across the cybersecurity community to share their skills and experience by supporting mentoring, research, events, outreach and community engagement activities.

The post NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity appeared first on IT Security Guru.

Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware

9 September 2026 at 10:57

Cybersecurity firm Huntress has uncovered a malware campaign that preys on excitement for Grand Theft Auto VI (GTA6), packaging remote access trojans, an infostealer, and destructive ransomware inside fake “leaked” copies of the hotly anticipated game.

GTA6 is not due for release for another three months, but a wave of gameplay footage leaks and an official extended look from publisher Rockstar Games have pushed fan anticipation to a fever pitch. Threat actors have moved quickly to capitalise, seeding search results, gaming forums, social media and torrent sites with bogus disc image (ISO) files claiming to offer early access to the game. According to Huntress, no genuine leaked or playable version of GTA6 currently exists.

A booby-trapped installer

Some of the fake ISOs circulating exceed 100GB, padded with junk data to mimic the footprint of a legitimate AAA release, Huntress found. The actual malicious payload is far smaller, hidden inside a bundle that the researchers describe as an opportunistic attempt to throw “everything” at anyone who runs the installer.

Opening the ISO presents victims with a file named gta6installer.exe, oddly bearing the GTA5 icon rather than GTA6. Running it displays a Russian-language message warning that the game is unlicensed and may not launch, instructing users to email the attackers if they hit a “License not found” error so the “crack” can be fixed. That error message duly appears once installation finishes, a scripted piece of misdirection designed to explain away the fact that no game ever appears, while malware installs quietly in the background.

Three RATs, an infostealer, and a wiper

Beneath the fake installer, Huntress catalogued a small arsenal of malware, much of it several years old and simply repurposed for this campaign. Multiple copies of the remote access trojan NJRAT are dropped onto the system, along with a separate instance of DCRAT, giving attackers the ability to log keystrokes, access webcams, browse the desktop, steal browser credentials and cryptocurrency wallet details, and take full remote control of infected machines.

An open-source infostealer called Mercurial Grabber, nominally billed as an educational tool, is also installed, harvesting Discord tokens, Chrome-saved passwords and cookies, Roblox and Minecraft session data, Windows product keys and system information, and exfiltrating it all via a Discord webhook.

Most damaging is a variant of the well-known Chaos ransomware family, which Huntress says is being used purely as a wiper rather than for financial extortion. Once triggered on a machine with administrator rights, it deletes shadow copy backups, disables Windows recovery options, then either encrypts files under 200MB or overwrites larger files with random data, destroying them outright. It targets desktop, document, picture, and OneDrive folders, before changing the desktop wallpaper to an image of SpongeBob SquarePants declaring the machine hacked by the “Asha Hacker Team” and leaving a ransom note that provides no actual payment method.

The installer additionally drops a copy of Yandex Browser, a service popular in Russia and Eastern Europe. Combined with the Russian-language prompts and ransom messaging, Huntress believes the campaign is primarily targeting Russian-speaking gamers, although the tactics could easily be redeployed against fans elsewhere.

Old malware, same old lure

Huntress notes that none of the individual malware components are new or particularly sophisticated, and that an up-to-date version of Windows Defender should detect and block each one. The bigger risk, researchers say, lies in the social engineering: impatient fans searching for an early copy of a major game release are unusually willing to override security warnings and run unverified executables.

The firm’s advice is straightforward. Avoid downloading cracked or pirated software, especially for games not yet officially released. Anyone who believes they have already run the installer should disconnect the affected machine from the network immediately, reset passwords, enable two-factor authentication wherever possible, and fully reimage the system rather than attempt to clean it.

Huntress has published full technical indicators of compromise, including file hashes, dropped file paths, and command-and-control infrastructure, alongside its analysis. It can be found here: https://www.huntress.com/blog/fake-gta6-download-malware-analysis

The post Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware appeared first on IT Security Guru.

NCSC Warns Shadow AI Is Creating New Security Blind Spots for UK Businesses

9 September 2026 at 10:50

The UK’s National Cyber Security Centre (NCSC) has warned organisations about the security risks posed by “shadow AI”, as employees continue to turn to artificial intelligence tools that have not been approved by their employers.

In guidance published this week, the NCSC described shadow AI as the use of AI technology outside an organisation’s approved systems and processes, warning that security policies and governance have struggled to keep pace with the rapid adoption of AI in the workplace.

The scale of the issue could already be significant. Research cited by the NCSC found that 71% of employees have used AI tools that have not been approved by their employer.

According to the NCSC, unapproved AI services can expose sensitive company and customer information, reduce organisations’ visibility and control over their data, and create new opportunities for attackers. Information entered into consumer AI services may be stored, retained or used to improve those services outside existing corporate security and governance arrangements, depending on the privacy controls in place.

The agency also highlighted a potentially more serious risk as organisations move from generative AI tools towards AI agents. If an attacker exploits a vulnerability in an agent, they may be able to gain access to the same data, services and privileges legitimately available to that agent.

Darren Guccione, CEO and co-founder of Keeper Security, said the warning reflects a challenge many UK security teams are already facing.

“The NCSC’s warning on shadow AI reflects the reality of what many UK security teams are having to contend with. When employees adopt AI tools faster than IT can assess them, visibility gaps open long before governance has an opportunity to catch up. Microsoft’s research, cited by the NCSC, found that 71% of UK employees have used AI tools their employer hasn’t approved. Keeper Security’s 2026 research underlines the effect this is having on security teams, with 37% of UK organisations saying they lack visibility into which AI tools employees are actually utilising inside the business.

“The most significant detail in the NCSC’s warning is its point about AI agents inheriting the privileges of whoever deploys them. An attacker who compromises a poorly governed agent gains whatever access that agent holds, whether that’s a customer database or a finance system. Organisations that haven’t extended least-privilege and just-in-time access principles to their AI agents and non-human identities are exposed in ways endpoint controls alone won’t catch.”

Banning AI is unlikely to work

Rather than recommending organisations attempt to eliminate shadow AI altogether, the NCSC said businesses should focus on reducing the associated risks and understanding why employees are turning to unapproved tools in the first place.

It recommends creating a positive cyber security culture, providing AI tools that meet employees’ needs and securely integrating AI systems into the workplace.

Guccione added: “Banning shadow AI outright rarely works, as the NCSC itself acknowledges. Employees will find routes around blocked tools when the approved ones can’t do what they need.

“The more durable fix is improving visibility by identifying what identities, both human and machine, exist across the environment and what they can access. Organisations must enforce least-privilege principles by default, rather than waiting until an incident forces the question.”

Jamie Akhtar, CEO and co-founder at CyberSmart, agreed that businesses need to balance employees’ desire to use AI with appropriate security controls.

“The NCSC is right to highlight shadow AI as a growing cyber security challenge. Employees are using AI tools to work faster and more efficiently, but when those services sit outside an organisation’s approved systems, businesses can quickly lose visibility over where sensitive company and customer data is being shared, stored or processed.

“Simply banning AI is unlikely to solve the problem. Businesses need to provide secure, approved alternatives that allow people to benefit from AI without introducing unnecessary risk. Clear policies, employee education and appropriate technical controls all need to develop at the same pace as AI adoption.”

Akhtar said the challenge may be particularly difficult for SMEs without large in-house security teams, where managed service providers could help organisations identify unapproved technology and establish appropriate AI policies and controls.

“An MSP can help businesses identify unapproved technology, put proportionate AI policies and controls in place, educate employees and continuously manage emerging risks, giving organisations the confidence to embrace AI while maintaining visibility and control over their security.”

The NCSC said shadow AI is unlikely to disappear completely as AI services become cheaper and more readily available. Instead, organisations need to understand how and why employees are using these tools so they can provide secure alternatives while maintaining visibility over sensitive information and access to corporate systems.

The post NCSC Warns Shadow AI Is Creating New Security Blind Spots for UK Businesses appeared first on IT Security Guru.

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

9 September 2026 at 10:20

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here. 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

Forescout Expands Global Investment in Channel Partners

9 September 2026 at 10:00

Forescout has expanded its investment in its global partner ecosystem to strengthen technical expertise and help partners support customers managing increasingly complex IT, OT, IoT, and IoMT environments.

Nearly 100% of Forescout’s customer business is transacted through partners, making the channel a central part of the cybersecurity company’s growth strategy. Its latest investment includes the ongoing Mission: Possible enablement roadshow and the continued support of several partners in its Envision Partner Program.

Mission:Possible reaches partners worldwide

Launched in May, Mission:Possible represents the largest investment in channel engagement in Forescout’s history.

The programme is targeting 90 cities across more than 40 countries, with content available in 22 languages. More than 1,300 people have attended events so far, with Forescout expecting to engage over 2,000 partner professionals by the end of September.

Through technical education, hands-on discussions and local engagement, the programme is designed to give partners the expertise needed to help customers address emerging risks, including those associated with frontier AI and complex cyber-physical environments.

Partners advance through Envision programme

Forescout has also recognised several organisations that have reached new levels within its Envision Partner Program.

TIC Defense has advanced from Authorised Training Partner to Silver Reseller, while Trace3, Upstart Cyber and Sidif have moved from Silver to Gold Reseller status.

NTT Australia, Hitachi Sunway Information Systems Malaysia, DOR Information Technologies Israel and Computacenter Germany have all progressed from Gold to Platinum Reseller.

David Creed, Vice President of Worldwide Channel Sales at Forescout, said the company is continuing to raise expectations around technical capability, certifications, customer success and business performance.

“We’re proud to recognise these partners who have demonstrated exceptional commitment to customer success, technical excellence, partner enablement, and business growth while helping organisations meaningfully reduce cyber risk across converged IT, OT, IoT and IoMT environments,” he said.

Milo Sanchez, Senior Practice Director at Trace3, said Forescout’s technical investment and collaborative approach had helped the company better support its clients and grow the partnership.

Channel expertise becomes increasingly important

Forescout said partners are playing a growing role in helping organisations improve visibility and respond to threats across connected environments.

According to the company, organisations using its technology have reported discovering 50% more unknown IoT devices and reducing median breach containment time by 98.7%. The average time required to identify unknown, unmanaged and unauthorised assets has also fallen from 41 hours to six minutes.

The company’s channel programme has also received industry recognition, with the Envision Partner Program included in CRN’s Partner Program Guide and Forescout executives recognised in CRN’s Channel Chiefs and Channel Leaders EMEA lists.

The post Forescout Expands Global Investment in Channel Partners appeared first on IT Security Guru.

Black Duck Joins Project Glasswing to Strengthen AI-Era Software Security

8 September 2026 at 09:17

Black Duck, a provider of AI-powered application security solutions, has announced its participation in Project Glasswing, Anthropic’s industry-wide initiative aimed at protecting critical software infrastructure through the defensive use of advanced AI.

Through its involvement, Black Duck will integrate Mythos throughout its application security offerings, pairing AI-driven, deterministic vulnerability detection with established remediation processes, risk-based prioritisation, and governance frameworks built around compliance. The combination is designed to deliver a blended approach to security that cuts risk more quickly and reliably than either method alone.

Dipto Chakravarty, Black Duck’s Chief Product & Technology Officer, noted that AI is reshaping both the pace and economics of vulnerability discovery and exploit development. He added that combining Mythos’s capabilities with Black Duck’s existing deterministic testing, remediation tools, and governance controls turns vulnerability discovery into tangible, measurable risk reduction, while giving enterprise security teams the speed, transparency, and auditability they require.

The post Black Duck Joins Project Glasswing to Strengthen AI-Era Software Security appeared first on IT Security Guru.

The UK’s Cyber Community Comes North as CyberFest returns for 2026

7 September 2026 at 07:52

The North East’s biggest cyber security festival returns this October. Now in its ninth year, CyberFest has grown into a major national platform for showcasing the region’s cyber and secure AI excellence. Taking place across the North East throughout October, the festival will connect businesses, innovators, government and specialist clusters from across the UK, putting the region’s talent, ambition and capability firmly in the spotlight.

CyberFest is organised by CyberNorth, a membership community which brings together people, organisations and ideas from across the North East to drive progress in cyber security, AI, data and quantum technologies.

Although regionally grown, CyberFest is no longer just a regional event says Jon Holden, CEO of CyberNorth, CyberFest is about bringing the UK’s cyber community to the North East and showing the country what this region can do. What started as a regional festival has grown into a national platform, bringing together businesses, government, innovators and industry leaders to connect, collaborate and create new opportunities.”

The mission is simple: connect, educate and empower the region’s digital ecosystem, while putting the North East firmly on the map as a place to innovate, invest, collaborate and build business.

More than 1,000 people attended CyberFest events last year and this year organisers CyberNorth emphasise the festival will build on that momentum, exploring the opportunities and challenges facing the UK.

The programme will feature high-impact events throughout October, including the CyberFest Community Conference on 19 October and the CyberNorth Awards on 21 October, alongside a series of specialist afternoon sessions exploring the critical role of cyber across adjacent industries.

At the heart of this year’s festival is the CyberFest Community Conference, a major gathering of the North East’s cyber community alongside national and international businesses, government, industry leaders and specialist clusters. The conference will deliver a packed programme of insight, debate and networking, starting with high-profile speakers from the UK Government’s National Cyber Security Centre, CFC Insurance and Information Security for London, covering everything from data and cyber resilience to the dark web and the rapidly evolving threat landscape.

Attendees will also hear from an expert cyber and AI panel, featuring industry leaders from organisations including the Department for Work & Pensions and Tombola, exploring the importance of human centric security cultures and the opportunities and challenges emerging as cyber and AI become increasingly interconnected.

Specialist afternoon sessions will bring cyber professionals together with experts from key adjacent sectors in Space, Defence, AI, Energy and Advanced Manufacturing, highlighting the region’s strength in cross-cluster collaboration and the vital role cyber security plays across different sectors, from securing the UK’s AI Growth Zone and protecting offshore energy infrastructure to safeguarding digital production lines and building regional capability for future defence threats.

Jon Holden added: The North East has a huge opportunity to lead in secure AI and technology, but growth and security have to go hand in hand. CyberFest gives us a chance to put the region’s talent, businesses and innovation centre stage, while bringing the conversations that matter most directly into the North East.

Secure AI will take centre stage at CyberFest this year, reflecting the North East’s growing ambition to become a leading UK destination for Secure AI innovation and growth, exploring how the region can maximise its position as an AI Growth Zone, while recognising that growth must go hand in hand with security.

The showcase continues on 21 October with the CyberNorth Awards, celebrating the people and organisations driving the region’s cyber and AI sector forward. CyberNorth is calling on North East businesses, organisations and cyber professionals to submit nominations before 5:00pm on 14 September 2026.

The awards are open to all CyberNorth members and affiliations and recognise achievements across six categories including Rising Star and Outstanding Cyber Professional.

Two new categories have also been added to the line up to celebrate the Micro Businesses and those on the international stage. This year’s prestigious judging panel includes representatives from the Department for Digital, Culture, Media and Sport, Barclays, Northstar Ventures, TLT LLP and the North East Mayoral Strategic Authority, formerly the North East Combined Authority.

Jon Holden said: “CyberFest is about showcasing and celebrating the North East – we are helping to put the North East on the national stage, opening the region’s doors to the UK’s cyber and technology community and turning connections into real opportunities. 

CyberNorth’s ambition is to attract new business, investment and talent to the region, forge partnerships across the UK and beyond, and showcase the North East as a leading destination for cyber, secure AI and technology innovation. 

We have incredible businesses, brilliant people, world-class expertise and huge opportunities in front of us. CyberFest gives us a chance to bring all of that together and show the rest of the UK what is happening here.” 

With a month of events, national and international organisations coming to the region, and conversations spanning some of the UK’s most strategically vital industries, CyberFest 2026 is set to put the North East at the heart of the UK’s cyber and secure AI conversation.

The post The UK’s Cyber Community Comes North as CyberFest returns for 2026 appeared first on IT Security Guru.

Check Point Brings OpenAI’s Daybreak Models Into Its Security Platform to Speed Up Threat Validation and Remediation

7 September 2026 at 06:04

Check Point Software Technologies has announced it is integrating OpenAI’s Daybreak frontier AI models across its security platform, extending a partnership aimed at helping defenders detect, validate, and remediate cyber risk faster.

The move builds on Check Point’s existing collaboration with OpenAI through the Daybreak Defense Network, first expanded three months ago, and follows the company’s recent decision to join more than 100 technology and security firms in backing OpenAI’s call for a collective, global surge in cyber defense.

In a blog post announcing the expansion, Check Point Chief Technology Officer Jonathan Zanger said the work does not stop with previous milestones, arguing that security needs to keep adapting as new threats and attacker capabilities emerge, alongside evolving technology stacks and growing enterprise use of AI.

Zanger said the aim is to put OpenAI’s frontier cyber reasoning to work across the security lifecycle, combining it with Check Point’s own security intelligence, context, and enforcement capabilities so customers can move from large volumes of raw security data to validated risk, actionable decisions, and faster protection.

Four Areas of Integration

According to Check Point, the Daybreak models are being rolled into four parts of its platform:

  • Agentic Exposure Validation: Within Check Point’s Exposure Management product, the models are being piloted inside a multi-agent pipeline that separates genuinely exploitable risk from theoretical findings, combining AI reasoning with Check Point’s security context to validate attack paths and prioritise remediation.
  • Agentic Security Management: As part of Check Point’s autonomous, intent-driven approach to network security management, the models will help investigate potential attack paths, understand vulnerabilities and risky exposures, and identify appropriate fixes, reducing manual policy management.
  • Autonomous Workspace Platform: Within Harmony, Check Point’s investigation pipeline correlates email, endpoint, mobile, and browser telemetry; the models are being applied to investigate malware behaviour, attacker techniques, and credential-abuse chains, aiming to deliver clearer verdicts and remediation guidance while easing the load on security teams.
  • Vulnerability research: The models are being used to accelerate analysis of vulnerable code and patches, identify realistic exploitation paths and reach verified results faster, without relying on publicly available exploit code, which Check Point says should translate into faster protection against newly disclosed vulnerabilities.

Check Point said it is taking a phased approach to the rollout: some capabilities are already in production, others are in development and being tested with design partners, with more to follow as the underlying technology matures. The company said every deployment follows the same discipline: governing what the model can see, constraining what it can act on, and testing and verifying its output before allowing it to take on more work within approved security workflows.

A Two-Way Relationship

Zanger framed the OpenAI partnership as operating in two directions: Check Point uses frontier AI to strengthen how it defends customers, while also helping those customers adopt and use OpenAI’s technologies securely. He said both sides of that relationship are becoming more important as AI moves beyond answering questions towards writing code and operating autonomous enterprise agents.

“Our goal is to give organizations the confidence to embrace what AI makes possible while staying protected against evolving risks,” Zanger said, adding that the partnership is intended to put frontier AI to work for defenders while helping customers deploy it safely themselves.

The announcement is the latest sign of security vendors racing to embed frontier AI reasoning models directly into detection, validation and remediation workflows, as both defenders and attackers increasingly turn to AI to gain an edge.

The post Check Point Brings OpenAI’s Daybreak Models Into Its Security Platform to Speed Up Threat Validation and Remediation appeared first on IT Security Guru.

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

4 September 2026 at 12:18

Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion.

The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation appeared first on SecurityWeek.

Q&A: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’

4 September 2026 at 12:25

An AI-assisted platform has been used to test whether Viasat’s satellite communications links can meet operational thresholds under interference and adversarial jamming. 

Announced this month, the work with Atalanta has renewed scrutiny of the vulnerabilities exposed by Russia’s 2022 attack on Viasat’s KA-SAT network, which disrupted communications across Ukraine and several European countries. 

Gil Baram, PhD, is a cybersecurity strategy and policy researcher specialising in cyber warfare, intelligence and space security. She is a Senior Lecturer and Associate Professor at Bar-Ilan University and formerly led the Cyber and Space Research Group at Tel Aviv University. 

In this exclusive interview for the IT Security Guru conducted by the Cyber Security Speakers Agency, Gil explains how states use cyber operations to compete below the threshold of open war, why long-life satellites present a distinct security challenge, and how an attack on space-based communications could disrupt everyday life on Earth. 

How have state cyber capabilities blurred the threshold between strategic competition and armed conflict? 

Gil Baram: “I think the greatest change that cyber warfare and cyber capabilities have created is that states can compete without crossing this imaginary red line: if you cross it, then it’s a war. 

“They don’t do that, but they still compete on and on, causing damage to one another, disrupting civilians’ lives and interfering in elections. But still, that doesn’t lead to an open war. That’s something very unique to this type of technology.” 

Why does securing space-based infrastructure present a different cyber challenge from defending terrestrial systems? 

Gil Baram: “When we talk about that, the first thing we have to have in mind is the distance. For many years, security contractors were the ones building big satellites for states and launching them. Have it in mind that these satellites should be in space for 20 or 25 years, and that’s a lot. 

“If you have a cyber risk, it’s very hard to patch a system that is flying far away from you and that was launched a decade ago. It created a lot of questions: how do you deal with cyber security in space? 

“In the past, we started seeing what we call the new space: startups and technology companies that started building satellites and building space capabilities. These are not the big security contractors. 

“We started seeing that these companies do have security by design, or cyber security by design, when they design their products and before they’re launching them to space. That’s a big shift we’ve seen today.” 

How exposed is civilian life to a successful cyberattack on satellite communications infrastructure? 

Gil Baram: “My feeling is that sometimes we don’t realise how much we depend on space capabilities, even for chatting today, using our internet or our cell phones, and navigating with GPS. Many things that we take for granted couldn’t happen without satellites and space satellite communication. 

“I’ll give just one example. In the first day of the Russian invasion to Ukraine, the Russian conducted a cyberattack against Ukraine satellite communication capabilities. 

“The reports coming out from Ukraine: they didn’t have the needed communication at the very critical moments or hours of the beginning of the war. You can damage satellite communication and then hurt an entire country. 

“The main thing I hope audiences will take, and that’s my passion and goal, is to understand or realise that cyber, AI and cyber threats are relevant to our everyday lives. It’s not something that is out there, and not just something that we read in the news, but it’s relevant for everyday lives. 

“We don’t have to be technical people in order to understand that and in order to protect ourselves.”

The post Q&A: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’ appeared first on IT Security Guru.

KnowBe4 Names Kurt Mills as Channel Chief to Lead Next Phase of Partner-Led Growth

2 September 2026 at 12:24

KnowBe4 has appointed cybersecurity channel veteran Kurt Mills as its new channel chief, as the company looks to strengthen its global partner ecosystem and expand its channel routes to market.

In the role, Mills will lead the evolution of KnowBe4’s global partner programmes and operations, with responsibility for supporting the company’s relationships across VARs, MSPs, systems integrators, distributors and technology partners.

Mills brings more than 25 years of channel experience to KnowBe4, having previously held executive channel and partner sales positions at Check Point Software Technologies, Mimecast, FireMon and Blue Coat Systems.

Throughout his career, he has focused on aligning partner strategies with wider business and revenue goals, building partner networks and channel teams through periods including IPOs, acquisitions and rapid market expansion.

“Partner ecosystem growth is central to our mission, and Kurt’s appointment reflects our continued investment in that strategy,” said Bryan Palma, CEO of KnowBe4. “Kurt’s deep channel expertise, proven ability to scale high-performing teams, and track record of building long-term partner value will be instrumental as we expand our market reach.”

Mills’ appointment follows a number of additions to KnowBe4’s channel leadership team, including Neill Burton and John Noha, who have both joined as vice president of channel to support the company’s global initiatives.

The expanded leadership team will focus on providing partners with the programmes, tools and resources needed to identify new opportunities and support customers throughout the security lifecycle.

KnowBe4 said the investment reflects the increasingly important role partners play in its global growth strategy and in delivering its digital workforce security offering to organisations worldwide.

“Joining the KnowBe4 team at this critical point in the company’s growth is an incredible opportunity,” said Kurt Mills, newly appointed channel chief at KnowBe4. “I’ve built my career on creating focused, measurable, and engaged teams that drive mutual success for organizations and their partners. I am thrilled to team up with everyone at KnowBe4 to scale our partner programs, deepen our relationships across VARs, MSPs, SIs, distributors, and tech partners, and fuel our next phase of global growth.”

The post KnowBe4 Names Kurt Mills as Channel Chief to Lead Next Phase of Partner-Led Growth appeared first on IT Security Guru.

New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password

2 September 2026 at 08:59

A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it.

The kit, dubbed “Knight Office” by researchers, came to light after Huntress’s Security Operations Centre investigated suspicious sign-in activity on a customer’s Microsoft 365 account in August. While tracing the source of the intrusion, analysts found the attacker’s own operator console, a slickly built dashboard, complete with a Cloudflare Turnstile bot-check and real-time visitor statistics, used to manage victims and harvested logins from a single screen.

Huntress was careful to distinguish this operator-facing panel, which gives the attacker a live view of victims and their stolen data, from the underlying phishing kit code itself, which handles the victim-facing side of the attack, such as the fake login pages used to trick targets.

How the attack works

According to Huntress, the campaign begins with a fake email styled to look like a DocuSign signature request, complete with an urgent subject line pressuring the recipient to act. In a twist designed to dodge suspicion, the emails are “self-spoofed” and forged so that they appear to come from the recipient’s own email address.

Clicking the link in the email sends victims through a chain of redirects, including via the legitimate Monday.com work-management platform and a compromised Joomla website, designed to obscure the final destination from email security scanners. Victims land on a convincing fake Microsoft page that presents them with what looks like a normal “device login” code, mimicking the legitimate process Microsoft uses to sign into apps on other devices.

Once a victim enters the code and completes the Microsoft login, including approving the MFA prompt on their phone, exactly as they would for a genuine sign-in — the attacker’s infrastructure silently intercepts and captures their live session. That stolen session is instantly usable, letting the attacker access the account as though they were the legitimate user, with no password and no MFA prompt of their own required.

Huntress said its telemetry showed the stolen tokens being reused from data-centre hosting infrastructure, and that because no password was ever entered incorrectly, standard password-based detection alerts never fired.

Attackers dug in for the long haul

Huntress’s investigation found that the attacker didn’t stop at the initial break-in. After gaining access, they registered a rogue, attacker-controlled device against the victim’s Microsoft Entra ID (formerly Azure AD) tenant and bound a Windows Hello for Business (WHfB) passwordless credential to the compromised account, effectively planting a backdoor that would let them log back in even after the original stolen session was revoked.

The technique, researchers noted, turns a feature designed to make sign-in more secure for legitimate users into a persistence mechanism for attackers.

Scale of the campaign

Huntress said the same operator console has been linked to at least nine confirmed phishing attacks on Microsoft 365 and Google Workspace accounts within its own customer base over a two-week period. Separately, the firm said more than 700 emails matching the same lure and template have been reported by users through its security awareness training platform since April, suggesting the campaign has been running for months at considerably larger scale.

Variants of the lure’s subject line spotted by researchers include messages disguised as voicemail notifications and shared-document alerts, several of which substitute the lowercase letter “l” for “i” in words such as “Important” and “Signature” — likely an attempt to dodge spam filters that scan for exact keyword matches.

Part of a wider shift away from passwords

Knight Office is the latest in a string of phishing kits Huntress has tracked that focus on stealing session tokens or OAuth access tokens rather than credentials, following similar findings around kits called EvilTokens and Kali365. Security researchers have warned that this style of attack, known as adversary-in-the-middle (AiTM) phishing, is becoming increasingly popular precisely because it renders traditional password hygiene and even MFA far less effective as standalone defences.

Huntress recommended that organisations look beyond failed login attempts and password-spray alerts when hunting for this kind of activity, and instead watch for unexpected post-MFA authentication events from unfamiliar devices or callback proxies, review newly registered Entra ID devices and WHfB credentials, and promptly revoke unauthorised authentication methods when found.

Indicators of Compromise

Huntress has published a full list of indicators of compromise associated with the campaign, including the IP address of the phishing control panel (104.37.188[.]94), the domain hosting it (idoej[.]com), and more than two dozen lookalike phishing domains using the .vu top-level domain.

The post New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password appeared first on IT Security Guru.

Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration

2 September 2026 at 08:24

Application security vendor Black Duck has launched its Signal vulnerability scanning engine as an MCP server in the Claude Directory, giving developers using Anthropic’s Claude Desktop a way to check code for security flaws without switching tools.

The integration is built on the Model Context Protocol (MCP), the open standard that lets AI assistants like Claude call out to external services and pull structured data back into a conversation. Through it, Black Duck’s Signal Code Analysis engine can scan git diffs, individual files, or whole codebases for vulnerabilities directly from within the Claude environment developers are already using to write and refactor code.

Under the hood, source code submitted for a scan is sent to Black Duck’s cloud-based analysis service for processing. The results then come back as MCP resources, structured data that Claude can read and reason over, allowing it to explain identified risks and suggest remediation steps in plain language rather than simply returning a raw findings report.

The launch reflects a wider shift in how security vendors are approaching AI-assisted coding. As tools like Claude speed up how quickly developers can write and ship software, security teams are under pressure to embed checks earlier in the process rather than relying on scans that happen after code has already been merged. Black Duck is positioning Signal as a way to close that gap by putting vulnerability detection at the point of code generation itself.

Dipto Chakravarty, Chief Product & Technology Officer at Black Duck, framed the move as a response to the pace at which AI coding tools now operate. “security keeps pace with how fast teams are building,” he said of the aim behind bringing Signal into the Claude Directory.

Signal is available now through the Claude Directory listing, with Black Duck directing prospective users to speak to a company representative to get set up. The release follows Black Duck’s broader push into AI-focused application security tooling, part of a growing trend among established AppSec vendors to adapt existing scanning capabilities for workflows increasingly driven by AI coding assistants rather than traditional IDEs.

It also underscores the growing role of MCP as connective tissue between AI assistants and specialist enterprise tools. Since Anthropic opened up the protocol, a steady stream of security, development and productivity vendors have released their own MCP servers, letting Claude act as a front end for capabilities that would otherwise require developers to leave their AI workflow entirely.

The post Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration appeared first on IT Security Guru.

❌
❌