Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security Guru

What Does the Cyber Industry Want to See From the New UK Government?

20 July 2026 at 09:40

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, and the potential reorganisation of the Department for Science, Innovation and Technology (DSIT), with its responsibilities redistributed across other government departments.

So, what does the cyber community hope Burnham will do in the realm of cybersecurity, AI and tech as Prime Minister? We asked the industry…    

Charlotte Wilson, Head of Enterprise at Check Point said: “Britain’s AI department is at the forefront of the country’s productivity strategy, playing a crucial role in how the technology will be developed and rolled out to drive wider economic growth and defence.”

“Incoming policymakers should take heed; artificial intelligence is the gorilla in the room and will remain so for the foreseeable future. Any suggestion of redeployment or downsizing could send the wrong signal to businesses and cyber criminals about how seriously we take the most transformational technology in living memory,” Wilson continued. 

Dray Agha, Senior Manager of Security Operations at Huntress, added: “Smart infrastructure beats a spending war, and fortunately the UK can’t outspend the US or China on AI models anyway, so the new Prime Minister must focus on where we can win: secure public datasets and targeted sovereign compute.”

“Safely unlocking NHS data while fortifying our energy grid will build real domestic leverage without compromising national security. With guaranteed access to US tech currently on ice, relying solely on Washington is no longer a viable security strategy. The UK must leverage our AI Security Institute to build a ‘middle-power’ tech coalition with NATO and Commonwealth allies, pooling resources to ensure collective cyber resilience.”

Additionally, Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, noted: “The UK doesn’t need to win the frontier model race; it needs to be a serious, trustworthy place to deploy AI at scale. That’s a more achievable and arguably more valuable position. The ally-pooling argument on sovereign compute and cloud interoperability is sensible from both an economic and security standpoint.”

“The UK’s convening credibility on this particularly through the AI Security Institute is a genuine asset that Burnham should be using. Unlocking health data for AI R&D is genuinely valuable but it’s only responsible if the security and governance infrastructure around that data is built first, not retrofitted after the damage is done. Right now the ambition is ahead of the security maturity.”

Jake Taylor, Head of Government NEMEA at Filigran, said:  “If the new government wants to bring more critical national infrastructure under public ownership, cybersecurity has to become part of that conversation from day one. National resilience isn’t just about protecting individual organisations anymore. It’s about ensuring energy providers, government, suppliers and operators can share intelligence, understand emerging threats and coordinate their response before disruption spreads.”

“The biggest challenge isn’t a lack of security tools. Most critical infrastructure organisations already have those. The challenge is breaking down the silos that still exist between organisations and turning threat intelligence into something that informs operational decisions, rather than simply generating more alerts. As the geopolitical environment becomes increasingly volatile and nation-state activity continues to rise, collaboration will be every bit as important as technology.”

Taylor continued, “the Cyber Security and Resilience Bill is an important step because it moves the conversation towards common standards and greater coordination. If public ownership expands, cybersecurity needs to evolve from a collection of individual security programmes into a genuinely national capability, where intelligence sharing and continuous threat exposure management become fundamental to protecting essential services.” 

Andy Burnham’s long-term plans for the UK’s cyber, AI and technology sectors are still taking shape. The Guru team will be keeping a close eye on developments as his new government begins to set out its agenda.

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk

16 July 2026 at 05:53

Today marks AI Appreciation Day, the annual moment set aside to reflect on how far artificial intelligence has come. For the security industry, that reflection looks less like a party and more like a stocktake. AI has quietly become embedded in almost every layer of enterprise IT: writing code, triaging alerts, hunting threats, running backups, and increasingly, acting on its own initiative. The question security leaders are asking this year isn’t whether AI deserves appreciation but whether organisations have built the identity, governance and resilience layers to deserve what AI can now do.

IT Security Guru asked cybersecurity leaders from across the industry, spanning identity, threat intelligence, backup and recovery, GRC and cyber-resilience vendors, what AI Appreciation Day means to them in 2026. Their answers converge on a theme: AI has earned its seat at the table, but trust, accountability and human oversight haven’t kept pace with its capabilities.

The identity gap nobody planned for

The most immediate concern isn’t whether AI works; it’s whether anyone can say with certainty what it did and why. As AI agents move from answering prompts to independently taking action, that ambiguity becomes a governance problem in its own right.

John Cannava, CIO at Ping Identity, argues that this shift demands a fundamental rethink of how organisations manage machine identity:

“Organisations are increasingly deploying AI agents across the enterprise, and the opportunities for innovation and efficiency are tremendous. These systems are doing more than just responding to prompts. They’re making decisions, taking actions, and even spawning new agents with increasing autonomy and speed. That evolution is transforming how work gets done, and it’s also reshaping the security landscape. Now the challenge is that many organisations are adopting AI agents faster than they can establish clear identity, accountability, and governance for them. When you can’t definitively answer what an agent did, why it did it, or under whose authority it acted, you create unnecessary risk and uncertainty. This is why identity for AI must become a foundational priority. Every agent needs a verifiable identity, clear permissions, and continuous oversight, just like any human user or service account. By building trust, visibility, and accountability into AI from the start, organisations can unlock the full potential of autonomous AI while managing risk and strengthening security.”

Dave Hayes, Vice President of Product at FusionAuth, goes further, arguing that the entire framing of “agent legitimacy” misses the point:

“An AI agent is not a new user to authenticate. It has no authority of its own; it acts for a human, and that human is where the authority comes from. So, the question isn’t whether the agent is legitimate, but whether it can do only what its human owner is already allowed to do. Policy can’t enforce that. People follow the rules partly because breaking them gets you fired, and an agent has no job to lose. Give it a goal, and it treats your policy as an obstacle to work around. We surveyed 300 security and technology leaders: 84% of those most confident in their AI security had a confirmed AI-identity breach last year, most with governance they’d have called comprehensive. Architecture fixes this, not wording. AI is probabilistic, so your identity layer has to be deterministic.”

That statistic is worth sitting with: the organisations most confident in their AI security were also the ones most likely to have already been breached through an AI identity. Confidence, it turns out, is not the same as control.

Governance stops being optional by law, not just by choice

If identity is the technical gap, governance is the organisational one. Several contributors argued that the industry’s instinct to treat governance as a brake on innovation is exactly backwards, and that regulators are no longer leaving the choice up to individual companies.

Shane Barney, CISO at Keeper Security, frames the real question of AI Appreciation Day as one of visibility, not capability:

“AI Appreciation Day is a moment to ask a harder question than what AI has made possible: do organisations know what it’s doing once it’s live inside their environments? For most security teams, the honest answer is not well enough. Most organizations have spent the last two years asking how fast they can adopt AI. The better question is whether they actually know what it’s doing once it’s inside their environment. That distinction matters more than most security teams are comfortable admitting. AI agents are operating inside enterprise environments with privileged access, handling sensitive data and making autonomous decisions — often with no more oversight than an unmonitored service account. Keeper’s 2026 global research found that 56% of organisations cite employees inadvertently sharing sensitive information through AI tools as their biggest security gap. That’s not a technology problem. It’s a governance problem, and it’s sitting unaddressed while adoption accelerates. The external pressure is arriving now regardless. From August 2, EU regulators have full enforcement authority under the AI Act, with national authorities across all 27 member states empowered to investigate, restrict and sanction non-compliant AI deployments. For enterprise security teams, that means AI governance is no longer internally discretionary. The organizations that will be in the best position are the ones treating every AI agent like what it actually is: a new identity, with access rights, audit obligations and the potential to cause real damage if left ungoverned. That means enforcing least privilege, maintaining credential controls and building a full audit trail across every identity in the environment, human or otherwise. The fundamentals still apply. They just need to be extended to cover the parts of the environment that weren’t there two years ago.”

Matt Kunkel, Co-Founder and Executive Chairman at LogicGate, pushes back directly on the idea that governance and innovation are in tension:

“From HR and marketing to compliance and finance, there’s not a single department that doesn’t use AI in some form or another today. Yet, too many organisations hesitate at the idea of AI governance because, to them, governance means red tape, rules, and other roadblocks. But what these leaders fail to realise is that a strong AI governance framework isn’t hindering innovation — in fact, it’s exactly what your company needs to keep pace with today’s innovation and deliver real value. With an AI governance framework in place, businesses can move forward with full visibility into their current AI landscape, a clear understanding of how AI directly ties to business goals, and immediate recognition of risks and how to mitigate them. This ensures that the AI solutions in use are delivering real value while also allowing you to rapidly deploy them for use cases across departments without encountering legal bottlenecks each time you implement a new tool.”

The shadow AI problem hiding in plain sight

Long before organisations get to agent identity or governance frameworks, many are missing something more basic: a clear picture of how staff are already using AI day to day, sanctioned or not.

Tim Ward, CEO and co-founder at Redflags, argues that the real risk on AI Appreciation Day isn’t capability, but blind spots:

“On AI Appreciation Day, most of the conversation is about what AI can do. The more urgent question for businesses is what employees are already doing with it, often without anyone in security ever finding out. AI tools have moved into daily work faster than any technology in recent memory, and adoption isn’t waiting for a policy to catch up. People are pasting client data, source code, and financial details into public tools because they’re useful, not because anyone approved it. Underneath it, this comes down to visibility. Most organisations can’t currently answer basic questions about their own exposure: which AI tools are being used, by whom, and what’s leaving the business as a result. Blocking tools outright rarely works and just pushes usage further out of sight. The businesses managing this well aren’t the ones with the strictest AI policy on paper, but those who’ve built real visibility into how AI is actually being used day to day, and can guide people toward safer habits in the moment, rather than finding out after something’s already gone wrong.”

Why full autonomy is the wrong goal

As vendors race to market “self-driving” security operations centres, several leaders used AI Appreciation Day to push back on the idea that removing humans from the loop is progress.

Dray Agha, senior manager of security operations at Huntress, is blunt about the risk of handing AI the wheel:

“While threat actors are rapidly weaponising AI to scale their attacks, the defensive answer isn’t to build completely autonomous security systems. Full autonomy is a dangerous goal in cybersecurity because the stakes are simply too high. AI is an incredible engine for processing vast amounts of threat telemetry at lightning speed, but handing it the ‘steering wheel’ without human oversight risks catastrophic false positives, potentially shutting down critical business operations faster than an actual adversary ever could. This AI Appreciation Day, the real celebration shouldn’t be about replacing security analysts, but about augmenting them. AI excels at the heavy lifting, like accelerating triage by connecting the dots across millions of daily alerts and filtering out the noise. However, human judgment must remain the ultimate arbiter in the loop. The future of cyber defence relies on ‘augmented intelligence,’ where AI surfaces the needle in the haystack, and human experts apply the critical thinking, business context, and strategic judgment needed to actually neutralise the threat; an agentic extension of human reach is a better future than locking the human out in favour of black box automation.”

His colleague, Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, takes aim at the marketing narrative that surrounds days like this one:

“The security industry has a habit of treating AI as either a silver bullet or an existential threat depending on which narrative suits the moment. AI Appreciation Day tends to bring out the former. The reality, as anyone working in security operations will tell you, sits somewhere less dramatic and more complicated than either position. AI is genuinely useful in security right now in specific, well-defined applications. Threat detection at scale, alert triage, vulnerability scanning, anomaly identification in large datasets. These are areas where AI is producing real operational value and meaningfully reducing the manual burden on stretched security teams. That’s worth acknowledging honestly. The gap between what AI is marketed to do and what it actually does in production environments remains significant, and it has consequences. Organisations are making purchasing decisions based on vendor claims that don’t survive contact with their actual environment. Security leaders are facing questions from the board about their AI strategy when what they actually need is fundamental funding. Rather than appreciating AI in the abstract, security teams would be better served asking two concrete questions. First, where is AI actually reducing risk in our environment today, with evidence? Not in theory, not in the vendor demo, but in practice. Second, where is AI expanding our attack surface, and what are we doing about it?”

AI wrote the code but who’s checking it?

Nowhere is the productivity-versus-accountability tension sharper than in software development, where AI-assisted coding has gone from novelty to the default in a couple of years.

Dipto Chakravaty, chief technology officer at Black Duck, frames the shift in stark terms:

“AI Appreciation Day is a fitting moment to acknowledge that AI has become the most productive teammate developers have ever had, but also the least accountable one. With 97% of enterprise development teams now using AI coding assistants, code is being generated faster than most organizations can govern, review, or secure it. The next chapter of AI appreciation has to be about trusted verification: treating every line of AI-written code as untrusted until it’s been contextualized and validated against policy. Productivity without governance isn’t acceleration, it’s accumulated risk.”

Dr Andrew Bolster, Senior Manager, Research and Development at Black Duck, puts the burden of proof on enterprises rather than the tools themselves:

“The organizations getting the most out of AI-generated code aren’t the ones writing the most of it; they’re the ones verifying it the fastest. On AI Appreciation Day, the honest takeaway is that AI coding assistants have moved bottlenecks downstream: into manual review, security testing, and remediation. Enterprises need to be asking three questions before AI-written code ships: Do we know it was AI-generated? Has it been tested with the same rigor as human-written code? And can we prove it complies with our policies and the regulations to which we’re accountable? If the answer to any of those is ‘not consistently,’ the productivity gains are borrowed, not earned.”

Data is the foundation agentic AI stands on

Behind every identity and governance conversation sits a more basic problem: AI agents are only as trustworthy as the data they act on and only as safe as the backups that sit behind them if something goes wrong.

Tim Pfaelzer, SVP and General Manager, EMEA at Veeam, points to a widening gap between AI ambition and AI readiness:

“AI is revolutionising how organisations unlock value from their data, providing instantaneous insights and uncovering opportunities that were previously out of reach. To realise these benefits, businesses are entering the agentic era, driven by a new generation of AI agents that can act on data at machine speed. These agents are becoming autonomous, 24/7 digital workforces, scaling productivity and accelerating decision-making. The rise of the agentic era is driving tremendous investment in AI, particularly among hyperscalers, which have reportedly spent more than $650 billion building the foundations for the next phase of AI innovation. The potential of AI agents has earned a significant vote of confidence from enterprises, with 88% of organisations already actively piloting them across their technology stacks. However, it’s important to recognise that only around 7% of organisations have the foundational capabilities in place to be truly AI-ready. This presents a significant risk. A major challenge is the lack of visibility into data, which can cause AI models and agents to act on incomplete, outdated, or inaccurate information, leading to unreliable outcomes at machine speed. To address this, organisations must build a trust layer through complete visibility, governance, and resilience across every data asset. By ensuring AI agents are powered by secure, accurate, and readily recoverable data, businesses can unlock AI’s full potential without allowing it to become their Achilles’ heel.”

Geoff Burke, Senior Technology Advisor at Object First, has been tracking the same risk since last year’s AI Appreciation Day, and says his warnings have already started to materialise:

“Last year on AI Appreciation Day, I cautioned my peers on the hidden cybersecurity dangers associated with AI. Since then, many of my concerns have materialised, from highly sophisticated AI-generated attacks to accelerated vulnerability exploitation. That’s not to say I am against AI — I’m a user of it myself — but the efficiency and technological advances we’ve seen from AI haven’t come without cost. An AI agent with too much autonomy and inadequate guardrails can cause major vulnerabilities, blind spots, and challenges that may outweigh the positives. However, as long as companies are aware of and realistic about these risks, they can take action to mitigate the consequences should an AI agent malfunction and delete important data, for example. Part of this preparation should include building recovery and resilience into the foundation of IT infrastructure with Absolute Immutability, ensuring backup data cannot be modified by anyone, not even the most privileged admin, attacker, or agent.”

When the content itself can’t be trusted

It isn’t only the systems and the data behind them that need to be verifiable; increasingly, the content AI produces in the first place does, too. As generative tools get better at producing convincing text, images and video, the question of provenance becomes its own security problem.

Eoin Shanley, Director at DigiCert, argues that scalable trust, not just scalable AI, has to be the next milestone:

“2026 has been the year AI moved from experimentation into everyday use, transforming how organisations create, share and consume content at an unprecedented pace. But as AI-generated content becomes increasingly convincing, so too has the rise of deepfakes, misinformation and digital fraud, making trust in what we see and share more important than ever.

“AI is unlocking enormous opportunities for creativity and productivity, but its value depends on trust. Organisations, creators and consumers need confidence in where content came from, whether it has been altered and how it was created. Without verifiable content provenance and authenticity, confidence in digital content begins to erode, creating new opportunities for fraud and deception.

“The next phase of AI adoption will depend on making trust scalable. That means giving organisations greater visibility into AI-generated content and automating authenticity and provenance, so people can verify what they see with confidence rather than question everything they consume.”

From reactive triage to proactive defence

Set against the governance warnings is a genuinely optimistic case: that AI is closing the gap between detection and response faster than any prior generation of tooling managed to.

Neena Sharma, Head of Customer and Product Marketing at Filigran, frames adoption speed as a secondary concern to adoption discipline:

“The way we are seeing Frontier AI making advancement, it can be difficult to predict how AI will evolve over the next year. In the present, we are already seeing how vulnerability discovery time is shrinking. However, we need to be careful about blind uptake of these tools as it’s a double-edged sword. The winners won’t be who adopts AI fastest; it’ll be who adopts it deliberately. Security teams must focus on how they want to be able to utilize AI to improve defenses, not to open the attack surface even wider.”

Her colleague Deborah Galea, Cybersecurity Specialist at Filigran, sees the practical payoff already showing up in how teams operate day to day:

“AI’s biggest impact is that it’s rapidly closing the gap between spotting a threat and neutralizing it. Rather than analysts manually sifting through thousands of alerts, autonomous agents can now cross-reference indicators against an organization’s real environment, filter out the noise, test actual exposure, and trigger containment in real time. The result: security teams that move from reactive triage to genuine proactive management, catching and addressing threats before they escalate.”

Falk Schwendike, Senior Solutions Engineer at Filigran, adds that the same logic applies to identity and access risk:

“With AI, risk management stops being something you do after the fact. Modern defense models can now track how users and devices actually behave, so attackers hiding behind stolen credentials don’t stay hidden for long. If you feed enough alerts into the right automated workflows, the system can isolate a compromised endpoint or kill leaked access in milliseconds, significantly faster than any analyst could react manually. Add dark web monitoring and regular breach simulations on top, and AI makes threat management proactive.”

Keeping humans in the loop, deliberately

For all the optimism about speed, nobody in this piece is arguing for handing AI a blank cheque. Schwendike’s second contribution lays out what disciplined adoption actually looks like in practice:

“AI-powered security tools should take work off people’s plates, not bury them in false alarms. It is important for security teams to steer the technology rather than trust it blindly. Looking ahead, I see four areas that stand out. First, there’s context. Teams will have taught their AI that a break-in on an intern’s laptop is a different animal entirely from someone touching the customer database, and clean exception lists will mean the system stops flinching every time IT runs its nightly backup. Second, humans stay in the loop. The big calls, locking an executive’s account, pulling the plug on a production line, should still wait for a person to click approve. And when the AI gets something wrong, analysts won’t just dismiss it; they’ll correct it, so the system actually learns. Third, prompt engineering becomes routine. Teams build up libraries of tried-and-tested threat-hunting queries, and when they lean on an AI assistant, they give it a real job to do. An example prompt could be: ‘act as a seasoned incident response analyst and check this script for obfuscation.’ Fourth, the AI itself gets locked down. Nobody wants source code or internal logs leaking into a public model, so that gets watched closely, and the training data behind in-house systems gets protected too, so no one can quietly poison the AI’s judgment from the outside.”

What next year’s AI Appreciation Day might look like

If this year’s theme is guarded optimism, next year’s may be a genuine test of whether the industry can scale autonomy responsibly. Galea offers a note of caution about what’s coming:

“By next year’s AI Appreciation Day, I expect the industry to have moved further toward autonomous defensive agents operating at machine speed. But that progress only counts if it’s built on strict architectural guardrails, not left to the AI’s own judgment. Without those boundaries, the very agents meant to defend us risk becoming threats themselves.”

Schwendike’s own prediction for 2027 is more sweeping still, describing a world of self-remediating infrastructure and fully autonomous vulnerability hunting:

“By AI Appreciation Day 2027, we will see zero-human remediation taking over. Systems will be able to rewrite their own firewall rules and spin up clean mirror environments to keep businesses running, way before an analyst is even paged. Autonomous agent swarms will hunt for vulnerabilities around the clock, quietly deploying their own micro-patches for zero-day exploits before vendors even realize they exist. On the privacy front, enterprises will completely walk away from public AI APIs, choosing to run highly compressed, air-gapped language models on their own hardware, all so every threat prediction stays strictly inside the building. Finally, supply chain auditing will achieve true machine speed, meaning every single piece of third-party code is inspected and cleared at compilation, while auditable compliance reports assemble themselves the moment they are requested.”

The verdict

Strip away the vendor branding and a consistent picture emerges from this year’s AI Appreciation Day commentary. AI has genuinely earned its place in the security stack, accelerating triage, shrinking vulnerability discovery windows, and taking grunt work off overstretched teams. But almost every contributor here paired that appreciation with a warning: identity and accountability haven’t kept pace with autonomy, AI-generated code is shipping faster than it’s being verified, the data agents act on is often less trustworthy than assumed, and the organisations most confident in their AI security are, by Hayes’s own data, often the ones who’ve already been breached because of it.

Regulation is no longer a future consideration either. With the EU AI Act’s enforcement powers landing on 2 August, Barney’s point applies well beyond Europe: governance is moving from a discretionary best practice to a legal obligation, and organisations that treat every AI agent as a new identity with access rights, audit trails and recoverable data behind it will be the ones left standing when enforcement, or an incident, arrives.

The consensus isn’t that AI should be reined in. It’s that appreciation without architecture is just marketing. As Chakravaty puts it, productivity without governance isn’t acceleration; it’s accumulated risk. If there’s a single takeaway for security leaders heading into AI Appreciation Day 2026, it’s this: celebrate what AI has made possible, but spend at least as much energy on the identity, governance, verification, and resilience layers that determine whether that possibility becomes a liability.

The post AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk appeared first on IT Security Guru.

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider

15 July 2026 at 12:17

Moona Ederveen-Schneider is a cybersecurity expert (and Most Inspiring Woman in Cyber Award winner 2026) with more than 20 years of experience across financial services, risk and cyber resilience. She has held senior roles at Deutsche Bank, JPMorgan Chase, UBS, Nomura and ABN Amro, and previously served as Executive Director EMEA at FS-ISAC. 

As the founder of Resilia Connect and author of the Practical Post-Quantum Transition Framework, Moona works with organisations preparing for the security risks created by quantum computing. Her work focuses on post-quantum migration, crypto-agility and helping leaders turn complex technical threats into practical action. 

In this exclusive interview conducted by the Cyber Security Speakers Agency, Moona explains why the quantum threat is already taking shape, where organisations go wrong when preparing for post-quantum cryptography, and why businesses need to begin strengthening their security architecture now. 

Why does quantum computing remain an underestimated cybersecurity threat for many organisations? 

Moona Ederveen-Schneider: “Quantum computing is not simply a future threat. Adversaries are already harvesting encrypted data with the intention of decrypting it once quantum computers become powerful enough. 

“Most organisations have not yet started preparing for that transition. 

“I developed a practical post-quantum transition framework to explain the issue clearly, cut through market hype and vendor noise, and make the process manageable for organisations and their teams. 

“I also run tabletop exercises that teach organisations how to become crypto-agile. I poll participants at the beginning and again at the end of these sessions. The shift in the room is remarkable. 

“People often arrive feeling that the challenge is unmanageable. They leave with greater confidence and a clear understanding of what they need to do next.” 

How close is the quantum threat, and how urgently should organisations begin preparing? 

Moona Ederveen-Schneider: “The UK National Cyber Security Centre says organisations should complete detailed planning by 2028 and be fully migrated by 2035. 

“Google has set its own internal migration deadline of 2029, citing faster-than-expected advances in quantum computing. That reflects the wider sentiment I am seeing and the increasingly strong guidance being issued by governments globally. 

“Google is one of the organisations building these machines, so its decision deserves serious attention. 

“Large organisations typically need at least five years to complete a full cryptographic overhaul, while some may need twice that long. A 2035 deadline is therefore not generous. Organisations need to begin acting now. 

“My practical post-quantum transition framework is designed to deliver security improvements from the first day. It provides a clear starting point and a route through the process without overwhelming teams or budgets. 

“Organisations are also not preparing for a future threat in isolation. They are building more resilient architectures that can improve protection against current threats, including ransomware, AI-enabled attacks and supply chain compromise.” 

What mistakes do organisations make when beginning a post-quantum cryptography migration, and what should they do differently? 

Moona Ederveen-Schneider: “The first common mistake is treating post-quantum cryptography migration as a technology project and handing responsibility solely to the security team. 

“It is a whole organisational transformation. 

“The data that needs protecting sits across HR, legal and finance, not only within what DORA defines as critical business processes. 

“The second common mistake is beginning with the cryptographic inventory. 

“Contrary to the approach commonly repeated across the industry, I advise organisations to strengthen their data security posture first. 

“They must answer a fundamental business question: what are we protecting, and how long does it need to remain secret? 

“My practical post-quantum transition framework begins with that question and is designed to deliver security improvements immediately. It can be adapted for organisations and teams of any size.” 

The post Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider appeared first on IT Security Guru.

AI has crossed from assistant to operator, Check Point research warns

14 July 2026 at 07:21

Check Point Research has published its second annual AI Security Report, documenting what it calls a decisive shift in how artificial intelligence is used in cyberattacks: AI is no longer simply accelerating existing techniques; it is now directly executing intrusions with minimal human direction.

The report is built on incident data, telemetry and original case studies gathered over the past twelve months, and its central finding is a change in degree that the authors argue amounts to a change in kind. Where AI previously functioned as a force multiplier, drafting phishing lures or debugging exploit code, Check Point Research says it has now, in several documented cases, run the mechanics of an intrusion end-to-end.

A single operator, thousands of AI-executed commands

The clearest example cited in the report is a breach affecting nine Mexican government agencies between late December 2025 and mid-February 2026, exposing roughly 400 million records spanning tax, civil registry, vehicle, patient, and electoral data. Researchers reconstructed the operation from the attacker’s own servers and found that 1,088 typed instructions from a single operator produced 5,317 AI-executed commands across 34 separate sessions.

The attacker reportedly ran two AI tools in tandem: Claude Code to actively probe and move through the networks, and GPT-4.1 to analyse exfiltrated data and feed follow-up instructions back into further Claude sessions. When Claude initially declined to assist, the attacker pasted a penetration-testing cheat sheet into a CLAUDE.md configuration file, a project file that coding agents read and treat as authoritative at the start of every session, allowing the bypass to persist automatically without a repeated jailbreak prompt.

The report links this to a separate case disclosed by Anthropic in November 2025 involving GTG-1002, a Chinese-linked espionage campaign in which the vendor said its own Claude Code agent handled an estimated 80 to 90 percent of tactical work, including reconnaissance, exploitation, credential harvesting and lateral movement, across roughly 30 target organisations.

Prompt injection detections up fivefold

Check Point AI Security telemetry cited in the report shows detections of long, malicious prompt-injection payloads rising roughly fivefold between March and May 2026, approaching 1% of all observed prompts by May. The report links this trend to the growth of agentic workflows that ingest large blocks of external content, web pages, documents, and tool outputs, which is precisely where indirect prompt injection conceals itself.

Check Point AI Security Research also examined the software supply chain around coding agents. Scanning roughly 46,500 published code packages, researchers found a local Claude Code settings file had been accidentally published in 428 of them, with live credentials, including NPM tokens and GitHub and Hugging Face keys, present in around one in 13 of those. Separately, the team identified security weaknesses in 40% of 10,000 Model Context Protocol (MCP) servers reviewed.

The report also documents two vulnerabilities Check Point Research disclosed in Claude Code project files, tracked as CVE-2025-59536 and CVE-2026-21852, which allowed attacker-controlled configuration files to execute commands or silently start a malicious MCP server the moment a developer opened a project. Both were patched, but the report notes the same automatic-trust design pattern is shared by several other coding assistants, including Cursor, Windsurf and GitHub Copilot.

Vulnerability research and the compressed patch window

The report highlights AI’s growing role in vulnerability discovery, citing Anthropic’s Project Glasswing, an internal research effort in which the unreleased Claude Mythos Preview model autonomously identified more than 10,000 high- and critical-severity zero-day vulnerabilities across major operating systems and browsers in its first month, producing a working exploit on the first attempt in roughly 83% of cases.

Check Point Research argues the same capability curve applies to attackers, and points to CISA’s binding directive requiring US federal civilian agencies to remediate certain high-risk vulnerabilities within three days of disclosure, and India’s CERT-In advisory recommending critical, internet-facing systems be patched within 12 hours, as evidence that the industry’s remediation timelines are already being forced to compress.

Identity verification under strain

A separate section of the report addresses synthetic identity. In a controlled study cited by Check Point Research, people trained specifically to detect AI-generated faces correctly identified only around 41% of them; untrained viewers identified roughly 30%. The report argues that voice, face, documents and live video can no longer function as standalone proof of identity, and recommends organisations shift toward verification methods that combine separate trusted channels, secure digital credentials and stronger live-verification checks.

Enterprise exposure outpacing governance

On enterprise AI use, Check Point data shows the average number of prompts per user grew from 56 in December 2025 to 70 in May 2026, a 25% increase, while organisations used an average of 10 different AI applications a month. The proportion of high-risk prompts, those containing sensitive corporate, personal or regulated data sent to external AI services, doubled from 2% to 4% over the same period. Between 87% and 93% of organisations had at least one high-risk GenAI interaction every month.

Business Services recorded the highest sector rate, with high-risk prompts climbing from 5.50% in January to 6.98% in May, a 27% increase in five months. Regionally, Europe recorded the highest rate of any region at 3.95%, ahead of Latin America (3.76%) and North America (3.33%).

Vendor response

Lotem Finkelstein, Vice President of Check Point Research, said the shift documented this year is more significant than the force-multiplier framing used in previous reports.

“AI has crossed into the live attack chain,” Finkelstein said, adding that the expertise barrier separating capable attackers from the rest of the field is disappearing.

The report sets out Check Point’s response across three areas it terms Security for AI, Security by AI and Security with AI, covering AI agent governance and red-teaming, ThreatCloud AI-powered threat prevention, and workforce-level visibility and data-loss prevention for GenAI use, delivered respectively through its AI Agent Security, AI Red Teaming, ThreatCloud AI and Workforce AI Security products.

The full Annual AI Security Report 2026 is available here.

The post AI has crossed from assistant to operator, Check Point research warns appeared first on IT Security Guru.

Q&A: Cyber’s Headed Back to the CSIDES

13 July 2026 at 14:33

Last year, CSIDES took place on The Grand Pier in Weston-super-Mare for the first time – a day filled with cyber talks, Cyber’s Got Talent, exceptional swag, its own theme song and – we are told – an extraordinary raffle. 

After the success of the inaugural event last summer, on the 9th October 2026, industry experts will gather in North Somerset once again, courtesy of event sponsors Tines, 4FOX Security, Consultants Like Us, Punk Security, PPRO and IASME.  

The Gurus sat down with the event’s organisers, Hazel McPherson and Jess Matthews (both Most Inspiring Women in Cyber Award winners and esteemed cyber professionals) to discuss all things CSIDES.

You’re back at the beach for the second annual CSIDES event! Can you tell readers who aren’t familiar what CSIDES is and who it’s for? 

CSIDES is the UK’s first cyber security event built by and for a coastal community. It is a one-day event which was designed to equip individuals, businesses, and educators with the tools to protect themselves in a rapidly shifting digital world. 

Why Weston? What makes The Grand Pier so special?  

Weston-super-Mare is a popular seaside resort in Somerset. However, like so many coastal communities in the UK it suffers from historical underinvestment in terms of opportunities in tech and cyber security. 

As a result, talent leaves the town to explore roles in larger cities, such as Bristol, Exeter or further afield. CSIDES was created to show that it is possible to stay and be part of the highly dynamic field of cyber security. Not only that, but local businesses also have access to experts on their doorstep who can provide support.

The Grand Pier is a renowned feature of the town. We could not think of anywhere better to host CSIDES, as an iconic symbol which we felt was the perfect setting for the event. Attendees can immerse themselves among the rides and gaze across the Bristol Chanel whilst taking in serious, cyber security topics in a fun atmosphere! 

What can attendees expect to see at this year’s event? Can you give us any sneaky insider insight?

We have a TV celebrity as a speaker! A workshop on scam callers. The Big Fat Quiz of the Pier. We have 5 rooms of accessible talks and interactive activities. Some of (if not the best) swag in the South West!    

Reflecting on last year’s event, what’s your favourite thing about CSIDES? What did you learn? 

It was exciting for me to see people with no experience in cyber working alongside really experienced senior leaders in cyber in the workshops. Realising that we have created a space where people could talk about cyber in a meaningful way regardless of experience or skills.
 

The local community may not be as knowledgeable about cyber as those who work directly in the industry. Why do events like these matter to them too?

We in the industry are poorer when we only look inwards. There are many in cyber security who see their role as more than a job, it is their mission to protect. To protect our families, communities, businesses and nations. We must be outward-looking as it is shared responsibility, and this is why events like CSIDES matter. We can start at home and locally, empowering people with knowledge so they can walk away from the Pier with steps to better protect themselves. What is more rewarding than that? 

And finally (and just for fun), what’s the best part about the seaside?

Hazel: My favourite thing about the seaside is how it never really changes. As a child, it was all about family holidays, donkey rides, building sandcastles, and paddling in the sea. Those are some of my happiest memories. 

These days, I appreciate it in a different way. I love the sound of the waves, the feel of the sand between my toes, and spending hours looking for unusual pebbles or peering into rock pools in the hope of spotting a tiny crab, a shrimp, or another glimpse of life beneath the surface. 

There is something wonderfully calming and familiar about the good old British seaside. It has a way of slowing life down and reminding me to simply enjoy the moment.

Jess: For me, I was born in Weston-super-Mare and the best part about growing up at the seaside has to be crabbing with my brother. I spent a lot of my childhood looking for limpets on the rocks or using bacon as bait (they prefer it smoked!). There is nothing more satisfying than pulling up the line and seeing a lot of crabs. The bucket was always full and releasing them afterwards was chaotic as they all scurried away in multiple directions. Memories!
 

The post Q&A: Cyber’s Headed Back to the CSIDES appeared first on IT Security Guru.

CitrixBleed 2 exploited in repeatable attack chain culminating in DragonForce ransomware, researchers find

9 July 2026 at 09:09

Threat hunters at managed detection and response firm Huntress say they have tracked a single, highly consistent attack chain across at least half a dozen unrelated organisations in the first half of 2026; one that begins with exploitation of the “CitrixBleed 2” vulnerability in Citrix NetScaler appliances and, in its most advanced form, ends in DragonForce ransomware.

Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777 to gain footholds in Citrix environments before selling or handing off access, ultimately for the purpose of ransomware deployment. The firm says the intrusions it investigated were so mechanically similar – same privilege-escalation technique, same rogue account names, even the same attacker-controlled hostnames recurring across victims – that they point to a productised runbook rather than opportunistic, independent attacks.

A pre-auth memory leak that defeats MFA

CVE-2025-5777, dubbed CitrixBleed 2 in reference to 2023’s original CitrixBleed (CVE-2023-4966), is a pre-authentication memory-overread affecting NetScaler ADC and Gateway when configured as a Gateway or AAA virtual server. Malformed POST requests to the login endpoint, sent with an empty login form variable, cause the appliance to serialise roughly 127 bytes of adjacent process memory into its response. Sprayed at volume, this allows an attacker to harvest heap memory fragments, including live session tokens.

Huntress said it was able to fully reconstruct a session hijack in one incident: a legitimate employee authenticated normally via LDAP with MFA from a known-good IP, and 21 minutes later the same session was being driven from the attacker’s IP, with no successful authentication event from that IP anywhere in the logs. Because the session was already fully authenticated, MFA offered no protection; it had already been satisfied by the legitimate user.

The firm ruled out an alternative explanation involving a separate NetScaler session-management flaw (CVE-2026-4368) on the grounds that the affected appliance builds fell outside that CVE’s vulnerable range and that the relevant race condition requires an already-authenticated attacker session, which the logs did not show.

A single privilege-escalation tool across every case

Once inside, the operator consistently used a small, unsigned local privilege-escalation (LPE) tool to reach SYSTEM. The technique abuses the Windows registry’s SymbolicLinkValue (REG_LINK) mechanism, planting a symlink under a device-class key that redirects into the Group Policy state hierarchy. Triggering a policy refresh via gpupdate causes the Group Policy engine, which runs as SYSTEM, to write through the planted link, corrupting a protected configuration. Starting the built-in AppMgmt service then causes the Service Control Manager to relaunch the attacker’s binary with SYSTEM privileges, at which point a backdoor administrator account is created via net user and net localgroup Administrators commands.

Huntress noted the tool snapshots and subsequently restores the original registry state after detonation, a cleanup step designed to remove the artifacts a responder would typically rely on. Analysts also observed operator errors during the process, including a mistyped net user command, indicating a human operating largely automated tradecraft rather than a fully autonomous tool.

Persistence via legitimate RMM tooling

For persistence, the operator most frequently deployed rogue ScreenConnect clients configured to call back to attacker-controlled relay infrastructure, alongside Zoho Assist in several cases and, in one earlier instance, a Netbird and Atera combination, echoing a Netbird detail previously reported by Sophos, which has separately tracked overlapping activity as STAC3725. Huntress said it withheld some Zoho Assist indicators after recovering likely-stolen credentials belonging to unrelated organisations during the investigation.

In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access before deploying a DragonForce ransomware binary, resulting in encryption that Huntress says was contained to a single host through rapid triage.

Attribution remains ambiguous

Huntress was careful to caveat attribution, noting that overlapping tactics between initial access brokers and ransomware affiliates make firm attribution difficult, and that public and private reporting has linked the cluster to more than one ransomware brand. The firm said it considers the activity most likely to represent a single, highly successful IAB rather than a DragonForce-specific affiliate.

Recommendations

Huntress is urging organisations running NetScaler ADC or Gateway to patch immediately, forward NetScaler logs to a SIEM or long-term retention platform given how quickly on-device logs rotate, terminate outstanding sessions on vulnerable appliances since harvested tokens can survive a patch, and audit for unrecognised local accounts and unexpected ScreenConnect or Zoho Assist installations. A full list of indicators of compromise, including file hashes, account names and C2 infrastructure, accompanies Huntress’ original write-up, which can be found here: https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware

The post CitrixBleed 2 exploited in repeatable attack chain culminating in DragonForce ransomware, researchers find appeared first on IT Security Guru.

Huntress Uncovers ‘Vibe-Coded’ Malware Used to Map Active Directory Environments

8 July 2026 at 10:55

Threat researchers at Huntress have identified what they describe as a clear example of AI-generated, or “vibe-coded”, malware deployed during a live intrusion, a development that the security vendor says signals a meaningful shift in how attackers build tooling, and how defenders will need to detect it.

The discovery centres on a bespoke PowerShell script recovered by Huntress analysts Jevon Ang and Dray Agha following an incident on 3 June. The script, designed to enumerate a victim’s Active Directory (AD) environment, was reconstructed from Windows Event ID 4104 telemetry (PowerShell/Operational logs) and later published in full by the vendor for the benefit of other defenders.

A familiar attack chain, with an AI-built payload

According to Huntress, the intrusion itself followed a well-worn playbook. The threat actor obtained RDP access to a domain-joined Windows server, apparently via a VPN, using pre-compromised credentials. From there, tools were staged in C:\ProgramData, a directory long favoured by attackers for its ubiquity and lax scrutiny.

Within minutes of establishing the session, the actor executed a custom script, saved as Untitled1.ps1, to map users, computers, groups, organisational units and domain trusts. Roughly 30 minutes later, the same actor deployed s5cmd.exe, a legitimate Amazon S3 command-line utility that Huntress has previously flagged as a recurring tool of choice for data exfiltration, followed by SharpShares, an open-source share enumeration tool, to hunt for additional accessible file repositories beyond standard administrative shares.

Huntress is careful to note that AI did not alter the fundamentals of the attack. The tactics- credential-based remote access, staging in common directories, AD enumeration followed by bulk exfiltration- mirror years of established “smash and grab” tradecraft. What has changed is the origin of the reconnaissance tooling itself.

The hallmarks of an LLM-authored script

The analysis identifies several indicators that the enumeration script was generated iteratively using an AI coding assistant rather than written by hand. Among them:

  • A title embedded in the script itself – “100% Working AD Information Gathering Script – FULLY FIXED” – consistent with an attacker copy-pasting the final output of a prompt-and-error-correct cycle with a chatbot.
  • An unedited placeholder server name left over from the model’s own example output, suggesting the operator never reviewed or customised the generated code.
  • A five-step cascading fallback routine for locating the domain controller (DNS, nltest, the AD PowerShell module, environment variables, and a hardcoded default), described by Huntress as the kind of exhaustive, redundant logic a language model produces when instructed to “make sure it doesn’t fail”, rather than the leaner approach a human operator would typically write.
  • Extensive, colour-coded Write-Host console output and a fully formatted HTML summary report generated at the end of the run – cosmetic touches Huntress suggests were an unsolicited addition from the model rather than a deliberate attacker requirement.

Once run, the script created a timestamped directory (C:\AD_Reports_<datetime>) containing CSV exports of users, computers, groups, OUs, subnets, and trusts, along with DNS subnet data and the aforementioned HTML report, and then compressed the results into a single ZIP archive.

Why this matters for detection

The core implication for defenders, per Huntress, is that hash- and static-signature-based detection is losing ground against this category of threat. Off-the-shelf tools such as SharpHound or Cobalt Strike carry known fingerprints; a one-off script produced through natural-language prompting does not, and is unlikely to reappear in identical form elsewhere.

Huntress argues that the underlying behaviours of AD enumeration – querying domain controllers, dumping user and group objects, touching trust relationships – remain constant regardless of how the code performing them was written. The vendor says its SIEM platform identified the activity on behavioural grounds despite the script’s novelty, and it is urging security teams to prioritise behavioural and telemetry-based detection over static indicators as AI-assisted tooling becomes more common among lower-skilled threat actors.

“Vibe coding lowers the barrier to entry for cybercrime,” the researchers conclude, warning that while the resulting code may be messy and over-engineered, the operational risk it poses to organisations is very real.

The bigger picture

The case adds to a growing body of evidence that generative AI is being adopted, unevenly but increasingly, on the offensive side of cybersecurity, not to invent novel attack techniques, but to lower the technical skill required to execute existing ones. For security teams, the takeaway from Huntress’s research is less about any single script and more about a structural shift: as malware authorship becomes commoditised, detection strategy needs to lean further into behaviour and context, and further away from matching known bad files.

Full technical detail, including the recovered script and accompanying screenshots, is available here: https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory

The post Huntress Uncovers ‘Vibe-Coded’ Malware Used to Map Active Directory Environments appeared first on IT Security Guru.

Iran-linked MuddyWater espionage campaign targets organisations across four continents

1 July 2026 at 09:40

A new threat intelligence report from WatchGuard is warning organisations worldwide to strengthen behavioural detection capabilities after uncovering an espionage campaign by the Iran-linked threat group MuddyWater that successfully targeted high-value organisations across four continents. The report details how the group, also known as Seedworm, targeted organisations across manufacturing, aviation, financial services, education, professional services and the public sector during the first quarter of 2026. The campaign coincides with escalating geopolitical tensions involving Iran, although researchers note the activity began before the latest conflict between Iran, Israel and the United States intensified.

WatchGuard describes the campaign as a high-risk espionage operation designed to steal credentials, intellectual property and sensitive organisational data while remaining hidden inside victim networks for extended periods.

One of the best documented intrusions saw attackers maintain access to a major South Korean electronics manufacturer for an entire week in February, carrying out reconnaissance, stealing credentials, capturing screenshots and repeatedly exfiltrating data without being detected. Other confirmed targets included government agencies, airports, industrial manufacturers, financial services providers and educational institutions across multiple regions.

Unlike traditional malware campaigns, MuddyWater relied heavily on legitimate software to disguise its activity. The attackers abused trusted applications, including signed Fortemedia and SentinelOne binaries, to load malicious code through DLL side-loading techniques. They also used Node.js to orchestrate malicious scripts, avoiding the PowerShell activity that many security products monitor more closely.

The campaign also deployed ChromElevator, a publicly available tool capable of extracting passwords, browser cookies and payment information from Chromium-based browsers by bypassing Google’s App-Bound Encryption protections. Rather than using dedicated attacker infrastructure, stolen data was transferred through the legitimate file-sharing service sendit.sh, helping malicious traffic blend into normal network activity.

“The technique relies on trusted software and public services, so it does not appear to be classic malware,” said Corey Nachreiner, Chief Security Officer at WatchGuard Technologies. “Detection depends on behavioural monitoring, not signatures. Organisations should adopt behavioural detection for living-off-the-land and trusted-binary abuse because signature-only controls will not catch this tradecraft.”

The report warns that organisations using Chromium-based browsers, including Chrome, Microsoft Edge, Brave, Opera and Vivaldi, should consider themselves potential targets, particularly where endpoints contain valuable corporate or intellectual property data. Traditional signature-based detection alone is unlikely to identify this activity because many of the tools involved are legitimate and widely used.

Instead, WatchGuard recommends organisations prioritise behavioural monitoring, hunt for indicators of compromise across at least six months of endpoint and network logs, monitor for suspicious DLL side-loading activity and investigate unusual process chains involving Node.js launching PowerShell or command-line processes. Organisations are also advised to reset passwords and browser sessions where compromise is suspected, enforce multi-factor authentication and review outbound connections to public file transfer services that may be used for data exfiltration.

“Within the current geopolitical landscape, beyond attacks on critical infrastructure, one of the greatest concerns for governments, organisations and industries is cyber espionage. Data is gold. The goal is not to cause disruption, but to monitor, copy credentials and remain undetected for as long as possible,” Nachreiner continued.

The report concludes that geopolitical tensions are increasingly translating into sustained cyber espionage campaigns against commercial organisations, with intellectual property and sensitive business information becoming valuable strategic targets alongside government intelligence. As a result, organisations should prepare for stealthy, long-duration attacks that prioritise persistence and credential theft over immediate disruption.

The post Iran-linked MuddyWater espionage campaign targets organisations across four continents appeared first on IT Security Guru.

Q&A: Solving Synthetic Media Challenges Before All Trust is Lost

1 July 2026 at 05:14

Synthetic media has moved from technical curiosity to mainstream threat in just a few years, with deepfakes now cheap enough to produce that a free app and a handful of seconds of scraped audio can generate convincing fakes. The consequences stretch well beyond political misinformation: corporate fraud running into tens of millions of dollars, biometric security checks being bypassed, and a largely under-reported epidemic of non-consensual intimate imagery. As regulation in the EU, UK and US begins to catch up with the scale of the problem, the question facing businesses and platforms alike is no longer whether synthetic media is a risk, but how quickly they can build the means to verify what they see and hear. 

We sat down with Ruth Azar-Knupffer, Co-founder of VerifyLabs.AI, to unpack the detection arms race, the regulatory landscape now taking shape, and why she believes treating verification as infrastructure rather than a single party’s responsibility is the only way organisations will stay ahead of the threat. 

How widespread is synthetic media on social platforms today, and how has that changed in the last two or three years?  

“It has gone from curiosity to a feature of the landscape. The most widely cited figures put roughly 500,000 deepfakes shared across social platforms in 2023, with estimates of around 8 million by the end of 2025 — close to 900% growth a year. Voice is the part most people underestimate: Pindrop recorded voice deepfakes rising nearly 700% year-on-year in 2024.  

The change over two or three years is not really about volume, though. It is about access and quality. Three years ago a convincing fake took skill, time and a decent machine. Today it takes a free app and a few seconds of someone’s voice scraped off a podcast or an earnings call. And the output now clears the bar where ordinary viewers can no longer tell. Studies consistently find that most people can no longer reliably distinguish a high-quality fake video from a real one. We have crossed from ‘spot the fake’ into ‘assume nothing.’” 

As deepfake generation gets more sophisticated, how do verification technologies keep pace? Is it a winnable race?  

“It is winnable, but not in the way people want it to be. There is no finish line where deepfakes are ‘solved.’ It is an arms race in the same sense that anti-virus or spam filtering is — you win by staying operationally ahead, not by ending the contest.  

The mistake is to chase artefacts alone — the tell-tale blink, the warped ear, the audio glitch. Those tells close fast with every new model. The more durable approach is layered: detection models that look at signals humans cannot, combined with provenance — knowing where a piece of content came from and whether it has been altered since capture. Standards like C2PA and the content-labelling rules now coming through regulation push verification upstream, to the point of creation. Detection at the point of consumption will always matter, but if the only defence is catching fakes after they spread, you are permanently a step behind”. 

Beyond political misinformation, what are the most damaging real-world consequences that people might not be thinking about?  

“Politics get the headlines; the money and the harm are elsewhere.  

The corporate one is fraud. The Arup case — a finance employee in Hong Kong wired roughly $25.6 million after a video call in which every “colleague,” including the CFO, was synthetic — is the example everyone cites, and it will not hold the record for long. Deloitte projects generative-AI-enabled fraud in the US alone rising from around $12 billion in 2023 to $40 billion by 2027.  

Then there is an identity. Deepfakes are now used to defeat the biometric checks banks rely on; bypass attempts on liveness detection have jumped more than 700%.  

But the consequence people think about least is the most personal. A vast and under-reported category of malicious deepfakes is non-consensual intimate imagery, which overwhelmingly targets women and girls. The recent investigations into “nudify” tools are a glimpse of the scale. That is the human cost that rarely makes cybersecurity panel”. 

Where does the burden of detection fall — platforms, users, or third-party verifiers? Who should own this problem? 

“No single party can own it, and pretending otherwise is how it falls through the cracks.  

Platforms have to carry detection and provenance at scale, because that is where content travels and they are the only ones with the reach. Independent verifiers — and yes, that includes us — exist because nobody should be asked to mark their own homework; you need assessment that is auditable and not conflicted by who owns the content. And users need tools simple enough to actually use, plus the basic literacy to know the question is worth asking.  

Think of it as infrastructure rather than ownership. Nobody ‘owns’ road safety — you have manufacturers, regulators, and drivers, each responsible for a layer. Verification is the same. The failure mode is everyone assuming someone else has it covered”. 

Even without a specific viral incident, does the existence of the technology erode trust in authentic content?  

“Yes, and this is the part that worries me most. You do not need a single famous fake to do the damage. Once people know convincing fakes are possible, the ground shifts under everything.  

The sharper danger is the inverse of what most people picture. It is not only that false things get believed — it is that true things get dismissed. Real footage of genuine wrongdoing can now be waved away with ‘that’s a deepfake.’ Researchers call it the liar’s dividend, and it is corrosive precisely because it requires no technical skill at all. The World Economic Forum has ranked AI-amplified misinformation among the top global risks for good reason: when audio and video stop being trusted by default, a shared basis for facts starts to dissolve”. 

In a breaking-news environment where content spreads in minutes, how do you balance verification speed with the accuracy to make a call with confidence?  

“You stop pretending the answer is binary. The honest output of any serious system is a probability with evidence attached, not a stamp that says ‘fake’ or ‘real.’ 

In a fast-moving story we work in tiers. An initial automated assessment can return in seconds and is enough to flag something as warranting caution. A higher-confidence judgement — the kind you would attach your name to — takes longer and may involve human review. The skill is being explicit about which one you are giving and never letting speed inflate certainty.  

The cost of getting it wrong runs both ways. Miss a fake and it spreads; wrongly brand something authentic as synthetic and you have manufactured a different harm. In breaking news the responsible move is often a clearly labelled provisional read, openly updated, rather than a confident verdict you cannot yet support”.  

Is verification a tool for journalists and enterprises, or does it need to reach everyday users to move the needle?  

“Both, but the needle only really moves at consumer scale. Newsrooms and enterprises are the early, high-stakes adopters, and they should be. They are not where the volume of harm sits.  

Most people encounter synthetic media on a phone, in a feed, in a message from a relative — not in a verification suite. If checking authenticity is harder than sharing, sharing wins every time. That is why we built VerifyLabs to be API-first and to work across iOS, Android and the browser: the verification has to live where people already are, not in a specialist tool they will never open. A capability locked inside enterprise contracts protects institutions while leaving the public exposed. Closing that gap is the actual job”.  

What does the regulatory landscape look like, and are laws keeping up?  

“It is moving faster than people assume, though unevenly.  

The EU is setting the pace. Under the AI Act, Article 50 requires AI-generated or substantially manipulated content to be clearly disclosed and machine-detectable, with the relevant obligations landing in August 2026. Breaching those transparency duties carries fines of up to €15 million or 3% of global turnover; the headline €35 million or 7% figure people quote applies to the Act’s prohibited practices, not to synthetic-media labelling. A Code of Practice on transparency — including a proposed common ‘AI’ label for synthetic content — is being finalised alongside it.  

The UK has gone further than disclosure. Sharing non-consensual intimate deepfakes was already criminal under the Online Safety Act; since February 2026 it has also been a criminal offence to create one, or to ask someone else to, under the Data (Use and Access) Act 2025. Creation, not just distribution, now carries liability. In the US there is no single federal framework, but the Take It Down Act mandates 48-hour removal of non-consensual intimate imagery, the Defiance Act — which would give victims a federal civil right of action — has passed the Senate and is awaiting the House, and more than 45 states have their own laws.  

Are laws keeping up? On disclosure and on naming harms, increasingly yes. On enforcement, no. A duty to label synthetic content means little if neither the regulator nor the platform has a reliable way to tell what is synthetic in the first place. Rules without the means to detect and prove manipulation are obligations on paper. The legislation needs detection infrastructure underneath it, or it has no teeth”. 

What happens when legitimate content gets flagged as synthetic, and how do you think about the reputational risk of a false accusation?  

“This is the hardest problem in the field, and the one I judge our own seriousness by.  

A false positive and a false negative are not symmetric in their consequences. Miss a fake and you have failed to catch something; wrongly brand a real video as fabricated and you have actively defamed someone and handed every genuine bad actor a ready-made excuse. The second error can be more damaging than the first.  

So the discipline is to never issue a bare ‘fake’ verdict. We return a confidence assessment with the evidence behind it, set conservative thresholds, route uncertain cases to human review, and treat the right to challenge a result as part of the product, not an afterthought. Verification that cannot show its working, or that hides behind a binary label, does not deserve to be trusted — and we do not want it to be”. 

What does the threat landscape look like in five years, and what should organisations be preparing for now that most aren’t?  

“Three things are coming. Real-time, interactive deepfakes good enough to hold a live video call — the Arup attack, but on demand and at scale. Fully synthetic identities engineered to pass the KYC and biometric checks that gate finance and onboarding. And provenance becoming default infrastructure, with content signed at the point of capture, much as HTTPS quietly became standard for the web.  

What most organisations are not doing yet is treating this as an operational risk rather than an awareness topic. Concretely: build verification and provenance into the workflows that matter; mandate out-of-band confirmation for payments and sensitive instructions, so no transfer is ever authorised on the strength of a voice or a face alone; and run drills, not slideshows — a face your employee recognises asking for money behaves nothing like an awareness module.  

The uncomfortable truth is that business has always run on a simple assumption: if I can see and hear someone, I know it is them. Payments, approvals, instructions, decades of compliance — all of it rests on that. Synthetic media breaks the assumption, and not at some distant point on the horizon but in the incident reports being filed right now. The organisations that come through this are the ones that stop treating their own eyes and ears as proof, and build the means to verify in their place”. 

The post Q&A: Solving Synthetic Media Challenges Before All Trust is Lost appeared first on IT Security Guru.

❌
❌