Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

9 September 2026 at 10:20

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here. 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

Filigran Adds AI-Powered Attack Chaining to OpenAEV for Autonomous Pentesting

1 September 2026 at 08:40

Filigran has launched a new attack chaining capability for its OpenAEV platform, designed to help security teams test how multiple weaknesses can be combined to create a viable path through an organisation’s environment.

Released as part of OpenAEV v3, Attack Chaining allows penetration tests and red team exercises to adapt dynamically based on what a simulated attack discovers. Rather than testing individual techniques in isolation or following a fixed sequence, the platform can use findings from one stage, such as credentials, permissions or an open port, to determine what happens next.

The approach is intended to more closely reflect how real attackers operate, where an apparently minor weakness can provide the foothold needed to reach another system and ultimately sensitive data or critical assets.

From individual vulnerabilities to attack paths

Traditional security validation can be effective at establishing whether a particular technique or control works. However, Filigran argues that this can miss the wider risk created when weaknesses are combined.

Its recent State of Threat Management report found that 97% of organisations have difficulty determining whether their exposures are actually exploitable, while 84% said attacks they face often exploit risks that were already known but had not been prioritised. The study, conducted among 550 security decision-makers and practitioners, also found that 88% rely to some extent on manual processes for offensive attack simulation.

Attack Chaining attempts to address that gap by treating the result of each simulated action as an input for the next. A discovered credential, for example, could be tested against another system. If successful, the simulation could continue deeper into the environment. If a security control blocks the attempt, the chain can stop or take another route.

“Security validation has to evolve with the way attackers operate. The goal is no longer just to prove that we can block individual techniques; it is to understand whether those techniques can be combined into a path that leads to a real compromise,” said Julien Richard, co-founder of Filigran. “As adversaries become more adaptive and increasingly use AI to move faster, we need validation that can keep pace.”

AI takes on the red team

The new capability can be operated manually, autonomously through AI agents, or using a combination of the two. In operator-led mode, security teams define the attack logic and control execution themselves. In agent-led mode, a user instead provides an objective and scope in natural language, after which an AI agent can construct and adapt the attack chain according to the findings it encounters.

This could include generating phishing emails and landing pages as part of social engineering exercises.

Filigran said the agent remains subject to predefined scope controls and its decisions are logged, providing security teams with an audit trail of how the simulation reached a particular outcome. The development builds on Filigran’s wider push into agentic security automation. The company launched XTM One in June, introducing AI orchestration across OpenCTI and OpenAEV to automate workflows spanning threat intelligence, attack scenario generation, validation and remediation guidance.

Mapping the route to critical assets

OpenAEV v3 also introduces a live attack path graph that allows teams to watch a simulation progress through their environment. Each hop, branch and finding is displayed as the exercise takes place, allowing defenders to see how far the simulated attacker progressed and which security control eventually stopped it.

Filigran said this could help organisations identify “chokepoints” within attack paths. Instead of treating every vulnerability encountered during an exercise as equally urgent, teams can identify the control or weakness whose remediation would break the wider attack chain.

“A validation outcome is only actionable when security teams can trace the logic that generated it,” said Jean-Philippe Salles, VP of Product Management at Filigran. “With OpenAEV v3, teams can build or generate attack scenarios, watch attack paths unfold, and inspect the logic and evidence behind every step.”

OpenAEV v3 expands AI security testing

Alongside Attack Chaining, OpenAEV v3 includes a redesigned dashboard called the Adversarial Exposure Command Center, bringing security posture, simulation results and detection coverage into a single interface.

The release also adds an Adversarial Exposure Score for tracking validation results across exposure sources, automated reporting and AI red-teaming injectors which allows organisations to run adversarial simulations against LLM-powered agents and chatbots using the same validation engine employed to test traditional controls including EDR, SIEM and email defences.

OpenAEV v3 is available immediately, with Attack Chaining included in the platform’s Enterprise Edition.

The post Filigran Adds AI-Powered Attack Chaining to OpenAEV for Autonomous Pentesting appeared first on IT Security Guru.

7 Ways to Boost Conversions on Your Website

1 September 2026 at 05:13

If your website is attracting visitors but not generating enough enquiries, sales or leads, there are several techniques you can use to improve your conversion rate. From adding a website toolbar and interactive calculators to using limited-time offers and personalised pop-ups, the key is to make it easier and more compelling for visitors to take the next step.

This is particularly important because even small improvements can have a meaningful impact. For example, Baymard Institute estimates that the average ecommerce cart abandonment rate is 70.22%, highlighting how many potential customers leave before completing a purchase. 

Meanwhile, research from Popupsmart found that more than 10,000 popup campaigns achieved an average conversion rate of 3.49%, demonstrating that well-designed pop-ups can still play an important role in lead generation.

1. Website Toolbar

A website toolbar like this one from Barra can provide visitors with immediate access to your most important calls to action. Instead of making users search through your website for contact details, offers or booking options, a toolbar can keep these features easily accessible as they browse.

For example, you could include your telephone number, live chat, special offers, reviews, social media links or a “Get a Quote” button.

The advantage is that visitors don’t need to scroll back to the top of the page to take action. Your key conversion opportunities remain visible throughout their journey.

2. Limited-Time Offers

Creating urgency can encourage visitors who are interested in your product or service to act now rather than putting off their decision.

Limited-time discounts, seasonal promotions and offers with a genuine expiry date can all help create this sense of urgency. You could also include a countdown timer showing exactly how long remains.

The important word here is genuine. If customers regularly see the same “24-hour” offer every day, it can undermine trust. Make sure your deadlines and promotions are legitimate.

3. Calculators

Interactive calculators can be an excellent conversion tool because they provide something useful while getting visitors actively involved with your website.

A mortgage company could offer a repayment calculator, for example, while a finance provider might have a borrowing calculator. A business offering professional services could provide a cost calculator to give visitors an indication of what they might pay.

Once someone has entered their information and received a result, you can then encourage them to take the next step, such as requesting a personalised quote or speaking to an expert.

4. Pop-Ups

Pop-ups have a reputation for being intrusive, but the right pop-up, shown at the right time, can be an effective conversion tool.

Rather than displaying one immediately after someone lands on your website, consider triggering it after a visitor has spent some time on the page, scrolled through your content or shown an intention to leave.

You could use a pop-up to offer a discount, collect an email address, promote a downloadable guide or encourage someone to contact your sales team.

Recent research from Omnisend, based on 1.24 billion popup displays, found an average email popup conversion rate of 2.1% in 2025. The takeaway isn’t that every pop-up will achieve the same result, but that timing, relevance and simplicity matter.

5. Phone Numbers with a Sales Agent’s Face

A telephone number can become more effective when it’s paired with a real person.

Adding a photograph and name alongside your phone number can make your business feel more approachable and give visitors confidence that there is a real person available to help them.

This can work particularly well for businesses offering expensive, complicated or highly personalised products and services. Instead of simply seeing “Call us”, visitors see exactly who they could speak to, like this example from VZ Builders.

You can strengthen this further with messaging such as “Speak to Sarah today” or “Call our team for expert advice”.

6. Spin the Wheel

Gamification can make an otherwise standard lead-generation form more engaging. A “spin the wheel” feature gives visitors the opportunity to win a discount, free consultation or another incentive.

It can be particularly effective for ecommerce businesses, where a visitor might receive 10% off, free delivery or another relevant reward in exchange for their email address.

There is some evidence behind the approach, too. Omnisend’s 2025 data found that gamified pop-ups such as “Wheel of Fortune” formats achieved conversion rates of 3.5% or higher, compared with its overall average of 2.1%.

7. Questionnaires

Finally, consider replacing a traditional contact form with an interactive questionnaire.

Instead of asking visitors to immediately provide their name, email address and telephone number, you can start by asking questions about their requirements such as this example from Daylight Protect. This makes the process feel more like a conversation and can help you understand what the visitor actually needs. It is essentially ‘less forced.’

Plus, there is evidence that narrowing down a customer’s requirements helps with the final conversion.

At the end of the questionnaire, you can ask for contact details in exchange for a quote, recommendation or more information.

Start Testing Your Website

There isn’t one conversion technique that will work for every business. What works for an ecommerce store may be completely different from what works for a financial services company or property business.

The best approach is to test different techniques, measure the results and continually refine your website. A combination of a persistent website toolbar, well-timed offers, useful calculators, targeted pop-ups and personalised interactions can help turn more of your existing website traffic into genuine enquiries and customers.

The post 7 Ways to Boost Conversions on Your Website appeared first on IT Security Guru.

Retired Devices, Active Risks: How an ITAD Company Protects Data After Decommissioning

1 September 2026 at 05:09

A laptop can be removed from an employee’s desk, disconnected from the network and marked retired in an asset system within the same afternoon. None of those steps means the data risk has disappeared.

Retired technology often sits in storage rooms or staging locations before reaching its final destination. During that period, devices still contain business records, credentials, customer information and employee files. Once hardware leaves normal IT operations, familiar controls such as endpoint monitoring and access management often stop following it.

For security teams, decommissioning is a transition point rather than the end of the job. A secure disposition process must account for the device, the data on it, every handoff and the evidence showing what ultimately happened.

1. Retired Devices Are Still Data Bearing Assets

The first mistake in technology retirement is treating unused equipment as ordinary surplus. A device that no longer has operational value can still hold valuable information.

That is why working with a certified IT asset disposition company matters when equipment leaves active service. A qualified ITAD Company should treat security as part of disposition from the first inventory scan through sanitization, reuse, recycling or destruction.

Risk is not limited to functioning equipment. A laptop with a broken screen can still contain a readable solid state drive. A server that will not boot can retain intact storage media. Even devices headed to recycling need controlled handling until data has been addressed.

2. Residual Data Appears in More Places Than Expected

Security teams usually think first about hard drives and solid state drives. Those are obvious targets, but they are not the only places information remains. Retired technology can contain:

  • Local documents, downloads and cached files
  • Browser history, saved sessions and authentication tokens
  • Email archives and application data
  • Customer, employee or student records
  • Network settings, configuration files and system logs
  • Stored credentials and encryption related information
  • Data on removable media, memory cards and attached storage

Printers, multifunction devices, phones, tablets, networking equipment and specialized hardware also contain storage. A sound retirement program begins by identifying data bearing assets rather than assuming only traditional computers require sanitization.

3. Factory Resets and File Deletion Are Not a Security Program

Deleting a file normally removes its reference from the active file system. It does not prove that the underlying information is unrecoverable. A factory reset also varies by device, operating system and storage technology.

This matters when hundreds or thousands of devices are retired at once. A technician clicking through reset menus is not the same as a controlled sanitization process with defined methods, verification and reporting.

An experienced ITAD Company should have a written approach for different media types and clear procedures when a normal wipe fails. Security teams need evidence of the result, not simply confirmation that someone started a reset.

4. Pickup and Transportation Create a Different Kind of Exposure

Once equipment leaves an office, school, hospital or data center, physical security becomes part of data security. Devices can be misplaced, mixed with another shipment or arrive with inventory discrepancies.

The strongest controls start before pickup. Organizations should establish an inventory or manifest, define who can release the equipment and document the point where custody transfers. Packaging, loading, transport and receiving should fit into the same controlled process.

For multi location projects, consistency matters even more. Equipment collected from several offices should follow the same handling rules even when pickup dates differ.

5. Chain of Custody Turns Movement Into Evidence

A documented chain of custody answers a basic audit question: where was the asset, and who controlled it?

Good records connect a unique asset identifier with meaningful events. Depending on the project, that includes pickup, receipt, serialized intake, data processing and final disposition. If the receiving count does not match the pickup manifest, the difference should be recorded and investigated. Useful chain of custody records generally include:

  • Serial number, asset tag or another unique identifier
  • Collection location and pickup information
  • Receiving and inventory confirmation
  • Data sanitization or destruction status
  • Exceptions such as missing drives, damaged devices or failed wipes
  • Final disposition such as resale, reuse, recycling or destruction

For security and compliance teams, this record closes the gap between equipment leaving the building and knowing what happened to it.

6. NIST 800-88 Provides a Framework for Sanitization Decisions

NIST SP 800-88 gives organizations a structured way to manage media sanitization. The current Revision 2 guidance focuses on a sanitization program based on information sensitivity, the media involved and its intended disposition.

The three methods are Clear, Purge and Destroy. Clear uses logical techniques to protect against simple, noninvasive recovery through the normal device interface. Purge uses stronger physical or logical techniques intended to make recovery infeasible even with advanced laboratory methods while preserving potential reuse. Destroy renders recovery infeasible and leaves the media unusable for data storage.

The right method depends on the device, storage technology, data sensitivity and what will happen to the asset afterward. Reusable equipment often benefits from verified sanitization that preserves resale or redeployment value. Media that cannot be reliably sanitized needs another path.

7. Physical Destruction Has a Specific Role

Shredding every drive is not automatically the right answer. It eliminates opportunities for reuse and value recovery when secure sanitization is appropriate. At the same time, some media should not return to service.

Physical destruction is appropriate when storage is damaged, sanitization fails, policy requires destruction or the media contains information that warrants that disposition method. It also provides a route for drives that cannot be accessed well enough to complete a verified wipe.

A capable ITAD Company should distinguish between assets that can be securely sanitized and reused and media that requires destruction. That decision should follow policy rather than convenience.

8. Asset Level Reporting Exposes the Exceptions

Large disposition projects rarely proceed without a few surprises. A listed laptop is missing. A drive has been removed. A device arrives damaged. A wipe does not complete. A serial number appears in the shipment but not on the original inventory.

These are not administrative nuisances. They are security exceptions that need to be visible.

Asset level reporting allows an organization to reconcile the project instead of receiving one final number. Reports should show what was received, how each data bearing asset was handled, which records failed normal processing and how those exceptions were resolved.

This detail also helps other business teams connect security outcomes with resale, recycling and final disposition.

9. A Certificate of Data Destruction Needs Supporting Detail

A certificate has value only when it proves something specific. A generic document stating that a shipment was destroyed offers little help if an auditor asks about one particular server or laptop.

A useful certificate of data destruction should connect the outcome to identifiable assets and the processing record. It should establish what was sanitized or destroyed, the method used, the result and the relevant date or project information.

The certificate should also align with the broader audit trail. If an exception occurred, reporting should show how it was resolved. If some devices were sanitized for reuse while other drives were physically destroyed, the records should make that difference clear.

10. Provider Evaluation Should Go Beyond a Certification Logo

Certifications give buyers an important starting point, but security teams still need to understand how a provider operates. R2v3 and recognized ISO management system certifications can demonstrate that documented processes and independently assessed controls are in place. They do not replace project specific evidence.

When evaluating an ITAD Company, buyers should examine how the provider handles serialized inventory, chain of custody, sanitization, physical destruction, exceptions, downstream recycling and final reporting. They should also ask which controls apply at the facility processing their equipment.

A provider should explain the process plainly. Security teams should know when custody changes, how failed sanitization is handled and how each asset is reconciled at project close.

Keeping Data Security Intact Through Final Disposition

Technology retirement changes a device’s location and purpose, but it does not erase the information stored on it. The security obligation continues until data has been appropriately sanitized or destroyed and the organization has records that support the outcome.

A well managed ITAD process keeps those final steps visible. It connects physical control, data handling and documentation so retired hardware does not become an overlooked gap in an otherwise mature security program.

The post Retired Devices, Active Risks: How an ITAD Company Protects Data After Decommissioning appeared first on IT Security Guru.

Vega Introduces Detection Skills, The New Open Standard for AI Reasoning in Agentic Cyber Defense

12 August 2026 at 10:42

Vega, the pioneer of Agentic Cyber Defense, today launched Detection Skills: an open standard that redefines security operations for the AI era. The standard captures a team’s expert judgment as a self-improving agentic loop across detection, triage, and investigation. Available to the community as an open standard, or natively within the best-in-class Vega platform, they allow modern Cyber Defense Engineers to architect their reasoning once and scale it across everything they defend. It gives every company an answer to the question that matters most: can our defense keep pace with AI?

“AI-driven adversaries bypass static rules in every legacy SIEM, and no rule catches an attack it has never seen,” said Eli Rozen, co-founder and CTO, Vega. “Detection Skills answer with scaled AI reasoning that brings the judgment of your best Cyber Defense Engineers to every alert, in real-time. We made the standard open to ensure the whole industry rises with it: as attacks scale, defense compounds.”

Why Now

Frontier AI has collapsed the economics of cyberattacks. Intrusions that took skilled teams weeks now take minutes, with advanced models breaking containment and autonomously breaching organizations. Defenses built on legacy SIEM have not kept pace: they can only recognize known patterns in a threat landscape where attacks are generated, not repeated.

From Static Rules to AI Reasoning

Just as Sigma defined the traditional detection rule format, Detection Skills is what comes next for AI-first Cyber Defense teams. The engineer who builds a detection and the analyst who answers it at 2 a.m. often never meet, and the context dies in the handoff.

Detection Skills solves that: built on the Agent Skills framework originally developed by Anthropic, it attaches triage, investigation, and optimization directly to the detection, so the reasoning travels with it, enabling security teams to:

  • Detect and decide at AI speed. Triage and investigations run automatically the moment a detection fires, slashing MTTD and MTTR. Only what matters reaches a human, with a finished, evidence-backed workbook attached.
  • Scale cyber defense expertise. Author a skill once and the same judgment reaches every alert, known or unknown. Engineers keep complete transparency and control over the AI’s reasoning: what it checked, why it decided, and no change without their sign-off.
  • Adopt without disruption. Works alongside existing security investments. It launches with the Agentic Detection Library: 50+ skills from Vega Research and our partners, plus a sandbox to build, test, and export spec-compliant detections, and GitHub to contribute your own.

Vega proved Detection Skills in production on its Cyber Defense Platform, the standard’s reference implementation. Built on the Security Analytics Mesh (SAM), the platform runs the full loop directly on an organization’s data wherever it lives, across cloud object storage, Legacy SIEMs, and data lakes, with no data migration or ingestion tax.

Everything is live today at detectionskills.io and within the Vega platform. The full framework debuts this week at Black Hat USA 2026 at booth 3452.

Rushmere Fernandes, Deputy Chief Information Security Officer, Peloton

“We adopted Detection Skills early and started by encoding our own triage logic, the way our team actually works an alert, not a generic playbook. Every skill we ship gives us more explicit control over what the AI checks, escalates, and dismisses. The result is a queue we trust: fewer false positives, and every verdict arrives with its reasoning attached.”

Shawn McGhee, Chief Information Security Officer, Exemplar Luxury Group

“Retail runs on peak moments, and attackers know exactly when those are. My team cannot be the constraint on a Saturday in December. Detection Skills gives us leverage we can plan around: the expertise is written down, it runs on every alert, and it holds up when volume spikes. We are adopting it and sharing what we learn, because no security team should have to rebuild this work alone.”

Lamont Orange, Chief Information Security and Trust Officer, Cyera

“Defenders have never faced a moment like this: attackers are compounding their capability, and for the first time we can compound ours. An open standard for how detection decisions get made – auditable, transparent, shared – is how trust gets built at industry scale. Adopting Detection Skills and helping shape it is what good digital citizenship looks like in the AI era.”

Read the announcement: https://vega.io/blog/vega-introduces-detection-skills · See it live: vega.io/get-a-demo

The post Vega Introduces Detection Skills, The New Open Standard for AI Reasoning in Agentic Cyber Defense appeared first on IT Security Guru.

Margarita Howard’s HX5 Operationalizes CMMC Compliance Before AI Rules Arrive

10 August 2026 at 10:10

Margarita Howard has spent two decades running a company in a government contracting market where the rules rarely hold still.

HX5, the defense and aerospace services firm she founded in 2004 and still leads, supports Department of Defense and NASA missions and has employed over 1,000 people across 34 states and 90 government locations over the course of its history.

For most of that span, the price of remaining eligible to do the work has been a requirement that keeps changing shape. Its current form is the Pentagon’s Cybersecurity Maturity Model Certification, known as CMMC, and behind it a second, still-forming set of rules aimed at artificial intelligence. How HX5 has prepared for both is a case study in the need to prepare for sudden shifts in security technology.

The CMMC

For years, contractors handling sensitive government data attested to their own cybersecurity practices. CMMC replaces much of that self-attestation with graded, checkable proof. The framework, which took effect under a Defense Department rule in 2025, sorts contractor obligations into three levels tied to the sensitivity of the information involved.

Level 1 covers basic Federal Contract Information and allows an annual self-assessment. Level 2 applies to Controlled Unclassified Information (the sensitive-but-unclassified material that runs through most substantive defense work) and, depending on the program, requires verification by an accredited outside assessor. Level 3 covers the government’s most critical programs and is assessed by the Pentagon itself.

The schedule is what gives the program its teeth. Phase 1 took effect on November 10, 2025, and the first certification requirements entered new contracts. Phase 2 follows exactly one year later, on November 10, 2026, when independent third-party certification becomes a condition of award for contractors handling Controlled Unclassified Information. At Level 2, that means demonstrating all 110 security practices drawn from the NIST SP 800-171 standard, backed by evidence an assessor can test rather than a contractor’s word.

That evidentiary bar is where many contractors are finding a gap between feeling compliant and being audit-ready. By early 2026 the assessment market had become a bottleneck. Industry trackers counted only about 1,000 contractors certified at Level 2, far short of the tens of thousands expected to need it, with roughly 80 accredited assessment organizations available to do the work. Wait times now stretch into months.

HX5 entered that crunch from the front of the line. The company was among a limited group of contractors to hold CMMC Level 2 certification by the end of 2025, well ahead of the Phase 2 mandate.

The distinction at the center of the scramble is between being aligned and being audit-ready. Many contractors hold documentation showing they meet the NIST practices on paper; far fewer can produce the evidence a certified third-party assessor will demand to confirm each control is implemented and operating. Early assessments can falter on the unglamorous fundamentals: access control, audit and accountability, incident response. The program also limits how much a contractor can defer through a plan to fix gaps later. Critical practices have to be working at the time of assessment, not promised. Closing that gap typically takes six to 12 months of focused work.

HX5’s Distributed Footprint and the Audit-Ready Bar

Firms like HX5 work across dozens of government locations, supporting research and development, engineering, information technology, and mission operations for federal customers. Holding a single, defensible compliance posture across distributed operations is an exercise in standardization: building the same expectations into vendor qualification, contract management, and the daily routines of each location, rather than reconstructing them program by program.

Certification is not a perimeter a contractor can defend alone, either. CMMC obligations flow down a contract: a prime that handles controlled data is responsible for confirming that the subcontractors and vendors it shares that data with meet the level required of them before the information changes hands. For a firm spread across dozens of programs, that turns compliance into a procurement function as much as a technical one. The company has to qualify partners against the standard, write the expectation into agreements, and verify it rather than assume it. The administrative weight of that work scales with the number of relationships a contractor maintains, which is part of why a footprint as broad as HX5’s makes the discipline harder to retrofit and more valuable once it’s in place.

Margarita Howard points to the pandemic as the stress test that proved the model. When operations went remote in 2020, the company had to keep meeting the government’s security and reporting standards while its workforce scattered. “We very quickly had to set up our employees to work remotely … to ensure the security standards that we have to report on,” she said, crediting a flexible, secure infrastructure the company had already paid for. The episode reinforced a lesson that maps directly onto CMMC: the firms that weather a sudden change in requirements are usually the ones that built the capacity before they needed it.

Howard frames the work as a matter of record-keeping discipline as much as technology. “It’s important that a company’s records are impeccable when working with the government due to the compliance reporting and audits that companies have to agree to in order to perform on government contracts,” she said.

She explained that HX5 put money into accounting and management systems built for government-contracting environments early on, and it keeps standing advisory capacity on hand for the regulatory questions that surface as programs evolve.

“We have built and maintained a team of advisers that specialize in the government industry,” Howard said. “They help us stay current with the policies and regulations that govern the defense sector.”

Workforce composition reinforces the same habit. Veterans make up more than 30% of HX5’s employees. Many arrive having already worked inside government security environments, with a built-in sense of why controls exist and what an audit will ask for. The company has taken part in the Defense Department’s SkillBridge initiative and the Hiring Our Heroes Corporate Fellowship Program since 2021, and the Department of Labor recognized its veteran-hiring record with a 2025 HIRE Vets Gold Medallion.

The capability also depends on a steady supply of people who can do the technical work behind the controls. Howard pointed to university partnerships as one of the company’s more productive and less expected investments. Those collaborations keep HX5 close to emerging technology and feed a pipeline of graduates into roles that, in this market, are hard to fill and harder to clear. A compliance program is only as strong as the staff who implement it day to day, and the same recruiting channels that bring in cleared engineers and technicians supply the people who keep audit evidence current between assessments.

The same rising bar that burdens HX5 also reshapes the field it competes on. Compliance has become a fixed cost of doing defense work, and fixed costs fall hardest on firms without the scale or the standing infrastructure to absorb them. Some smaller contractors may decide the controlled-data work is no longer worth the overhead; some larger primes have narrowed the lower-margin contracts they pursue. A mid-tier company that has already paid for the capability sits in the gap that opens between those two retreats, potentially able to take on work that requires certification without treating each new requirement as a fresh capital project.

But for contractors that deferred the investment, Phase 2 arrives as both a timeline problem and a cost problem. Assessor capacity is finite, the queue is long, and assembling a compliance foundation under deadline pressure costs more than building it in calmer conditions.

Howard’s read on that math reflects a market she has worked in since the company’s small-business beginnings. “There are heightened cybersecurity requirements,” she said, “and contractors will not have a choice but to implement them if they want to be a government contractor.”

The AI Layer Arriving on Top of CMMC

The next requirement is already visible. The FY2026 National Defense Authorization Act, signed in December 2025, directs the Pentagon to build a cybersecurity and physical-security framework for artificial-intelligence and machine-learning systems and to fold it into the existing CMMC program, a step often shorthanded as “CMMC for AI.”

Section 1513 of the law tells the Defense Department to address workforce, supply-chain, and adversarial-tampering risks in AI systems acquired for government work, drawing on established NIST standards. The provision does not set a final implementation date, but it required a status report to Congress on the plan in June 2026, with the new requirements ultimately expected to reach contractors through the same acquisition rules that carry CMMC.

The framework Congress has in mind is broad. As drafted, it reaches “covered” AI and machine-learning systems acquired by the Defense Department along with their components (source code, model weights, and the data and methods used to build them), and concentrates the most stringent requirements on the highly capable systems likeliest to draw the attention of sophisticated adversaries. It extends the logic of CMMC, protecting sensitive information, into a new category of asset the original program was not written to address.

The timing is what makes the moment unusual. The third-party certification requirement and the new AI rules are advancing through the same window, on the same acquisition machinery, aimed at overlapping populations of contractors. A firm that treats them as two separate fire drills faces a doubled burden in a compressed period. A firm that treats compliance as one continuous capability sees the AI framework as an extension of work already under way rather than a second front.

How fast the AI requirements bind on contractors is still unsettled. Section 1513 sets a planning process in motion rather than a finished rule, and the report due to Congress is a milestone in that process rather than the finalized rule itself. The practical questions will be answered in rulemaking still to come: which systems count as covered, how the requirements map onto CMMC levels, and when they appear in contract clauses.

For HX5, that uncertainty is an argument for the posture it already holds. A contractor with mature compliance machinery can wait for the specifics without falling behind, because adapting an existing program is a smaller task than building one.

The point is less whether the AI rules are wise than that they will arrive on top of an obligation the company already meets, through machinery it has already built. A contractor that has internalized CMMC should have the assessment discipline, documentation habits, and advisory bench to absorb an added layer without starting over. One still scrambling for its first Level 2 certification will be asked to take on a second, harder problem before finishing the first.

Howard has been pointing in this direction for some time. She, like many others in the industry, has stressed that government agencies will increasingly use AI to streamline procurement and evaluate contractor performance, and that compliance itself will grow more automated.

“Contractors will be required to integrate systems that provide continuous reporting and real-time audit capabilities,” she said. “We’ve invested heavily in technology infrastructure to meet these future demands.”

The post Margarita Howard’s HX5 Operationalizes CMMC Compliance Before AI Rules Arrive appeared first on IT Security Guru.

Greg Soros Shares How Podcasters Build Lasting Authority Through Thought Leadership

3 August 2026 at 07:45

Authority in podcasting is earned slowly and lost fast. Any host can launch a show. Building a reputation that makes listeners return for your take, over everyone else’s on the same subject, requires something more deliberate: a consistent editorial identity that holds up episode after episode, not just on the days when the topic lands perfectly.

Why Podcast Thought Leadership Works Differently From Other Platforms

LinkedIn posts, op-eds, and keynote talks can signal expertise. Podcasting does something different. It gives audiences an extended, unfiltered window into how a host thinks, reasons, and engages with complexity. Across 40 minutes, a listener forms a genuine impression of a host’s intellectual range and editorial judgment. That impression accumulates over episodes into something closer to a relationship than a resume.

Greg Soros has produced thought leadership content for executives, entrepreneurs, and independent voices across industries. Across those projects, the shows that built the deepest authority had something in common: a host willing to model good thinking in real time, draw unexpected connections, and hold a position under pressure. A bio might earn initial attention. The quality of the thinking across those 40 minutes is what earns a subscription.

Building a Recognizable Point of View

The most common mistake new podcast hosts make is trying to cover everything. A host with a take on every development in a broad space ends up sounding like a trade publication. The ones who build lasting reputations pick a lane and defend it. They develop a point of view that listeners learn to anticipate, argue with, and come back to test against new information.

Building that kind of editorial focus takes deliberate decisions in pre-production: What does this show believe? What would it refuse to say? What positions is the host willing to hold even when they’re unpopular? Answering those questions before recording begins is the difference between a podcast and a platform.

Greg Soros works with clients at this stage of development to find the angle that fits their actual expertise and stands apart in the market. Most professionals have a stronger point of view than they give themselves credit for. The job of production is to surface it and give it a format that holds up over time.

The Long Game of Podcast Brand Authority

Thought leadership built through podcasting compounds. A host who publishes consistently for two years with a clear editorial identity accumulates a body of work that’s searchable, shareable, and worth quoting. Each episode adds to a public record of ideas that keeps reinforcing the host’s credibility on specific topics.

That body of work tends to open doors other content formats rarely do: speaking invitations, media requests, business development conversations. The podcast becomes evidence. When someone is evaluating a host’s expertise before bringing them onto a panel or into a deal, a back catalog of substantive episodes carries more weight than a bio page.

Greg Soros built his studio around this long-game philosophy. The company creates content built to hold its value across time, earn attention on an ongoing basis, and keep building the case for the host’s authority long after the recording session ends.

The post Greg Soros Shares How Podcasters Build Lasting Authority Through Thought Leadership appeared first on IT Security Guru.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

21 July 2026 at 09:17

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the report‘s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

“AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

“In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

“As attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

“Many organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

Mike Winston on Why Jet.AI Shifted From Aviation to AI Infrastructure

7 July 2026 at 10:53

Private aviation runs on tight margins and tighter schedules. The AI tools Jet.AI built to optimize both placed the company in an unusual vantage point: watching production inference workloads run against real operational constraints, before the data center power shortage became a mainstream story. Mike Winston, investor and founder of Jet.AI (NASDAQ: JTAI), built those tools inside an operating aviation business and drew from them a conclusion that now anchors two public companies: the constraint binding the AI infrastructure buildout is power, and the gap between available supply and projected demand will persist for years. That conclusion informs the February 2025 agreement to transfer Jet.AI’s aviation operations to flyExclusive, the data center development pipeline being assembled through the Convergence Compute joint venture, and the $138 million SPAC raised through AI Infrastructure Acquisition Corp. (NYSE: AIIA). For investors trying to understand Jet.AI’s trajectory, the aviation chapter is where the thesis actually originates.

From Jet Token to Jet.AI: A Sequence With a Logic

What happened at Jet.AI between 2016 and 2025 reads, from the outside, as a series of technology pivots. The company began as Jet Token, a blockchain-based private aviation startup founded by Mike Winston, CFA, whose prior career had run from equity research at Credit Suisse First Boston through five years as a portfolio manager in merger arbitrage and event-driven investing at Millennium Partners. Regulatory constraints closed off the blockchain model’s commercial path. The company rebuilt around AI tools for aviation: agentic booking software, route optimization for fuel and carbon efficiency, dynamic pricing for charter operations. Each change tracked external conditions. Each stage also produced information the next depended on.

What Building Aviation AI Software Actually Reveals

The tools Jet.AI developed for private aviation required real compute at operational scale. Agentic booking software coordinates availability, pricing, and scheduling across multiple aircraft against a customer base with variable and often short-notice demand. Route optimization requires running real-time models against weather, airspace, and fuel data. Dynamic pricing models consume compute at a rate that scales with transaction volume and prediction complexity.

Running those workloads inside an operating aviation company (not in a research environment, in production, against real cost constraints) produces a specific kind of knowledge. The compute requirements of operational AI are higher than they appear from the outside. The power requirements of compute at scale are higher still.

Through building AI tools for aviation, we saw firsthand the scale of transformation AI would bring,” Winston said in an April 2026 interview. “That led us to data centers, where the infrastructure opportunity is significant. Given my background in real estate finance and telecom, it was a natural transition. Today, we’re extending that into power generation using aero-derivative engines, another area with strong underlying demand.”

That insight came from operating a business where AI was a production tool, measured against real cost constraints.

The Power Problem, Quantified

The constraint Winston identified by operating inside aviation AI is now visible across the broader market.

The U.S. Department of Energy estimated data center electricity consumption at 176 terawatt-hours in 2023. Analysis by Alderman & Co. projects that figure could reach 580 TWh by 2028. That would put data centers at between 6.7% and 12% of all U.S. electricity. Grid interconnection queues in some U.S. jurisdictions now run eight to 10 years, measured from the point of application.

New gas turbines from major manufacturers are not closing that gap fast enough. Contact GE Vernova today for an LM6000 order and the delivery window runs three to five years minimum. GE Vernova CEO Scott Strazik said in early 2025 that the company expected to be largely sold out through the end of 2028 by that summer. Siemens Energy reported that more than 60% of its U.S. gas turbine orders that year were linked to AI data center demand. Mitsubishi’s newer turbine blocks ordered in 2025 may not ship until the 2030s.

The practical solution for data center operators who need power now is the aero-derivative gas turbine: units built around retired commercial jet engine cores, modified for stationary generation. ProEnergy has sold 21 of its PE6000 units to just two data center projects: more than one gigawatt of combined bridging power. Each unit produces 48 megawatts and can be operational within 30 days of delivery. ProEnergy was quoting 2027 availability when GE Vernova’s order book had already closed into 2028 and beyond.

The Aviation Industry as an Early Observer

The CF6-80C2 turbofan engine, the core unit that ProEnergy overhauls for its ground-based power systems, was widely used on Boeing 767s and Airbus A310s. Approximately 1,000 of these engines are expected to retire from commercial aviation service over the next decade. The supply is quantifiable, the retirement schedule is predictable, and the companies with operational knowledge of aviation hardware were positioned to recognize the secondary market forming around those cores.

Jet.AI was an aviation company with AI tools and capital markets literacy. That combination produced an earlier read on the intersection of retiring aviation hardware and data center power demand than financial analysis alone typically generates.

The competition for aero-derivative turbines has since created cross-sector friction that Alderman & Co. analysts Ryan Kirby and Joseph Lakaj documented in March 2026: aero-derivative units share a near-identical manufacturing base with commercial flight engines, relying on the same specialized castings, high-temperature alloys, and precision forgings. A large data center order for turbines now directly competes with engine deliveries for new commercial aircraft. Boeing and Airbus are both navigating extended delivery timelines driven in part by engine shortfalls. Two industries are pulling on the same supply chain, and the aviation sector is both a contributor to that constraint and, through companies like Jet.AI, a beneficiary of it.

The flyExclusive Transaction and What It Unlocked

The agreement to transfer Jet.AI’s aviation operations to flyExclusive removed the operational complexity that had kept two structurally different businesses inside a single public vehicle.

flyExclusive takes the Citation and HondaJet fleet and the private aviation customer base. The combined platform has the scale to extract returns Jet.AI’s aviation division could not reach independently. Jet.AI shareholders receive flyExclusive (NYSE American: FLYX) equity alongside their retained JTAI position. The post-close version of Jet.AI carries no fleet, no pilots, and no charter operating costs.

What remains in JTAI: the Convergence Compute joint venture with Consensus Core Technologies, targeting one gigawatt of data center capacity across three campuses in North America; a $5 million economic interest in a special purpose vehicle anchored by SpaceX and xAI equity; and the 49.5% economic stake in the AIIA sponsor.

On June 1, 2026, Glass Lewis issued a “FOR” recommendation on the flyExclusive merger. Glass Lewis is one of two proxy advisory firms whose research institutional investors consult as a standard checkpoint before shareholder votes. The special shareholder meeting is scheduled for June 11, 2026. Approval requires an affirmative vote from a majority of all outstanding shares. Institutional participation is essential to clearing that threshold.

Public markets tend to undervalue companies that operate across two structurally distinct businesses. Aviation and AI infrastructure attract different investors on different time horizons. Separating them into distinct listed vehicles removes the valuation friction that a mixed balance sheet creates.

AI Infrastructure Acquisition Corp.

AIIA raised $138 million in its October 2025 IPO. Its mandate is to identify and close a business combination in data center infrastructure or AI, a focus the company describes as “ship to grid.” As of early 2026, management confirmed active engagement with several targets.

The connection to JTAI runs through sponsor economics. SPAC sponsors typically receive 20% of post-IPO equity as founder shares plus warrants exercisable at $11.50. Jet.AI’s 49.5% position in the AIIA sponsor entity means that if AIIA closes a qualifying business combination, nearly half the sponsor economics flow back to JTAI shareholders. The stake was carried at $17.23 million on Jet.AI’s balance sheet as of Q1 2026, and the company reported $13.5 million in cash with no debt.

Winston has positioned the infrastructure bet across two independent paths: an organic buildout through Convergence Compute and an acquisition vehicle through AIIA. The structure means not every outcome depends on a single execution.

Winston’s Background and the Pattern It Reveals

Winston joined Credit Suisse First Boston in 1999 on a telecom research team that Institutional Investor Magazine ranked first, at the start of one of the largest infrastructure capital cycles of the modern era. Five years at Millennium Partners followed, co-managing a $1 billion merger arbitrage and event-driven book through Catapult Capital Management. That discipline produces a specific habit: determine what an asset is worth if the market-moving event does not occur, then price accordingly.

The data center power thesis runs through that same lens. The demand is documented: grid interconnection timelines, turbine manufacturing lead times, and hyperscaler capex commitments are all public record. The question event-driven analysis poses is not whether the demand is real but whether the specific positioning captures the value before it prices in. Winston has spent a career in disciplines that reward being right about that second question.

He founded Sutton View Capital in 2012 after departing Millennium Partners. The firm advised one of the largest academic endowments in the world and co-led successful activist litigation against the Dole Foods board, securing a 35% increase in total consideration for shareholders. The CFA credential, the Institutional Investor ranking, the Columbia MBA: the credentials are institutional. The career decisions have been independent. Jet.AI and AIIA are both built outside established platforms, on conviction about where specific structural conditions point.

Where the Risk Lives

AIIA has a standard SPAC window of 18 to 24 months from its October 2025 IPO. No business combination has been announced. The clock is running, and trust account mechanics create real deadline pressure regardless of whether the acquisition market cooperates on the same schedule.

Convergence Compute has three of four development milestones complete, with power studies and permitting underway across its three campus sites. Construction, equipment procurement, and customer acquisition follow. The financial returns depend on those campuses being built, leased, and stabilized. Each step carries execution risk appropriate to a company of JTAI’s current scale.

The supply constraints that make the thesis credible are also the supply constraints that make execution difficult. Developer competition for turbine delivery slots, permitting capacity, and project financing is intensifying as more capital chases the same infrastructure gap.

The observational logic that runs from aviation AI tools to data center infrastructure holds up as an account of how Winston read the market. Whether Jet.AI can execute against it before the supply advantage narrows is what the next 18 months will determine.

Disclosure: This article discusses Jet.AI, Inc. (NASDAQ: JTAI) and AI Infrastructure Acquisition Corp. (NYSE: AIIA). Readers should conduct their own due diligence before making investment decisions. This piece reflects publicly available information and does not constitute investment advice.

The post Mike Winston on Why Jet.AI Shifted From Aviation to AI Infrastructure appeared first on IT Security Guru.

George Murnane’s One-Question Test for Real AI

7 July 2026 at 10:52

Ask George Murnane how to separate real artificial intelligence from a marketing slogan, and he gives you one question: what does the model predict, and what is its loss function?

George Peter Murnane has spent more than three decades running asset-intensive aviation businesses, 14 of those years as a chief operating officer, a chief financial officer, or both at once. He is now chief executive of Jet.AI Inc. (NASDAQ: JTAI) and a director and CFO of AI Infrastructure Acquisition Corp., the blank-check company that closed an upsized $138 million IPO in October 2025. That résumé sits at the exact junction where capital, operations, and AI claims collide. It also makes him unusually hard to sell to.

The George Murnane filter: name the prediction, name the loss function

The test is deliberately unglamorous. If a company can tell you precisely what its model forecasts and what error it is trained to minimize, the AI is probably real. If the best it can offer is that the technology “makes the experience smarter,” the label is doing work the software cannot.

That distinction matters more in aviation than in almost any other industry, because the cost base is high and the margins are thin enough that a small efficiency gain compounds into real money. Murnane’s filter is a way of routing scarce capital toward the few applications that move those numbers, and away from the many that only move a pitch deck.

Where AI is real in aviation: the AOG math

Start with predictive maintenance, the application Murnane considers genuinely valuable. The economics are not subtle. A single aircraft-on-ground event can cost an operator between $10,000 and $150,000 per hour of downtime, once you add lost revenue, crew rest and overtime, passenger re-accommodation, and the scramble to source a replacement part.

Predictive maintenance attacks that cost directly. By reading sensor data, flight history, and maintenance records, the models flag a deteriorating component before it fails, which lets an operator move an unplanned repair into a scheduled window. A 2022 Deloitte analysis cited by Radome Technologies estimated that predictive maintenance, properly implemented, can cut maintenance costs by up to 30% and reduce AOG events by more than half. Delta cut unscheduled maintenance by more than 30% using predictive engine monitoring.

The use case is specific enough to survive Murnane’s question. The model predicts a component failure. Its loss function penalizes false negatives, the missed failures that ground an aircraft, and false positives, the needless part swaps that waste a maintenance slot. There is a number on both sides of the ledger. Investors have noticed the same thing: the predictive airplane maintenance market is projected to grow from $5.35 billion in 2026 to $18.87 billion by 2034, a compound annual rate above 17%.

Predictive maintenance is not the only application that clears the bar. Crew scheduling optimized against duty-time limits has a defined objective and a hard constraint set written into federal regulation. Dynamic pricing run against forward booking curves predicts demand and optimizes yield. Document automation in SEC filings and merger diligence has a measurable output and a measurable error rate. Each of these can be described in a sentence that names what is being predicted. That is the tell.

The failure modes George Murnane watches for

The opposite of a loss function is an adjective. Murnane’s interviews return repeatedly to two ways companies dress up old or absent technology as AI.

The first is rebranding. A regression model that has been forecasting demand or pricing risk for 30 years gets relabeled “AI” because the term raises a valuation. The math is the same forecast it always was, repackaged under a more valuable label.

The second failure mode is more current and more expensive. A company bolts a large language model onto a workflow without redesigning the workflow underneath it. The result is a chatbot marginally more eloquent than the FAQ page it replaced, sold as a transformation. The model is real, but the value is not, because no one re-engineered the process the model was supposed to improve.

Murnane’s caution here is partly reputational arithmetic. As he has put it, the credibility cost of overclaiming compounds faster than the marketing benefit. For a public company whose name carries the letters “AI,” that is not an abstract risk. Overstate what the software does, and the first product failure under pressure becomes the story.

How Jet.AI uses AI where the value is measurable

Jet.AI gives Murnane a place to apply his own test in public. The company’s software, built when it operated as a private-aviation platform, concentrated AI on functions with a number attached: booking optimization, matching customers to the right operator, and customer communication. Its CharterGPT app and the Ava agentic booking model used natural-language processing to compress a booking process that once ran on phone calls and faxes.

Those tools handle a deliberately narrow set of jobs. Flying the airplane, vetting an operator’s safety record, and resolving a mechanical failure at midnight stay with humans and regulators. The AI sits where its prediction is cheap to measure and its errors are cheap to correct, which is exactly where Murnane argues it belongs.

From booking software to AI data center infrastructure

The most telling application of the loss-function test is the one Jet.AI is now living through. The company has moved away from running aircraft and toward building AI data center infrastructure, describing itself as a technology company focused on data center development across North America, with projects spanning more than a gigawatt of planned capacity.

The reason behind the pivot reads like a case study in Murnane’s own discipline. Jet.AI built genuine AI products, including a large language model agent for private aviation, then ran into a constraint that no amount of marketing could fix: unreliable uptime for the computational resources those products depended on, which occasionally slowed the company’s ability to serve customers. The bottleneck sat below the algorithm, in the power, land, and compute the products ran on.

So the company went after the bottleneck. Based in Las Vegas, with access to land, solar power, and natural gas, Jet.AI signed a letter of intent for a 50-megawatt project on a 120-acre campus with room to scale toward a full gigawatt. The framing Executive Chairman Mike Winston used was almost a rebuke of the category’s usual rhetoric: the move “isn’t a flashy move, but it’s a smart one,” because data centers are “the bedrock of the AI economy” and create value that is “tangible, stable, and meaningful.”

That is the loss-function test pointed at infrastructure rather than software. The prediction is straightforward: compute demand keeps climbing, and the assets that supply it earn against it. The error is measurable in megawatts delivered and uptime maintained. There is a number on both sides.

Why the loss-function test travels

Murnane’s filter works because it is industry-agnostic. It ignores whether a technology looks impressive and asks instead whether anyone can state what the system is optimizing and check the result against reality.

That discipline is the through-line of his career, from pricing aircraft assets at global carriers to evaluating a data center SPAC. The same question that exposes a relabeled regression model also exposes an overhyped acquisition target. In both cases, the executive who can describe the objective function is operating from evidence. The one reaching for “smarter” and “seamless” is operating from hope.

For a sector where roughly every company now claims an AI strategy, the value of a one-question screen is that it is fast and hard to fake. Name the prediction. Name the loss function. If those two answers are specific, the technology is likely doing real work. If they dissolve into adjectives, the only thing being optimized is the marketing.

The post George Murnane’s One-Question Test for Real AI appeared first on IT Security Guru.

Huntress Signs Giacom to Widen UK MSP Access to Managed Detection and Response

7 July 2026 at 04:00

Huntress has struck a new distribution partnership with UK channel marketplace Giacom, giving the managed service providers (MSPs) on Giacom’s Cloud Market platform direct access to Huntress’ Agentic Security Platform and its 24/7 AI-centric Security Operations Centre (SOC). 

The deal is one of two announced this week, alongside a parallel agreement with MSP Nordics covering Denmark, Finland, Iceland, Norway and Sweden, as Huntress looks to broaden its footprint across EMEA. Both moves are aimed at removing friction for MSPs that want to add enterprise-grade detection and response capability without taking on new vendor relationships from scratch. 

Giacom supports more than 6,000 MSPs and technology providers in the UK through its Cloud Market platform, which bundles cloud, connectivity, mobile, hardware and security offerings from multiple vendors alongside sales, management and enablement tooling. Bringing Huntress into that catalogue means Giacom partners can now sell managed EDR, identity threat detection and response (ITDR), identity and endpoint security posture management, managed SIEM and security awareness training through a distributor relationship many of them already use.  

For Huntress, the tie-up also reinforces its existing alliance with Microsoft, giving the vendor a path to partners through Giacom’s established Microsoft practice, a route the company says will help it reach MSPs that remain heavily exposed to ransomware, business email compromise, account takeover, phishing and abuse of legitimate remote management tools. 

“MSPs are under increasing pressure to deliver stronger security outcomes for customers without adding complexity to their own operations,” said Carl Oliver, Head of Product & Cloud Practice at Giacom. “Huntress stands out for its ability to deliver high-quality managed detection and response in a way that is purpose-built for MSPs, backed by around-the-clock specialist support. By bringing Huntress into our portfolio, we are giving our partners another way to strengthen their security services, support more customers with confidence, and create new opportunities for growth.”

“Scaling security across regions depends on trusted relationships within those markets,” added Kevin Hallmark, Head of Global Distribution at Huntress. “Giacom and MSP Nordics bring the relationships, regional expertise, and partner-first approach needed to help us equip more MSPs to defend businesses across the UK and Nordics that remain most exposed to today’s cybercriminals.”

Huntress says its platform currently safeguards more than five million endpoints and 13 million identities worldwide, with its analyst-led SOC often among the first responders to major incidents affecting the security community. The company positions itself as making enterprise-grade protection accessible to businesses that would otherwise lack the budget or in-house expertise to defend against modern threats. 

 The Giacom and MSP Nordics agreements follow a pattern familiar to the channel: rather than selling direct, security vendors increasingly lean on regional distributors with existing trust and reach to accelerate adoption among smaller and mid-sized MSPs.  

 

The post Huntress Signs Giacom to Widen UK MSP Access to Managed Detection and Response appeared first on IT Security Guru.

The industries being reimagined by AI

2 July 2026 at 08:29

Throughout human history, technology has changed what we think is possible. Once, communication meant sending a letter. Now, we are all buried under a constant stream of emails, messages and notifications.

AI marks another major inflection point. For the first time, ordinary people can communicate with computers in natural language, not code. That shift is already reshaping whole industries, changing how work gets done, how decisions are made, and how quickly ideas can move from concept to reality.

In this article, I’ll look at three industries already being transformed by AI, and one that could be next.

DNA research

DNA research may not be the first industry that comes to mind when people think about AI, but it has already been transformed by it.

The reason is simple: AI is extremely good at processing vast amounts of complex data. In genetics, that matters enormously. Tools such as Google DeepMind’s AlphaGenome developed by the team led by Demis Hassabis, are helping researchers analyse DNA with a level of speed and precision that would have been unthinkable only a few years ago.

Calculations that once took hours can now be completed in seconds. That gives scientists a clearer view of how DNA works, how mutations develop, and what those mutations might mean for human health.

In practical terms, AI can help researchers track changes in DNA and forecast their likely impact. That gives scientists a serious head start in identifying which mutations matter, why they matter, and how they might contribute to disease. It is exactly the kind of groundwork that future cancer treatments will be built on.

Intelligent communication

AI is also changing the way businesses understand their own conversations.

Until recently, meetings, sales calls and internal discussions were easy to lose. Someone might take notes, but those notes were often incomplete, inconsistent or forgotten. Now, AI can record, transcribe, analyse and summarise those conversations automatically. Instead of rushing to capture every detail, teams can focus on the discussion itself.

Tools like XFactorAi, founded by AI entrepreneur John Margerison, take this a step further. Rather than simply telling you what was said, they can help identify what matters. They can flag risks, highlight opportunities, spot urgent follow-ups and show where action is needed.

That is a meaningful shift. It moves business communication from “here is a transcript” to “here is what you should do next.”

The real value is not just the time saved, although that is significant. It is the intelligence created from conversations that would otherwise disappear. Companies that properly analyse their meetings, sales calls and customer interactions can spot patterns faster. They can see what customers are asking for, where frustrations are building, and where opportunities are being missed.

Listening better has always been good business. AI simply makes it easier to listen at scale.

Advertising and branding

Image generation is still a relatively new part of AI, but it is already changing advertising, branding and creative production.

For small businesses, this is a huge breakthrough. Companies like Sourceful are making it possible to turn a website, logo or product image into professional-grade visual assets. What once required a studio, photographer, production team and significant budget can now be produced much more quickly and affordably.

That changes what is possible for smaller brands. High-quality creative is no longer limited to companies with large marketing budgets.

AI is also changing the production process for larger design and e-commerce teams. Tools like RiverflowAI can help reduce the cost and complexity of producing advertising assets. If a product image does not look quite right after the shoot has finished, the answer no longer has to be another expensive day in the studio. AI can adjust the image, refine the setting, change the background, and help creative teams get closer to the result they need.

If everything was shot against a pink background but the creative director now wants blue, that kind of change can be made quickly. What used to be a logistical problem becomes a creative adjustment.

That is why AI is so significant for advertising. It does not just make production cheaper. It makes creative work more flexible.

Forward-looking farming

Farming could be one of the next industries to be elevated by AI.

 

Take pesticide use. Traditionally, a farmer might spray a whole field to deal with weeds. With AI-powered computer vision, tractors can identify exactly which areas need treatment and apply pesticide only where it is required. Companies such as John Deere, led by CEO John May, are already developing this kind of precision agriculture technology, using AI and automation to help farmers treat crops more accurately. That reduces waste, protects healthy crops and lowers the amount of harsh chemicals used across the field.

The same logic applies to autonomous machinery. As self-driving vehicles become more advanced, the role of the farmer will start to change. Instead of operating one tractor at a time, farmers may increasingly manage fleets of autonomous machines working across thousands of acres.

That could make farms far more productive. A coordinated fleet could harvest faster, work longer hours, and operate during critical seasonal windows when timing matters most.

The challenge is infrastructure. Many rural areas still lack the reliable connectivity needed to support cloud-based AI systems. If a machine needs to send huge amounts of real-time data to a distant server and wait for instructions, a weak connection can create serious problems.

That creates a frustrating paradox. In many cases, the technology is ready, but the infrastructure is not.

Still, the direction of travel is clear. AI has the potential to make farming more precise, less wasteful and more productive.

From decoding cancer mutations to spotting weeds in a wheat field, the pattern is the same: AI is not simply replacing people. It is expanding what people are able to do.

The most exciting use of AI is not automation for its own sake. It is capability. It gives scientists, sales teams, designers and farmers new ways to understand problems, make decisions and act faster.

We are still at an early stage, but the direction is obvious. The industries that learn how to use AI well will move faster, operate smarter and create more value. Those that treat it as a passing trend risk being left behind.

The post The industries being reimagined by AI appeared first on IT Security Guru.

❌
❌