Normal view

There are new articles available, click to refresh the page.
Today — 22 July 2026IT Security Guru

Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective

22 July 2026 at 12:05

Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape.

The new practice brings together Bridewell’s existing intelligence-led services, original threat research and specialist analysts under a single identity, reflecting growing customer demand for threat intelligence that informs strategic decision-making rather than simply providing indicators of compromise.

According to Bridewell, organisations are looking beyond traditional security monitoring as ransomware groups become more organised, attackers exploit trusted services and social engineering campaigns become more sophisticated. Rather than reacting to incidents, businesses want intelligence that helps them anticipate threats, understand adversaries and focus security resources where they will have the greatest impact.

Led by Gavin Knapp, Head of Cyber Threat Intelligence, BCON Collective will provide strategic, operational and tactical intelligence designed to support more informed security decision-making. The team works across areas including threat detection, vulnerability prioritisation, incident response and long-term cyber resilience planning.

“Threat intelligence has become its own discipline within cybersecurity,” said Anthony Young, CEO of Bridewell. “Organisations are progressing to see it as not just something that sits alongside security operations, rather they expect it to shape strategic decisions, inform vulnerability management and strengthen incident response.

“Gavin and the team have built an exceptional reputation for producing intelligence that is both technically rigorous and genuinely actionable. As customer demand for these services continues to grow, it made sense to give this capability its own identity while keeping it firmly rooted within Bridewell’s wider cybersecurity expertise.”

Bridewell said its CTI team has built a reputation for producing original threat research covering emerging cyber threats and attacker activity. Recent research has examined ransomware groups including DragonForce, the tactics used by Scattered Spider during attacks against major UK retailers, emerging phishing techniques such as FileFix and ConsentFix, and nation-state activity linked to North Korea.

Knapp believes the real value of threat intelligence lies in helping organisations cut through the volume of available data.

“The biggest misconception about threat intelligence is that it’s about collecting more information. It isn’t. It’s about reducing uncertainty,” he said. “Every security team already has more data than it can realistically process. The challenge is knowing which threats actually matter, which risks deserve immediate attention and where to focus before attackers make the decision for you.

“Most importantly our threat research, threat intelligence and collaboration with both Bridewell offensive security, threat detection, and response capabilities allows us to provide the key components of a threat informed defense to our CNI client base.

“BCON Collective reflects the evolution of the work we’ve already been doing for our clients. It gives our threat research and intelligence capability its own identity and creates a platform through which we can share more of our research, collaborate more closely with customers and continue helping organisations stay one step ahead of an increasingly complex threat landscape.”

Alongside its advisory services, BCON Collective will expand its programme of original threat research, annual intelligence reports, threat actor profiling and strategic intelligence briefings for organisations operating across critical national infrastructure, the public sector and commercial sectors.

The post Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective appeared first on IT Security Guru.

Yesterday — 21 July 2026IT Security Guru

KeeperPAM strengthens privileged access management for global construction SaaS provider Asite

21 July 2026 at 11:01

Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations.

The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform as it looks to improve visibility, simplify administration and better secure access across its international infrastructure.

Asite provides cloud-based collaboration software for the construction industry, helping organisations manage projects ranging from digital twins and 3D models to document control and supplier collaboration. With more than 500 employees and data centres spanning nine global locations, the company required a more consistent approach to managing privileged accounts, passwords and machine identities.

According to the case study, Asite was looking to overcome the limitations of browser-based password managers alongside legacy privileged access management (PAM) and secrets management tools, which it found expensive and complex to maintain. The company also needed to securely extend privileged access controls to third-party suppliers and external partners working on customer projects.

“The deployment of KeeperPAM was extremely easy, one of the best in my experience,” said Tiago Rosado, Chief Information Security Officer at Asite. “I wish other tools were as easy to deploy.”

As part of the rollout, Asite standardised password management across its workforce using Keeper’s platform, replacing browser-based password managers with centrally managed credential controls. The organisation also implemented Keeper BreachWatch to identify compromised credentials exposed on the dark web, while Keeper Secrets Manager automated the creation and rotation of secrets and encryption keys, reducing reliance on long-lived credentials.

Keeper said the deployment reflects a broader challenge facing organisations managing privileged access across distributed IT environments. Its 2026 research found that 34% of UK employees reuse passwords across multiple accounts, while 36% of UK respondents said enforcing strong password and credential practices remains either extremely or very challenging for IT and security teams.

The vendor positions KeeperPAM as a unified, cloud-native platform that combines enterprise password management, secrets management, privileged session management, endpoint privilege management, secure remote access and dark web monitoring within a single zero-trust architecture.

“Privileged access management has become a critical control layer for any organisation operating across distributed infrastructure and third-party ecosystems,” said Darren Guccione, CEO and Co-founder of Keeper Security. “Asite’s deployment of KeeperPAM demonstrates how organisations can move from fragmented, costly legacy tools to a unified platform that enforces least-privilege access, automates provisioning and delivers the visibility their security team needs, without the complexity that has historically made PAM difficult to scale.”

The full customer case study is available on the Keeper Security website.

The post KeeperPAM strengthens privileged access management for global construction SaaS provider Asite appeared first on IT Security Guru.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

21 July 2026 at 09:17

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the report‘s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

“AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

“In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

“As attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

“Many organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

Before yesterdayIT Security Guru

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

20 July 2026 at 09:27

Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments.

The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance and runtime behaviour. The announcement comes as organisations rapidly adopt AI agents that can interact with enterprise systems and perform tasks autonomously. Because these agents rely on APIs to access data and invoke tools, Salt argues that traditional API governance has become an essential part of governing AI systems.

Rather than requiring organisations to build governance frameworks from scratch, the Policy Hub provides a library of policies that can be activated immediately and customised to suit different environments. Salt describes the approach as similar to an “app store” for agentic security, allowing security teams to deploy pre-built governance policies across the infrastructure that supports AI agents.

The expanded library includes more than a dozen policies designed specifically for agentic AI, covering areas such as MCP server configuration, agent authorisation and the risks associated with autonomous agent behaviour. Other policies address data security, OAuth, API architecture, third-party risk and compliance with frameworks including GDPR, ISO 27001, HIPAA, PCI DSS and SOC 2.

According to Salt, 61 of the 100 policies are enabled automatically, while the remaining policies can be activated with a single click. Organisations can also create their own custom policies to extend governance beyond the pre-built library. The Policy Hub forms part of the Salt Agentic Security Platform, which provides visibility across what the company calls the Agentic Security Graph, encompassing LLMs, MCP servers, APIs and connected enterprise applications.

Michael Callahan, VP of Strategy and CMO at Salt Security, said many organisations recognise the need for AI governance but struggle to know where to begin. “When we launched the Policy Hub in 2024, the most common thing we heard from CISOs was, ‘We know we need posture governance, but we have no idea where to start.’ That question was killing governance programmes before they launched. The inclusion of 100 policies means that question now has a concrete answer. Security teams can walk in on day one with meaningful protection already active and it can be extended from there without limit.”

Salt said many of the policies were originally developed for API posture governance but now play a broader role as organisations deploy AI agents. As AI systems increasingly depend on APIs, identity platforms and MCP servers to perform actions, the company believes governance must extend across the entire agentic infrastructure rather than focusing solely on AI models or prompts.

The company also highlighted its MCP server discovery capabilities, introduced in 2025, which are supported by dedicated governance policies for identifying configuration issues and controlling how MCP servers interact with enterprise systems.

In June, Salt also launched Salt Code, extending the same governance engine into the software development lifecycle to apply policies to AI-generated code during development.

Aner Gelman, VP of Products at Salt Security, said boards are increasingly asking organisations to demonstrate how AI is being governed.

“The board question CISOs are being asked right now is not whether we have AI governance. It is whether we can prove it. Having 100 policies in active deployment is a concrete, operational answer to that question. Not a roadmap. Not a strategy. An active governance layer running today.”

The 100 pre-built policies are available immediately to customers using the Salt Agentic Security Platform.

The post Salt Security tackles AI governance challenge with 100 pre-built agentic security policies appeared first on IT Security Guru.

CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging

17 July 2026 at 05:43

More than three-quarters of European CISOs believe their C-suite doesn’t fully understand the cyber risk posed by their own employees, a gap that’s widening just as AI makes attacks on human judgement faster, more convincing and harder to spot.

That’s according to new research from MetaCompliance, the human cyber risk management firm, which polled 200 CISOs across the UK, France, Germany and Sweden. The picture it paints is of security leaders trying to hold the line on human-layer risk without the consistent senior backing, clear ownership, or shared understanding they need to do so.

AI is changing what CISOs are worried about

The survey found that among CISOs who feel less confident about their organisation’s cyber resilience than they did a year ago, AI-enabled social engineering was the single biggest reason cited, named by almost half of that group. It’s a sign that attackers are moving away from crude, easily-spotted phishing and towards convincing impersonation and fraud attempts generated at scale.

Employees, unsurprisingly, remain squarely in the firing line. More than two in three CISOs still rank their own staff as the biggest security risk to the business, suggesting AI isn’t creating a new problem so much as turbocharging an old one.

Specific concerns bear that out:

  • Over 40% of CISOs are worried AI is increasing the speed and impact of social engineering attacks
  • 40% fear staff are feeding sensitive data into generative AI tools
  • 41% are concerned about malicious insiders using AI to enable fraud, cybercrime or data theft
  • In the UK specifically, deepfake impersonation stands out as a top worry — more than half of UK CISOs flagged it as a major threat, the highest figure of any country in the study

Support from the top doesn’t stick

Where the research gets more uncomfortable for boardrooms is on backing. Almost four in five CISOs (79%) say leadership enthusiasm for security awareness programmes tends to fade once the initial push is over, and 76% say they’re stuck trying to satisfy different stakeholders who all want different human-risk metrics. Roughly a quarter point to cross-functional alignment as one of the areas they feel least confident managing.

James Mackay, CEO of MetaCompliance, said AI has changed the stakes: “Attackers are no longer relying on obvious scams or poorly written phishing emails. They can now create highly convincing impersonation attempts, social engineering attacks and fraudulent communications at scale.”

He argued that puts a premium on sustained executive engagement rather than one-off initiatives: “Human cyber risk is no longer just an awareness issue or a training issue; it is a strategic business risk… If leadership support fades after the initial push, organisations are left exposed.”

Where CISOs go from here

Improving resilience against AI-driven social engineering is now a stated priority for the year ahead, with close to a quarter of CISOs naming it as a key focus. Mackay suggested the shift needs to be structural rather than seasonal: organisations that fare best will treat human risk as an ongoing management discipline rather than a periodic training exercise, giving employees real-time, contextual support at the moment a risky decision is actually being made, rather than relying solely on annual training modules.

The findings come at a moment when AI-generated phishing, deepfake voice and video, and synthetic impersonation are becoming difficult to distinguish from genuine communications — putting fresh pressure on security teams to secure top-level buy-in before the next wave of attacks arrives.

The post CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging appeared first on IT Security Guru.

AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk

16 July 2026 at 05:53

Today marks AI Appreciation Day, the annual moment set aside to reflect on how far artificial intelligence has come. For the security industry, that reflection looks less like a party and more like a stocktake. AI has quietly become embedded in almost every layer of enterprise IT: writing code, triaging alerts, hunting threats, running backups, and increasingly, acting on its own initiative. The question security leaders are asking this year isn’t whether AI deserves appreciation but whether organisations have built the identity, governance and resilience layers to deserve what AI can now do.

IT Security Guru asked cybersecurity leaders from across the industry, spanning identity, threat intelligence, backup and recovery, GRC and cyber-resilience vendors, what AI Appreciation Day means to them in 2026. Their answers converge on a theme: AI has earned its seat at the table, but trust, accountability and human oversight haven’t kept pace with its capabilities.

The identity gap nobody planned for

The most immediate concern isn’t whether AI works; it’s whether anyone can say with certainty what it did and why. As AI agents move from answering prompts to independently taking action, that ambiguity becomes a governance problem in its own right.

John Cannava, CIO at Ping Identity, argues that this shift demands a fundamental rethink of how organisations manage machine identity:

“Organisations are increasingly deploying AI agents across the enterprise, and the opportunities for innovation and efficiency are tremendous. These systems are doing more than just responding to prompts. They’re making decisions, taking actions, and even spawning new agents with increasing autonomy and speed. That evolution is transforming how work gets done, and it’s also reshaping the security landscape. Now the challenge is that many organisations are adopting AI agents faster than they can establish clear identity, accountability, and governance for them. When you can’t definitively answer what an agent did, why it did it, or under whose authority it acted, you create unnecessary risk and uncertainty. This is why identity for AI must become a foundational priority. Every agent needs a verifiable identity, clear permissions, and continuous oversight, just like any human user or service account. By building trust, visibility, and accountability into AI from the start, organisations can unlock the full potential of autonomous AI while managing risk and strengthening security.”

Dave Hayes, Vice President of Product at FusionAuth, goes further, arguing that the entire framing of “agent legitimacy” misses the point:

“An AI agent is not a new user to authenticate. It has no authority of its own; it acts for a human, and that human is where the authority comes from. So, the question isn’t whether the agent is legitimate, but whether it can do only what its human owner is already allowed to do. Policy can’t enforce that. People follow the rules partly because breaking them gets you fired, and an agent has no job to lose. Give it a goal, and it treats your policy as an obstacle to work around. We surveyed 300 security and technology leaders: 84% of those most confident in their AI security had a confirmed AI-identity breach last year, most with governance they’d have called comprehensive. Architecture fixes this, not wording. AI is probabilistic, so your identity layer has to be deterministic.”

That statistic is worth sitting with: the organisations most confident in their AI security were also the ones most likely to have already been breached through an AI identity. Confidence, it turns out, is not the same as control.

Governance stops being optional by law, not just by choice

If identity is the technical gap, governance is the organisational one. Several contributors argued that the industry’s instinct to treat governance as a brake on innovation is exactly backwards, and that regulators are no longer leaving the choice up to individual companies.

Shane Barney, CISO at Keeper Security, frames the real question of AI Appreciation Day as one of visibility, not capability:

“AI Appreciation Day is a moment to ask a harder question than what AI has made possible: do organisations know what it’s doing once it’s live inside their environments? For most security teams, the honest answer is not well enough. Most organizations have spent the last two years asking how fast they can adopt AI. The better question is whether they actually know what it’s doing once it’s inside their environment. That distinction matters more than most security teams are comfortable admitting. AI agents are operating inside enterprise environments with privileged access, handling sensitive data and making autonomous decisions — often with no more oversight than an unmonitored service account. Keeper’s 2026 global research found that 56% of organisations cite employees inadvertently sharing sensitive information through AI tools as their biggest security gap. That’s not a technology problem. It’s a governance problem, and it’s sitting unaddressed while adoption accelerates. The external pressure is arriving now regardless. From August 2, EU regulators have full enforcement authority under the AI Act, with national authorities across all 27 member states empowered to investigate, restrict and sanction non-compliant AI deployments. For enterprise security teams, that means AI governance is no longer internally discretionary. The organizations that will be in the best position are the ones treating every AI agent like what it actually is: a new identity, with access rights, audit obligations and the potential to cause real damage if left ungoverned. That means enforcing least privilege, maintaining credential controls and building a full audit trail across every identity in the environment, human or otherwise. The fundamentals still apply. They just need to be extended to cover the parts of the environment that weren’t there two years ago.”

Matt Kunkel, Co-Founder and Executive Chairman at LogicGate, pushes back directly on the idea that governance and innovation are in tension:

“From HR and marketing to compliance and finance, there’s not a single department that doesn’t use AI in some form or another today. Yet, too many organisations hesitate at the idea of AI governance because, to them, governance means red tape, rules, and other roadblocks. But what these leaders fail to realise is that a strong AI governance framework isn’t hindering innovation — in fact, it’s exactly what your company needs to keep pace with today’s innovation and deliver real value. With an AI governance framework in place, businesses can move forward with full visibility into their current AI landscape, a clear understanding of how AI directly ties to business goals, and immediate recognition of risks and how to mitigate them. This ensures that the AI solutions in use are delivering real value while also allowing you to rapidly deploy them for use cases across departments without encountering legal bottlenecks each time you implement a new tool.”

The shadow AI problem hiding in plain sight

Long before organisations get to agent identity or governance frameworks, many are missing something more basic: a clear picture of how staff are already using AI day to day, sanctioned or not.

Tim Ward, CEO and co-founder at Redflags, argues that the real risk on AI Appreciation Day isn’t capability, but blind spots:

“On AI Appreciation Day, most of the conversation is about what AI can do. The more urgent question for businesses is what employees are already doing with it, often without anyone in security ever finding out. AI tools have moved into daily work faster than any technology in recent memory, and adoption isn’t waiting for a policy to catch up. People are pasting client data, source code, and financial details into public tools because they’re useful, not because anyone approved it. Underneath it, this comes down to visibility. Most organisations can’t currently answer basic questions about their own exposure: which AI tools are being used, by whom, and what’s leaving the business as a result. Blocking tools outright rarely works and just pushes usage further out of sight. The businesses managing this well aren’t the ones with the strictest AI policy on paper, but those who’ve built real visibility into how AI is actually being used day to day, and can guide people toward safer habits in the moment, rather than finding out after something’s already gone wrong.”

Why full autonomy is the wrong goal

As vendors race to market “self-driving” security operations centres, several leaders used AI Appreciation Day to push back on the idea that removing humans from the loop is progress.

Dray Agha, senior manager of security operations at Huntress, is blunt about the risk of handing AI the wheel:

“While threat actors are rapidly weaponising AI to scale their attacks, the defensive answer isn’t to build completely autonomous security systems. Full autonomy is a dangerous goal in cybersecurity because the stakes are simply too high. AI is an incredible engine for processing vast amounts of threat telemetry at lightning speed, but handing it the ‘steering wheel’ without human oversight risks catastrophic false positives, potentially shutting down critical business operations faster than an actual adversary ever could. This AI Appreciation Day, the real celebration shouldn’t be about replacing security analysts, but about augmenting them. AI excels at the heavy lifting, like accelerating triage by connecting the dots across millions of daily alerts and filtering out the noise. However, human judgment must remain the ultimate arbiter in the loop. The future of cyber defence relies on ‘augmented intelligence,’ where AI surfaces the needle in the haystack, and human experts apply the critical thinking, business context, and strategic judgment needed to actually neutralise the threat; an agentic extension of human reach is a better future than locking the human out in favour of black box automation.”

His colleague, Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, takes aim at the marketing narrative that surrounds days like this one:

“The security industry has a habit of treating AI as either a silver bullet or an existential threat depending on which narrative suits the moment. AI Appreciation Day tends to bring out the former. The reality, as anyone working in security operations will tell you, sits somewhere less dramatic and more complicated than either position. AI is genuinely useful in security right now in specific, well-defined applications. Threat detection at scale, alert triage, vulnerability scanning, anomaly identification in large datasets. These are areas where AI is producing real operational value and meaningfully reducing the manual burden on stretched security teams. That’s worth acknowledging honestly. The gap between what AI is marketed to do and what it actually does in production environments remains significant, and it has consequences. Organisations are making purchasing decisions based on vendor claims that don’t survive contact with their actual environment. Security leaders are facing questions from the board about their AI strategy when what they actually need is fundamental funding. Rather than appreciating AI in the abstract, security teams would be better served asking two concrete questions. First, where is AI actually reducing risk in our environment today, with evidence? Not in theory, not in the vendor demo, but in practice. Second, where is AI expanding our attack surface, and what are we doing about it?”

AI wrote the code but who’s checking it?

Nowhere is the productivity-versus-accountability tension sharper than in software development, where AI-assisted coding has gone from novelty to the default in a couple of years.

Dipto Chakravaty, chief technology officer at Black Duck, frames the shift in stark terms:

“AI Appreciation Day is a fitting moment to acknowledge that AI has become the most productive teammate developers have ever had, but also the least accountable one. With 97% of enterprise development teams now using AI coding assistants, code is being generated faster than most organizations can govern, review, or secure it. The next chapter of AI appreciation has to be about trusted verification: treating every line of AI-written code as untrusted until it’s been contextualized and validated against policy. Productivity without governance isn’t acceleration, it’s accumulated risk.”

Dr Andrew Bolster, Senior Manager, Research and Development at Black Duck, puts the burden of proof on enterprises rather than the tools themselves:

“The organizations getting the most out of AI-generated code aren’t the ones writing the most of it; they’re the ones verifying it the fastest. On AI Appreciation Day, the honest takeaway is that AI coding assistants have moved bottlenecks downstream: into manual review, security testing, and remediation. Enterprises need to be asking three questions before AI-written code ships: Do we know it was AI-generated? Has it been tested with the same rigor as human-written code? And can we prove it complies with our policies and the regulations to which we’re accountable? If the answer to any of those is ‘not consistently,’ the productivity gains are borrowed, not earned.”

Data is the foundation agentic AI stands on

Behind every identity and governance conversation sits a more basic problem: AI agents are only as trustworthy as the data they act on and only as safe as the backups that sit behind them if something goes wrong.

Tim Pfaelzer, SVP and General Manager, EMEA at Veeam, points to a widening gap between AI ambition and AI readiness:

“AI is revolutionising how organisations unlock value from their data, providing instantaneous insights and uncovering opportunities that were previously out of reach. To realise these benefits, businesses are entering the agentic era, driven by a new generation of AI agents that can act on data at machine speed. These agents are becoming autonomous, 24/7 digital workforces, scaling productivity and accelerating decision-making. The rise of the agentic era is driving tremendous investment in AI, particularly among hyperscalers, which have reportedly spent more than $650 billion building the foundations for the next phase of AI innovation. The potential of AI agents has earned a significant vote of confidence from enterprises, with 88% of organisations already actively piloting them across their technology stacks. However, it’s important to recognise that only around 7% of organisations have the foundational capabilities in place to be truly AI-ready. This presents a significant risk. A major challenge is the lack of visibility into data, which can cause AI models and agents to act on incomplete, outdated, or inaccurate information, leading to unreliable outcomes at machine speed. To address this, organisations must build a trust layer through complete visibility, governance, and resilience across every data asset. By ensuring AI agents are powered by secure, accurate, and readily recoverable data, businesses can unlock AI’s full potential without allowing it to become their Achilles’ heel.”

Geoff Burke, Senior Technology Advisor at Object First, has been tracking the same risk since last year’s AI Appreciation Day, and says his warnings have already started to materialise:

“Last year on AI Appreciation Day, I cautioned my peers on the hidden cybersecurity dangers associated with AI. Since then, many of my concerns have materialised, from highly sophisticated AI-generated attacks to accelerated vulnerability exploitation. That’s not to say I am against AI — I’m a user of it myself — but the efficiency and technological advances we’ve seen from AI haven’t come without cost. An AI agent with too much autonomy and inadequate guardrails can cause major vulnerabilities, blind spots, and challenges that may outweigh the positives. However, as long as companies are aware of and realistic about these risks, they can take action to mitigate the consequences should an AI agent malfunction and delete important data, for example. Part of this preparation should include building recovery and resilience into the foundation of IT infrastructure with Absolute Immutability, ensuring backup data cannot be modified by anyone, not even the most privileged admin, attacker, or agent.”

When the content itself can’t be trusted

It isn’t only the systems and the data behind them that need to be verifiable; increasingly, the content AI produces in the first place does, too. As generative tools get better at producing convincing text, images and video, the question of provenance becomes its own security problem.

Eoin Shanley, Director at DigiCert, argues that scalable trust, not just scalable AI, has to be the next milestone:

“2026 has been the year AI moved from experimentation into everyday use, transforming how organisations create, share and consume content at an unprecedented pace. But as AI-generated content becomes increasingly convincing, so too has the rise of deepfakes, misinformation and digital fraud, making trust in what we see and share more important than ever.

“AI is unlocking enormous opportunities for creativity and productivity, but its value depends on trust. Organisations, creators and consumers need confidence in where content came from, whether it has been altered and how it was created. Without verifiable content provenance and authenticity, confidence in digital content begins to erode, creating new opportunities for fraud and deception.

“The next phase of AI adoption will depend on making trust scalable. That means giving organisations greater visibility into AI-generated content and automating authenticity and provenance, so people can verify what they see with confidence rather than question everything they consume.”

From reactive triage to proactive defence

Set against the governance warnings is a genuinely optimistic case: that AI is closing the gap between detection and response faster than any prior generation of tooling managed to.

Neena Sharma, Head of Customer and Product Marketing at Filigran, frames adoption speed as a secondary concern to adoption discipline:

“The way we are seeing Frontier AI making advancement, it can be difficult to predict how AI will evolve over the next year. In the present, we are already seeing how vulnerability discovery time is shrinking. However, we need to be careful about blind uptake of these tools as it’s a double-edged sword. The winners won’t be who adopts AI fastest; it’ll be who adopts it deliberately. Security teams must focus on how they want to be able to utilize AI to improve defenses, not to open the attack surface even wider.”

Her colleague Deborah Galea, Cybersecurity Specialist at Filigran, sees the practical payoff already showing up in how teams operate day to day:

“AI’s biggest impact is that it’s rapidly closing the gap between spotting a threat and neutralizing it. Rather than analysts manually sifting through thousands of alerts, autonomous agents can now cross-reference indicators against an organization’s real environment, filter out the noise, test actual exposure, and trigger containment in real time. The result: security teams that move from reactive triage to genuine proactive management, catching and addressing threats before they escalate.”

Falk Schwendike, Senior Solutions Engineer at Filigran, adds that the same logic applies to identity and access risk:

“With AI, risk management stops being something you do after the fact. Modern defense models can now track how users and devices actually behave, so attackers hiding behind stolen credentials don’t stay hidden for long. If you feed enough alerts into the right automated workflows, the system can isolate a compromised endpoint or kill leaked access in milliseconds, significantly faster than any analyst could react manually. Add dark web monitoring and regular breach simulations on top, and AI makes threat management proactive.”

Keeping humans in the loop, deliberately

For all the optimism about speed, nobody in this piece is arguing for handing AI a blank cheque. Schwendike’s second contribution lays out what disciplined adoption actually looks like in practice:

“AI-powered security tools should take work off people’s plates, not bury them in false alarms. It is important for security teams to steer the technology rather than trust it blindly. Looking ahead, I see four areas that stand out. First, there’s context. Teams will have taught their AI that a break-in on an intern’s laptop is a different animal entirely from someone touching the customer database, and clean exception lists will mean the system stops flinching every time IT runs its nightly backup. Second, humans stay in the loop. The big calls, locking an executive’s account, pulling the plug on a production line, should still wait for a person to click approve. And when the AI gets something wrong, analysts won’t just dismiss it; they’ll correct it, so the system actually learns. Third, prompt engineering becomes routine. Teams build up libraries of tried-and-tested threat-hunting queries, and when they lean on an AI assistant, they give it a real job to do. An example prompt could be: ‘act as a seasoned incident response analyst and check this script for obfuscation.’ Fourth, the AI itself gets locked down. Nobody wants source code or internal logs leaking into a public model, so that gets watched closely, and the training data behind in-house systems gets protected too, so no one can quietly poison the AI’s judgment from the outside.”

What next year’s AI Appreciation Day might look like

If this year’s theme is guarded optimism, next year’s may be a genuine test of whether the industry can scale autonomy responsibly. Galea offers a note of caution about what’s coming:

“By next year’s AI Appreciation Day, I expect the industry to have moved further toward autonomous defensive agents operating at machine speed. But that progress only counts if it’s built on strict architectural guardrails, not left to the AI’s own judgment. Without those boundaries, the very agents meant to defend us risk becoming threats themselves.”

Schwendike’s own prediction for 2027 is more sweeping still, describing a world of self-remediating infrastructure and fully autonomous vulnerability hunting:

“By AI Appreciation Day 2027, we will see zero-human remediation taking over. Systems will be able to rewrite their own firewall rules and spin up clean mirror environments to keep businesses running, way before an analyst is even paged. Autonomous agent swarms will hunt for vulnerabilities around the clock, quietly deploying their own micro-patches for zero-day exploits before vendors even realize they exist. On the privacy front, enterprises will completely walk away from public AI APIs, choosing to run highly compressed, air-gapped language models on their own hardware, all so every threat prediction stays strictly inside the building. Finally, supply chain auditing will achieve true machine speed, meaning every single piece of third-party code is inspected and cleared at compilation, while auditable compliance reports assemble themselves the moment they are requested.”

The verdict

Strip away the vendor branding and a consistent picture emerges from this year’s AI Appreciation Day commentary. AI has genuinely earned its place in the security stack, accelerating triage, shrinking vulnerability discovery windows, and taking grunt work off overstretched teams. But almost every contributor here paired that appreciation with a warning: identity and accountability haven’t kept pace with autonomy, AI-generated code is shipping faster than it’s being verified, the data agents act on is often less trustworthy than assumed, and the organisations most confident in their AI security are, by Hayes’s own data, often the ones who’ve already been breached because of it.

Regulation is no longer a future consideration either. With the EU AI Act’s enforcement powers landing on 2 August, Barney’s point applies well beyond Europe: governance is moving from a discretionary best practice to a legal obligation, and organisations that treat every AI agent as a new identity with access rights, audit trails and recoverable data behind it will be the ones left standing when enforcement, or an incident, arrives.

The consensus isn’t that AI should be reined in. It’s that appreciation without architecture is just marketing. As Chakravaty puts it, productivity without governance isn’t acceleration; it’s accumulated risk. If there’s a single takeaway for security leaders heading into AI Appreciation Day 2026, it’s this: celebrate what AI has made possible, but spend at least as much energy on the identity, governance, verification, and resilience layers that determine whether that possibility becomes a liability.

The post AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk appeared first on IT Security Guru.

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider

15 July 2026 at 12:17

Moona Ederveen-Schneider is a cybersecurity expert (and Most Inspiring Woman in Cyber Award winner 2026) with more than 20 years of experience across financial services, risk and cyber resilience. She has held senior roles at Deutsche Bank, JPMorgan Chase, UBS, Nomura and ABN Amro, and previously served as Executive Director EMEA at FS-ISAC. 

As the founder of Resilia Connect and author of the Practical Post-Quantum Transition Framework, Moona works with organisations preparing for the security risks created by quantum computing. Her work focuses on post-quantum migration, crypto-agility and helping leaders turn complex technical threats into practical action. 

In this exclusive interview conducted by the Cyber Security Speakers Agency, Moona explains why the quantum threat is already taking shape, where organisations go wrong when preparing for post-quantum cryptography, and why businesses need to begin strengthening their security architecture now. 

Why does quantum computing remain an underestimated cybersecurity threat for many organisations? 

Moona Ederveen-Schneider: “Quantum computing is not simply a future threat. Adversaries are already harvesting encrypted data with the intention of decrypting it once quantum computers become powerful enough. 

“Most organisations have not yet started preparing for that transition. 

“I developed a practical post-quantum transition framework to explain the issue clearly, cut through market hype and vendor noise, and make the process manageable for organisations and their teams. 

“I also run tabletop exercises that teach organisations how to become crypto-agile. I poll participants at the beginning and again at the end of these sessions. The shift in the room is remarkable. 

“People often arrive feeling that the challenge is unmanageable. They leave with greater confidence and a clear understanding of what they need to do next.” 

How close is the quantum threat, and how urgently should organisations begin preparing? 

Moona Ederveen-Schneider: “The UK National Cyber Security Centre says organisations should complete detailed planning by 2028 and be fully migrated by 2035. 

“Google has set its own internal migration deadline of 2029, citing faster-than-expected advances in quantum computing. That reflects the wider sentiment I am seeing and the increasingly strong guidance being issued by governments globally. 

“Google is one of the organisations building these machines, so its decision deserves serious attention. 

“Large organisations typically need at least five years to complete a full cryptographic overhaul, while some may need twice that long. A 2035 deadline is therefore not generous. Organisations need to begin acting now. 

“My practical post-quantum transition framework is designed to deliver security improvements from the first day. It provides a clear starting point and a route through the process without overwhelming teams or budgets. 

“Organisations are also not preparing for a future threat in isolation. They are building more resilient architectures that can improve protection against current threats, including ransomware, AI-enabled attacks and supply chain compromise.” 

What mistakes do organisations make when beginning a post-quantum cryptography migration, and what should they do differently? 

Moona Ederveen-Schneider: “The first common mistake is treating post-quantum cryptography migration as a technology project and handing responsibility solely to the security team. 

“It is a whole organisational transformation. 

“The data that needs protecting sits across HR, legal and finance, not only within what DORA defines as critical business processes. 

“The second common mistake is beginning with the cryptographic inventory. 

“Contrary to the approach commonly repeated across the industry, I advise organisations to strengthen their data security posture first. 

“They must answer a fundamental business question: what are we protecting, and how long does it need to remain secret? 

“My practical post-quantum transition framework begins with that question and is designed to deliver security improvements immediately. It can be adapted for organisations and teams of any size.” 

The post Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider appeared first on IT Security Guru.

Proton Launches Business Continuity Service to Keep Firms Communicating Through Outages

15 July 2026 at 07:37

Swiss encrypted communications provider Proton has launched a dedicated business continuity service, aimed at helping organisations keep email and video communications running when their primary IT infrastructure fails or is taken offline.

The service is built around Proton Mail and Proton Meet, and is designed to give security and IT teams a pre-configured fallback they can activate quickly during an outage, a ransomware incident, or a third-party service disruption, without requiring staff to install new software or reset credentials under pressure.

Proton said the launch responds to a threat landscape in which outages are increasingly frequent, ransomware is spreading further into the small and mid-sized business market, and organisations face growing exposure to decisions made by US-based cloud and software providers, which remain legally bound to comply with US government directives, including those restricting service to customers outside the United States.

The company argues this exposes a structural weakness common to many security architectures: because so much business email and collaboration software ultimately runs on a small number of hyperscale platforms, chiefly Amazon Web Services, Microsoft Azure and Google Cloud, a single infrastructure failure or access restriction can take down communications across otherwise unrelated organisations simultaneously.

How it works

Under Proton’s model, organisations set up two tiers of accounts in advance. Active accounts assigned to IT administrators, business continuity coordinators, and senior leadership remain configurable and testable at any time. Dormant accounts, provisioned for the wider workforce at a reduced cost, remain inactive in the background, tied to the correct user identity and permission group until needed.

When an incident is declared, an administrator makes a single DNS change, repointing the organisation’s MX record to Proton’s mail servers instead of its usual provider. Dormant accounts are activated when employees log in with credentials or access links distributed by their administrator, after which the whole team can continue operating on Proton’s infrastructure, which the company says is fully separate from Google, Microsoft and AWS.

Organisations can also pre-configure their existing email domain inside Proton Mail, or set up a secondary domain to test failover in advance, allowing continuity plans to be rehearsed before they are ever needed.

A security case built on jurisdiction and encryption

Proton is positioning the service as much on legal and jurisdictional grounds as on technical ones. The company’s infrastructure and legal base sit in Switzerland, which it describes as neutral territory outside both the Big Tech ecosystem and US regulatory reach. Proton Mail and Proton Meet use end-to-end encryption, and the company points to a decade-long uptime record, underpinned by a 99.95 percent service-level agreement, as evidence of its resilience credentials.

Raphael Auphan, Chief Operating Officer at Proton, said organisations increasingly need to plan for disruption that is political as well as technical in origin. “Whether it’s in a week or a year, preparing now will make the difference between a managed response and an operational crisis,” Auphan said.

Proton already counts more than 100,000 organisations as Proton Mail users, and offers an Easy Switch for Business tool for firms migrating their primary email service outright. The new continuity offering is aimed instead at organisations that want an emergency fallback without giving up their existing primary provider.

Security teams considering the service will need to weigh the operational overhead of maintaining dormant accounts and rehearsed failover processes against the risk reduction it offers — a trade-off likely to depend on an organisation’s existing business continuity maturity and its risk appetite around single-vendor dependency.

The post Proton Launches Business Continuity Service to Keep Firms Communicating Through Outages appeared first on IT Security Guru.

Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards

14 July 2026 at 12:28

New research from Forescout has uncovered a sophisticated phishing campaign that uses fake seasonal eCard invitations to trick victims into installing legitimate remote management software, giving attackers long-term access to compromised devices.

The campaign, dubbed SeasonalInvite by Forescout Research’s Vedere Labs, has been active since at least January 2026 and demonstrates how cybercriminals are increasingly combining social engineering, trusted enterprise software, and AI assisted development techniques to evade traditional security defences.

The full research is available here: SeasonalInvite research

Fake eCards lure victims

According to the report, the attackers use phishing emails disguised as seasonal eCard invitations to persuade users to install legitimate Remote Monitoring and Management (RMM) tools.

Rather than deploying traditional malware, the campaign abuses commercially available software that is commonly used by IT administrators for remote support. Once installed, the tools provide attackers with persistent remote access to compromised systems.

The campaign targets both Windows and macOS users.

During its investigation, Forescout confirmed the abuse of four legitimate RMM platforms:

  • ConnectWise ScreenConnect
  • LogMeIn Resolve
  • Kaseya
  • O&O Syspectr

Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.

Hundreds of phishing domains identified

Researchers identified a large infrastructure supporting the campaign, including 959 domains themed around electronic greeting cards.

The attackers also operated a sophisticated Traffic Distribution System (TDS) consisting of 2,658 gate pages. The infrastructure was designed to direct legitimate victims to phishing websites while preventing automated security scanners from detecting malicious content.

According to Forescout, this approach makes the campaign significantly harder for security researchers and automated detection systems to identify.

Evidence points to AI generated phishing pages

One of the report’s most notable findings is evidence suggesting the phishing kit itself was created with the assistance of artificial intelligence.

Researchers found indicators that the phishing pages contained AI generated code, leading them to believe the threat actor used a large language model to build delivery pages and quickly adapt the campaign over time.

The findings reflect a growing trend of cybercriminals using AI to accelerate phishing operations, reduce development time, and rapidly generate convincing attack infrastructure.

Trusted software becomes the attack vector

Forescout said SeasonalInvite demonstrates how attackers are shifting away from custom malware in favour of abusing legitimate enterprise tools that organisations already trust.

By combining social engineering with legitimate remote management software and AI assisted development, threat actors can bypass many traditional endpoint security controls while maintaining long-term access to victim devices.

The researchers warn that organisations should not rely solely on malware detection to identify these attacks. Instead, they recommend monitoring for the unauthorised installation and use of remote management tools, strengthening phishing awareness training, and implementing controls that can detect suspicious behaviour rather than simply malicious files.

As attackers continue to refine their techniques, campaigns like SeasonalInvite highlight how trusted software and artificial intelligence are becoming powerful tools in the modern cybercriminal’s arsenal.

The post Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards appeared first on IT Security Guru.

Lidl Confirms Data Breach After Third-Party IT Provider Hack

14 July 2026 at 09:46

Lidl has confirmed that a cyberattack on one of its third-party IT service providers exposed the personal data of online shop customers in Germany, Belgium and the Netherlands, the latest in a string of supply-chain breaches to hit major European retailers this year.

The discount supermarket chain, owned by Schwarz Group, said it was informed of the incident last week and moved to notify affected customers by email, as well as to publish breach notices on its German, Belgian and Dutch support websites. In its statement, Lidl said unknown individuals had briefly gained access to “a separately stored file containing customer data” and stolen part of it, stressing that “the online shop system itself was not affected.”

The incident is a reminder of how much of a retailer’s exposure now sits outside its own walls. Boris Cipot, principal security engineer at Black Duck, said, “This incident is a textbook reminder that your security posture is only as strong as your weakest third party. Even when a retailer’s own systems hold, a compromised service provider can expose millions of customers to identity fraud, phishing, and account takeover attacks. Personal data like names, birthdates, phone numbers, and email addresses may seem low risk in isolation, but combined they become a powerful toolkit for social engineering. Additionally, the downstream costs to consumers and brand trust can far outlast the incident itself.”

According to the company, the compromised data includes customers’ salutation, first and last name, phone number, email address, date of birth, and customer number. Lidl said it currently has no evidence that passwords, billing or delivery addresses, bank details or other payment information were affected, and that customer accounts themselves had not been compromised. The retailer added that the affected IT service provider responded immediately and took steps to restore full security to its systems.

Paul Bischoff, Consumer Privacy Advocate at Comparitech, argued the nature of the stolen data limits the immediate danger, though phishing remains a real risk: “Although the breach is unfortunate, the compromised data doesn’t pose a direct threat to victims’ money or identities. It doesn’t contain credit cards or Social Security numbers, for example. Scammers could use the data to launch tailored phishing attacks and other scams, so be on the lookout for malicious emails and text messages. Scammers might pose as Lidl or a related company to trick victims into clicking malicious links.”

Cipot was more measured about how the company has handled disclosure so far, while cautioning that the real test is still to come: “Lidl deserves credit for moving quickly to notify customers and being transparent about what they don’t yet know, including the possibility that passwords, addresses, and payment data could be involved. That kind of candor presents the appropriate posture under GDPR. The real test now is follow-through: how quickly they complete the forensic investigation, how clearly they communicate updates as the scope becomes known, and how rigorously they reassess the security requirements they place on their service providers going forward.”

Lidl has filed a police report, engaged external IT forensic experts to investigate the scope of the incident, and notified the relevant data protection authorities, including the Dutch and Belgian Data Protection Authorities. The company has not named the compromised service provider or disclosed how many customers were affected. As of writing, no threat actor has publicly claimed responsibility.

Lidl, Europe’s largest food retailer, operates around 12,900 stores across 32 countries in Europe and the US and employs more than 376,000 people. The breach adds it to a growing list of retailers hit by supply-chain and third-party attacks over the past year, including Marks & Spencer, Co-op, Louis Vuitton, Pandora and Harrods, several of which have been linked to the Scattered Spider hacking group. Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the pattern has become too consistent to ignore: “Another major retailer, another third-party service provider breach. The pattern is consistent enough now that it needs calling out clearly; one of the weakest points in most organisations’ security posture isn’t their own systems, it’s the extended ecosystem of service providers that touch customer data peripherally.”

Lidl has urged customers to be alert for phishing attempts, telling them to verify the authenticity of any sender before disclosing information or clicking links, and to watch out for messages referencing their Lidl account or recent orders. Patel echoed that advice directly to anyone who has shopped with the retailer online: “If you’ve shopped on Lidl’s online store in Germany, Belgium, or the Netherlands, treat this as a prompt to act. Change your Lidl account password immediately, and if you’ve used the same password anywhere else, change it there too. Password reuse remains the single most effective way attackers turn one breach into multiple account compromises. If you receive any communication claiming to be from Lidl asking you to verify details or click a link, contact Lidl directly through their official website rather than responding.”

Cipot offered similar guidance, with a reminder that stolen data of this kind tends to resurface in scams long after the headlines fade: “Customers should treat this as a wake-up call, not just a notification. Change your Lidl password immediately (and any password reused elsewhere), enable multi-factor authentication wherever it’s offered, and be on high alert for phishing emails, texts, or calls that reference your Lidl account or recent orders. Attackers will absolutely weaponize this stolen data to craft convincing scams in the weeks and months ahead. Monitor your bank and card statements closely and consider a credit freeze if you’re in a jurisdiction where that’s available.”

The post Lidl Confirms Data Breach After Third-Party IT Provider Hack appeared first on IT Security Guru.

Black Duck Adds AI-Powered Triage and CRA-Ready Checks to Coverity Static Analysis

14 July 2026 at 08:29

Black Duck has rolled out a set of AI-driven and compliance-focused updates to Coverity, its static application security testing (SAST) tool, as the application security vendor looks to align the two-decade-old product with both the rise of AI-assisted coding and tightening European regulation.

The release marks the first time AI-powered features have shipped in Coverity, and Black Duck was keen to stress that the new capabilities can be run against a customer’s own choice of large language model, rather than a vendor-hosted service. The company said this was designed to give security and development teams control over where code and scan data are processed, a point it framed as particularly relevant for regulated industries and organisations with strict data governance requirements.

AI features aimed at cutting false positives

Chief among the additions is an AI-assisted issue triage capability, which Black Duck says is tuned to reduce false positives in C and C++ findings, a long-standing pain point for teams working in those languages, while also improving triage accuracy across the rest of Coverity’s supported languages.

Coverity has also gained a Model Context Protocol (MCP) server, allowing AI coding agents to trigger local Coverity scans and pull security and quality findings directly into their workflow. Black Duck’s pitch is that this lets agentic tools act on deterministic, reproducible scan output rather than relying purely on a model’s own probabilistic judgement of whether code is safe.

A new checker adds AI-powered detection of Insecure Direct Object Reference (IDOR) flaws in JavaScript and TypeScript codebases. IDOR vulnerabilities occur when an application exposes internal identifiers, such as user IDs, database keys or filenames, without properly checking that the requester is authorised to access them, a class of bug that has featured heavily in API-related breach disclosures.

Positioning for the Cyber Resilience Act

With reporting deadlines under the EU Cyber Resilience Act approaching, Black Duck used the update to introduce two compliance-oriented features. A new Security Impact Lens lets users sort and filter findings by security priority, bringing to security triage the kind of prioritisation Coverity has historically applied to code quality issues. Alongside it, a CRA-aligned checker option is intended to map scan results more directly to the vulnerability management and cybersecurity obligations set out in the regulation.

The update also extends language coverage to Rust 1.92, and introduces a refreshed user interface with reworked navigation and issue filtering, which Black Duck says is intended to speed up triage for teams working through large volumes of findings.

“Coverity has set the gold standard for static analysis for more than two decades, and we’re raising the bar by pairing its deterministic precision with the speed of AI, meeting customers where modern software development is heading,” said Dipto Chakravarty, Chief Product & Technology Officer at Black Duck.

“Code today is written, reviewed, and shipped by agents, and businesses have to move at machine speed to stay ahead,” Chakravarty added, arguing the update delivers AI-driven triage without sacrificing auditability, agentic workflow integration via the MCP server, and tooling that makes CRA readiness “operational, not aspirational.”

Black Duck said all of the new capabilities are now generally available to existing Coverity customers, who gain access to the AI-powered features without changes to the deterministic, auditable scanning the product is built around. Further detail is available via the Coverity Documentation Portal.

The post Black Duck Adds AI-Powered Triage and CRA-Ready Checks to Coverity Static Analysis appeared first on IT Security Guru.

AI has crossed from assistant to operator, Check Point research warns

14 July 2026 at 07:21

Check Point Research has published its second annual AI Security Report, documenting what it calls a decisive shift in how artificial intelligence is used in cyberattacks: AI is no longer simply accelerating existing techniques; it is now directly executing intrusions with minimal human direction.

The report is built on incident data, telemetry and original case studies gathered over the past twelve months, and its central finding is a change in degree that the authors argue amounts to a change in kind. Where AI previously functioned as a force multiplier, drafting phishing lures or debugging exploit code, Check Point Research says it has now, in several documented cases, run the mechanics of an intrusion end-to-end.

A single operator, thousands of AI-executed commands

The clearest example cited in the report is a breach affecting nine Mexican government agencies between late December 2025 and mid-February 2026, exposing roughly 400 million records spanning tax, civil registry, vehicle, patient, and electoral data. Researchers reconstructed the operation from the attacker’s own servers and found that 1,088 typed instructions from a single operator produced 5,317 AI-executed commands across 34 separate sessions.

The attacker reportedly ran two AI tools in tandem: Claude Code to actively probe and move through the networks, and GPT-4.1 to analyse exfiltrated data and feed follow-up instructions back into further Claude sessions. When Claude initially declined to assist, the attacker pasted a penetration-testing cheat sheet into a CLAUDE.md configuration file, a project file that coding agents read and treat as authoritative at the start of every session, allowing the bypass to persist automatically without a repeated jailbreak prompt.

The report links this to a separate case disclosed by Anthropic in November 2025 involving GTG-1002, a Chinese-linked espionage campaign in which the vendor said its own Claude Code agent handled an estimated 80 to 90 percent of tactical work, including reconnaissance, exploitation, credential harvesting and lateral movement, across roughly 30 target organisations.

Prompt injection detections up fivefold

Check Point AI Security telemetry cited in the report shows detections of long, malicious prompt-injection payloads rising roughly fivefold between March and May 2026, approaching 1% of all observed prompts by May. The report links this trend to the growth of agentic workflows that ingest large blocks of external content, web pages, documents, and tool outputs, which is precisely where indirect prompt injection conceals itself.

Check Point AI Security Research also examined the software supply chain around coding agents. Scanning roughly 46,500 published code packages, researchers found a local Claude Code settings file had been accidentally published in 428 of them, with live credentials, including NPM tokens and GitHub and Hugging Face keys, present in around one in 13 of those. Separately, the team identified security weaknesses in 40% of 10,000 Model Context Protocol (MCP) servers reviewed.

The report also documents two vulnerabilities Check Point Research disclosed in Claude Code project files, tracked as CVE-2025-59536 and CVE-2026-21852, which allowed attacker-controlled configuration files to execute commands or silently start a malicious MCP server the moment a developer opened a project. Both were patched, but the report notes the same automatic-trust design pattern is shared by several other coding assistants, including Cursor, Windsurf and GitHub Copilot.

Vulnerability research and the compressed patch window

The report highlights AI’s growing role in vulnerability discovery, citing Anthropic’s Project Glasswing, an internal research effort in which the unreleased Claude Mythos Preview model autonomously identified more than 10,000 high- and critical-severity zero-day vulnerabilities across major operating systems and browsers in its first month, producing a working exploit on the first attempt in roughly 83% of cases.

Check Point Research argues the same capability curve applies to attackers, and points to CISA’s binding directive requiring US federal civilian agencies to remediate certain high-risk vulnerabilities within three days of disclosure, and India’s CERT-In advisory recommending critical, internet-facing systems be patched within 12 hours, as evidence that the industry’s remediation timelines are already being forced to compress.

Identity verification under strain

A separate section of the report addresses synthetic identity. In a controlled study cited by Check Point Research, people trained specifically to detect AI-generated faces correctly identified only around 41% of them; untrained viewers identified roughly 30%. The report argues that voice, face, documents and live video can no longer function as standalone proof of identity, and recommends organisations shift toward verification methods that combine separate trusted channels, secure digital credentials and stronger live-verification checks.

Enterprise exposure outpacing governance

On enterprise AI use, Check Point data shows the average number of prompts per user grew from 56 in December 2025 to 70 in May 2026, a 25% increase, while organisations used an average of 10 different AI applications a month. The proportion of high-risk prompts, those containing sensitive corporate, personal or regulated data sent to external AI services, doubled from 2% to 4% over the same period. Between 87% and 93% of organisations had at least one high-risk GenAI interaction every month.

Business Services recorded the highest sector rate, with high-risk prompts climbing from 5.50% in January to 6.98% in May, a 27% increase in five months. Regionally, Europe recorded the highest rate of any region at 3.95%, ahead of Latin America (3.76%) and North America (3.33%).

Vendor response

Lotem Finkelstein, Vice President of Check Point Research, said the shift documented this year is more significant than the force-multiplier framing used in previous reports.

“AI has crossed into the live attack chain,” Finkelstein said, adding that the expertise barrier separating capable attackers from the rest of the field is disappearing.

The report sets out Check Point’s response across three areas it terms Security for AI, Security by AI and Security with AI, covering AI agent governance and red-teaming, ThreatCloud AI-powered threat prevention, and workforce-level visibility and data-loss prevention for GenAI use, delivered respectively through its AI Agent Security, AI Red Teaming, ThreatCloud AI and Workforce AI Security products.

The full Annual AI Security Report 2026 is available here.

The post AI has crossed from assistant to operator, Check Point research warns appeared first on IT Security Guru.

UK Cyber Attacks Climb 34% as Ransomware Leadership Shifts, Check Point Research Reveals

13 July 2026 at 07:20

UK organisations faced an average of 1,589 cyber attacks per week in June 2026, a 34% increase compared with the same month last year, according to new threat intelligence from Check Point Research, the intelligence arm of Check Point Software Technologies.

The UK figure outpaces the global trend line. Worldwide, organisations experienced an average of 2,270 weekly attacks in June, up 17% year on year and 10% month on month, as a brief lull in May gave way to a broad rebound across regions and industries. Rather than concentrating in one geography or sector, the increase in attack volume appeared almost everywhere at once, a pattern researchers say points to attackers widening their targeting rather than intensifying pressure on a single weak point.

“June’s data shows a broad rebound in cyber activity, not a single isolated spike,” said Omer Dembinsky, Data Research Manager at Check Point Research. “Attackers are widening their reach across regions and industries, while ransomware groups continue to reorganise and scale. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”

Education, Government and Telecommunications remained the most targeted sectors globally. Education organisations faced an average of 4,816 weekly attacks, up 16% year on year, with open campus networks and constrained security budgets continuing to make schools and universities attractive targets. Government followed at 2,836 weekly attacks (up 5%), while Telecommunications recorded 2,835 (up 13%).

Regionally, Latin America remained the most heavily targeted, with 3,501 weekly attacks on average, a 27% year-on-year rise. Europe posted one of the sharpest regional increases globally at 22%, a trend the UK figures sit within and, on this data, exceed.

Ransomware activity intensified sharply in June, with 646 attacks recorded, a 33% rise on June 2025. Business Services remained the most targeted industry, accounting for 31% of reported victims, followed by Consumer Goods and Services (16%) and Industrial Manufacturing (14%). Government’s share of ransomware victims has climbed steadily, from 4.0% in April to 5.4% in June.

The most notable development was at the group level. The Gentlemen, a ransomware-as-a-service operation founded in mid-2025, overtook Qilin to become the most active ransomware group, responsible for 17% of published attacks compared with Qilin’s 11%. LockBit also surged, rising from 1% of published attacks in May to 7% in June, making it the third most prevalent group.

Check Point Research attributes The Gentlemen’s rapid rise to an unusual dual model: the group functions simultaneously as a RaaS provider and an Initial Access Broker, giving affiliates self-service access to an estimated 14,000 pre-exploited FortiGate devices tied to CVE-2024-55591. Researchers have linked the group to more than 320 confirmed data-leak-site victims, with an estimated 1,570+ actual compromises, placing it among the top seven ransomware threats globally within a year of launch. Its targeting is notably atypical, with the US accounting for only 12% of victims against a 50% ecosystem average, reflecting a victim-selection model driven by device availability rather than deliberate geographic targeting. The group’s cross-platform lockers target Windows, Linux and ESXi environments, and a May 2026 operator communication signalled a shift from blunt-force BYOVD-based EDR killing toward more surgical userland evasion techniques.

GenAI-related exposure also remained a persistent risk through June. Check Point Research found that 1 in every 26 enterprise GenAI prompts carried a high risk of sensitive data leakage, a global exposure rate of 3.9%, affecting 85% of organisations that regularly use GenAI tools. A further 27% of prompts contained potentially sensitive information. Healthcare and Medical organisations carried the highest exposure at 5.7%, followed by Telecommunications and Business Services at 5.1% each. Personal data was the most common category of sensitive information exposed, appearing across 80% of affected organisations.

With UK attack volumes rising faster than the global average, researchers say the combination of broader attacker targeting, a reshuffled ransomware leaderboard and steady GenAI-related exposure underscores the case for prevention-first security architectures that span network, cloud, endpoint and user activity.

The post UK Cyber Attacks Climb 34% as Ransomware Leadership Shifts, Check Point Research Reveals appeared first on IT Security Guru.

UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense

10 July 2026 at 07:24

The National Cyber Security Centre (NCSC) has unveiled plans for Cyber Shield, an ambitious initiative that aims to use agentic artificial intelligence to transform the nation’s cyber defenses and counter increasingly sophisticated cyber threats. The proposal forms part of a broader effort by the NCSC and the Department for Science, Innovation and Technology (DSIT) to build a national scale, AI powered cyber defense capability that can detect, analyze, and eventually respond to attacks at machine speed.

According to the NCSC, Cyber Shield will initially focus on using AI to identify vulnerabilities and detect threats before progressing toward automated mitigation, coordinated threat intelligence sharing, and national level response capabilities. The initiative is intended to help defenders keep pace with attackers who are increasingly using artificial intelligence to accelerate reconnaissance, vulnerability discovery, and exploitation.

AI changes the cyber defense equation

Rik Ferguson, Vice President of Security Intelligence at Forescout, believes the proposal reflects the reality of today’s threat landscape.

“The NCSC’s Cyber Shield proposal feels like a logical and necessary step, especially if we view it through the lens of ‘Assume Autonomy,'” Ferguson said.

“The core assumption should no longer be that autonomous cyberattacks are a distant or speculative problem. We should assume that adversaries will increasingly use AI agents to automate reconnaissance, vulnerability discovery, exploit development, credential attacks, lateral movement, and adaptation once inside an environment.”

Ferguson said security teams operating at human speed will struggle to defend against machine speed attacks, particularly across critical infrastructure, healthcare, and government networks.

“A national scale AI cyber shield is therefore not just about adding AI to existing security workflows. It is about building defensive systems that can detect, prioritize, and help contain threats at the same tempo at which AI enabled attackers can operate.”

However, he cautioned that autonomy must be implemented carefully.

“The opportunity is strongest where AI can improve visibility, correlation, triage, exposure management, and early intervention. The risk comes when automated systems act without sufficient context, governance, or operational guardrails.”

He added that AI alone cannot solve long-standing cybersecurity problems.

“AI can help defenders move faster, but it cannot compensate for poor asset visibility, weak segmentation, unpatched systems, or unclear ownership of cyber risk.”

Governance will be critical

Shane Barney, Chief Information Security Officer at Keeper Security, also welcomed the initiative but warned that the success of Cyber Shield will depend on strong governance.

“Cyber Shield is the right instinct, and it is arriving at a genuinely dangerous moment for both organizations and the wider public,” Barney said.

“Attackers are already using AI to compress reconnaissance and exploitation into minutes, and the NCSC is correct that human speed defense cannot keep pace with machine speed offense.”

Barney argued that many successful cyberattacks still rely on basic security weaknesses.

“Most successful attacks still exploit basic, preventable failures, including outdated systems, unpatched software, and weak access controls. No amount of agentic AI changes that equation if the underlying identity and access foundations are not solid.”

He also highlighted a potential new risk created by AI itself.

“Red and blue AI agents are themselves privileged non-human identities, granted authority to scan networks, share intelligence, and eventually remediate vulnerabilities autonomously.”

According to Barney, those AI agents will require the same security controls as privileged human administrators, including least privilege access, just in time provisioning, and complete visibility into their activity.

“An AI agent with unmanaged privileged access is not a defense. It is the next incident.”

A collaborative approach

The NCSC said Cyber Shield will rely on close collaboration between government, industry, academia, and critical infrastructure operators. Trusted information sharing and explainable AI will be central to the initiative as it evolves from vulnerability discovery toward coordinated national cyber defense.

While the idea of a Cyber Shield remains a long-term vision, security leaders broadly agree that AI will play an increasingly important role in defending against AI-driven cyberattacks. The challenge now will be ensuring those capabilities are introduced with the governance, transparency, and foundational security controls needed to make them effective.

The post UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense appeared first on IT Security Guru.

Healthcare, Hospitality and Construction Named UK’s Most Phishing-Prone Industries

10 July 2026 at 07:07

KnowBe4’s latest benchmarking report, based on 42 million phishing simulations worldwide, reveals the sectors most vulnerable to phishing attacks across the UK and Ireland, while highlighting the impact of continuous security awareness training. Healthcare and pharmaceutical organisations are the most susceptible to phishing attacks in the UK, followed by businesses in the hospitality and construction sectors, according to new research from cybersecurity awareness and digital workforce security provider KnowBe4.

The findings come from KnowBe4’s 2026 Phishing by Industry Benchmarking Report, which analysed 42 million phishing simulation tests involving 14.8 million users across 64,000 organisations worldwide. The research found that before any security awareness training is introduced, 43.9% of employees in healthcare and pharmaceuticals are likely to engage with a phishing attack. Hospitality follows at 38%, while construction recorded a baseline Phish-prone Percentage (PPP) of 34.1%.

Financial services (30.7%) and energy and utilities (29.3%) complete the top five most vulnerable sectors in the UK and Ireland.

Across all industries, the average UK baseline PPP stands at 30.3%, meaning almost one in three employees is likely to fall for a phishing attempt before receiving any formal training. Larger organisations face greater risk, with enterprises employing more than 10,000 people recording a baseline PPP of 33.1%, compared with 24.8% among small businesses.

The report also demonstrates the long-term impact of continuous security awareness programmes. Organisations reduced phishing susceptibility by 34.7% after 90 days of training, while after one year of ongoing education the average PPP fell by 81.9%, reaching just 5.5%.

The findings arrive as attackers increasingly use artificial intelligence to create convincing phishing emails, business email compromise (BEC) campaigns and deepfake-enabled social engineering attacks.

Javvad Malik, lead CISO advisor at KnowBe4, said the rise of AI is changing both the threat landscape and the workforce organisations need to protect. “As organisations in the UK expand their workforce from humans to include autonomous AI agents, the attack surface grows in ways traditional controls were not designed to address. This complexity is being exploited, evidenced by a 17% spike in phishing attacks since late 2025 alone. However, the data proves organisations can combat this through continuous personalised training, which drops employee phishing susceptibility to 5.5% over 12 months.”

Globally, the report found Africa recorded the highest baseline phishing susceptibility at 35.9%, followed by North America at 34.5% and South America at 31.5%. Asia reported the lowest baseline risk at 24.9%.

KnowBe4 said the findings reinforce the importance of ongoing, behaviour-focused security awareness programmes, particularly as organisations adopt AI technologies that expand the number of identities and systems requiring protection.

The post Healthcare, Hospitality and Construction Named UK’s Most Phishing-Prone Industries appeared first on IT Security Guru.

CitrixBleed 2 exploited in repeatable attack chain culminating in DragonForce ransomware, researchers find

9 July 2026 at 09:09

Threat hunters at managed detection and response firm Huntress say they have tracked a single, highly consistent attack chain across at least half a dozen unrelated organisations in the first half of 2026; one that begins with exploitation of the “CitrixBleed 2” vulnerability in Citrix NetScaler appliances and, in its most advanced form, ends in DragonForce ransomware.

Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777 to gain footholds in Citrix environments before selling or handing off access, ultimately for the purpose of ransomware deployment. The firm says the intrusions it investigated were so mechanically similar – same privilege-escalation technique, same rogue account names, even the same attacker-controlled hostnames recurring across victims – that they point to a productised runbook rather than opportunistic, independent attacks.

A pre-auth memory leak that defeats MFA

CVE-2025-5777, dubbed CitrixBleed 2 in reference to 2023’s original CitrixBleed (CVE-2023-4966), is a pre-authentication memory-overread affecting NetScaler ADC and Gateway when configured as a Gateway or AAA virtual server. Malformed POST requests to the login endpoint, sent with an empty login form variable, cause the appliance to serialise roughly 127 bytes of adjacent process memory into its response. Sprayed at volume, this allows an attacker to harvest heap memory fragments, including live session tokens.

Huntress said it was able to fully reconstruct a session hijack in one incident: a legitimate employee authenticated normally via LDAP with MFA from a known-good IP, and 21 minutes later the same session was being driven from the attacker’s IP, with no successful authentication event from that IP anywhere in the logs. Because the session was already fully authenticated, MFA offered no protection; it had already been satisfied by the legitimate user.

The firm ruled out an alternative explanation involving a separate NetScaler session-management flaw (CVE-2026-4368) on the grounds that the affected appliance builds fell outside that CVE’s vulnerable range and that the relevant race condition requires an already-authenticated attacker session, which the logs did not show.

A single privilege-escalation tool across every case

Once inside, the operator consistently used a small, unsigned local privilege-escalation (LPE) tool to reach SYSTEM. The technique abuses the Windows registry’s SymbolicLinkValue (REG_LINK) mechanism, planting a symlink under a device-class key that redirects into the Group Policy state hierarchy. Triggering a policy refresh via gpupdate causes the Group Policy engine, which runs as SYSTEM, to write through the planted link, corrupting a protected configuration. Starting the built-in AppMgmt service then causes the Service Control Manager to relaunch the attacker’s binary with SYSTEM privileges, at which point a backdoor administrator account is created via net user and net localgroup Administrators commands.

Huntress noted the tool snapshots and subsequently restores the original registry state after detonation, a cleanup step designed to remove the artifacts a responder would typically rely on. Analysts also observed operator errors during the process, including a mistyped net user command, indicating a human operating largely automated tradecraft rather than a fully autonomous tool.

Persistence via legitimate RMM tooling

For persistence, the operator most frequently deployed rogue ScreenConnect clients configured to call back to attacker-controlled relay infrastructure, alongside Zoho Assist in several cases and, in one earlier instance, a Netbird and Atera combination, echoing a Netbird detail previously reported by Sophos, which has separately tracked overlapping activity as STAC3725. Huntress said it withheld some Zoho Assist indicators after recovering likely-stolen credentials belonging to unrelated organisations during the investigation.

In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access before deploying a DragonForce ransomware binary, resulting in encryption that Huntress says was contained to a single host through rapid triage.

Attribution remains ambiguous

Huntress was careful to caveat attribution, noting that overlapping tactics between initial access brokers and ransomware affiliates make firm attribution difficult, and that public and private reporting has linked the cluster to more than one ransomware brand. The firm said it considers the activity most likely to represent a single, highly successful IAB rather than a DragonForce-specific affiliate.

Recommendations

Huntress is urging organisations running NetScaler ADC or Gateway to patch immediately, forward NetScaler logs to a SIEM or long-term retention platform given how quickly on-device logs rotate, terminate outstanding sessions on vulnerable appliances since harvested tokens can survive a patch, and audit for unrecognised local accounts and unexpected ScreenConnect or Zoho Assist installations. A full list of indicators of compromise, including file hashes, account names and C2 infrastructure, accompanies Huntress’ original write-up, which can be found here: https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware

The post CitrixBleed 2 exploited in repeatable attack chain culminating in DragonForce ransomware, researchers find appeared first on IT Security Guru.

Huntress Uncovers ‘Vibe-Coded’ Malware Used to Map Active Directory Environments

8 July 2026 at 10:55

Threat researchers at Huntress have identified what they describe as a clear example of AI-generated, or “vibe-coded”, malware deployed during a live intrusion, a development that the security vendor says signals a meaningful shift in how attackers build tooling, and how defenders will need to detect it.

The discovery centres on a bespoke PowerShell script recovered by Huntress analysts Jevon Ang and Dray Agha following an incident on 3 June. The script, designed to enumerate a victim’s Active Directory (AD) environment, was reconstructed from Windows Event ID 4104 telemetry (PowerShell/Operational logs) and later published in full by the vendor for the benefit of other defenders.

A familiar attack chain, with an AI-built payload

According to Huntress, the intrusion itself followed a well-worn playbook. The threat actor obtained RDP access to a domain-joined Windows server, apparently via a VPN, using pre-compromised credentials. From there, tools were staged in C:\ProgramData, a directory long favoured by attackers for its ubiquity and lax scrutiny.

Within minutes of establishing the session, the actor executed a custom script, saved as Untitled1.ps1, to map users, computers, groups, organisational units and domain trusts. Roughly 30 minutes later, the same actor deployed s5cmd.exe, a legitimate Amazon S3 command-line utility that Huntress has previously flagged as a recurring tool of choice for data exfiltration, followed by SharpShares, an open-source share enumeration tool, to hunt for additional accessible file repositories beyond standard administrative shares.

Huntress is careful to note that AI did not alter the fundamentals of the attack. The tactics- credential-based remote access, staging in common directories, AD enumeration followed by bulk exfiltration- mirror years of established “smash and grab” tradecraft. What has changed is the origin of the reconnaissance tooling itself.

The hallmarks of an LLM-authored script

The analysis identifies several indicators that the enumeration script was generated iteratively using an AI coding assistant rather than written by hand. Among them:

  • A title embedded in the script itself – “100% Working AD Information Gathering Script – FULLY FIXED” – consistent with an attacker copy-pasting the final output of a prompt-and-error-correct cycle with a chatbot.
  • An unedited placeholder server name left over from the model’s own example output, suggesting the operator never reviewed or customised the generated code.
  • A five-step cascading fallback routine for locating the domain controller (DNS, nltest, the AD PowerShell module, environment variables, and a hardcoded default), described by Huntress as the kind of exhaustive, redundant logic a language model produces when instructed to “make sure it doesn’t fail”, rather than the leaner approach a human operator would typically write.
  • Extensive, colour-coded Write-Host console output and a fully formatted HTML summary report generated at the end of the run – cosmetic touches Huntress suggests were an unsolicited addition from the model rather than a deliberate attacker requirement.

Once run, the script created a timestamped directory (C:\AD_Reports_<datetime>) containing CSV exports of users, computers, groups, OUs, subnets, and trusts, along with DNS subnet data and the aforementioned HTML report, and then compressed the results into a single ZIP archive.

Why this matters for detection

The core implication for defenders, per Huntress, is that hash- and static-signature-based detection is losing ground against this category of threat. Off-the-shelf tools such as SharpHound or Cobalt Strike carry known fingerprints; a one-off script produced through natural-language prompting does not, and is unlikely to reappear in identical form elsewhere.

Huntress argues that the underlying behaviours of AD enumeration – querying domain controllers, dumping user and group objects, touching trust relationships – remain constant regardless of how the code performing them was written. The vendor says its SIEM platform identified the activity on behavioural grounds despite the script’s novelty, and it is urging security teams to prioritise behavioural and telemetry-based detection over static indicators as AI-assisted tooling becomes more common among lower-skilled threat actors.

“Vibe coding lowers the barrier to entry for cybercrime,” the researchers conclude, warning that while the resulting code may be messy and over-engineered, the operational risk it poses to organisations is very real.

The bigger picture

The case adds to a growing body of evidence that generative AI is being adopted, unevenly but increasingly, on the offensive side of cybersecurity, not to invent novel attack techniques, but to lower the technical skill required to execute existing ones. For security teams, the takeaway from Huntress’s research is less about any single script and more about a structural shift: as malware authorship becomes commoditised, detection strategy needs to lean further into behaviour and context, and further away from matching known bad files.

Full technical detail, including the recovered script and accompanying screenshots, is available here: https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory

The post Huntress Uncovers ‘Vibe-Coded’ Malware Used to Map Active Directory Environments appeared first on IT Security Guru.

Mike Winston on Why Jet.AI Shifted From Aviation to AI Infrastructure

7 July 2026 at 10:53

Private aviation runs on tight margins and tighter schedules. The AI tools Jet.AI built to optimize both placed the company in an unusual vantage point: watching production inference workloads run against real operational constraints, before the data center power shortage became a mainstream story. Mike Winston, investor and founder of Jet.AI (NASDAQ: JTAI), built those tools inside an operating aviation business and drew from them a conclusion that now anchors two public companies: the constraint binding the AI infrastructure buildout is power, and the gap between available supply and projected demand will persist for years. That conclusion informs the February 2025 agreement to transfer Jet.AI’s aviation operations to flyExclusive, the data center development pipeline being assembled through the Convergence Compute joint venture, and the $138 million SPAC raised through AI Infrastructure Acquisition Corp. (NYSE: AIIA). For investors trying to understand Jet.AI’s trajectory, the aviation chapter is where the thesis actually originates.

From Jet Token to Jet.AI: A Sequence With a Logic

What happened at Jet.AI between 2016 and 2025 reads, from the outside, as a series of technology pivots. The company began as Jet Token, a blockchain-based private aviation startup founded by Mike Winston, CFA, whose prior career had run from equity research at Credit Suisse First Boston through five years as a portfolio manager in merger arbitrage and event-driven investing at Millennium Partners. Regulatory constraints closed off the blockchain model’s commercial path. The company rebuilt around AI tools for aviation: agentic booking software, route optimization for fuel and carbon efficiency, dynamic pricing for charter operations. Each change tracked external conditions. Each stage also produced information the next depended on.

What Building Aviation AI Software Actually Reveals

The tools Jet.AI developed for private aviation required real compute at operational scale. Agentic booking software coordinates availability, pricing, and scheduling across multiple aircraft against a customer base with variable and often short-notice demand. Route optimization requires running real-time models against weather, airspace, and fuel data. Dynamic pricing models consume compute at a rate that scales with transaction volume and prediction complexity.

Running those workloads inside an operating aviation company (not in a research environment, in production, against real cost constraints) produces a specific kind of knowledge. The compute requirements of operational AI are higher than they appear from the outside. The power requirements of compute at scale are higher still.

Through building AI tools for aviation, we saw firsthand the scale of transformation AI would bring,” Winston said in an April 2026 interview. “That led us to data centers, where the infrastructure opportunity is significant. Given my background in real estate finance and telecom, it was a natural transition. Today, we’re extending that into power generation using aero-derivative engines, another area with strong underlying demand.”

That insight came from operating a business where AI was a production tool, measured against real cost constraints.

The Power Problem, Quantified

The constraint Winston identified by operating inside aviation AI is now visible across the broader market.

The U.S. Department of Energy estimated data center electricity consumption at 176 terawatt-hours in 2023. Analysis by Alderman & Co. projects that figure could reach 580 TWh by 2028. That would put data centers at between 6.7% and 12% of all U.S. electricity. Grid interconnection queues in some U.S. jurisdictions now run eight to 10 years, measured from the point of application.

New gas turbines from major manufacturers are not closing that gap fast enough. Contact GE Vernova today for an LM6000 order and the delivery window runs three to five years minimum. GE Vernova CEO Scott Strazik said in early 2025 that the company expected to be largely sold out through the end of 2028 by that summer. Siemens Energy reported that more than 60% of its U.S. gas turbine orders that year were linked to AI data center demand. Mitsubishi’s newer turbine blocks ordered in 2025 may not ship until the 2030s.

The practical solution for data center operators who need power now is the aero-derivative gas turbine: units built around retired commercial jet engine cores, modified for stationary generation. ProEnergy has sold 21 of its PE6000 units to just two data center projects: more than one gigawatt of combined bridging power. Each unit produces 48 megawatts and can be operational within 30 days of delivery. ProEnergy was quoting 2027 availability when GE Vernova’s order book had already closed into 2028 and beyond.

The Aviation Industry as an Early Observer

The CF6-80C2 turbofan engine, the core unit that ProEnergy overhauls for its ground-based power systems, was widely used on Boeing 767s and Airbus A310s. Approximately 1,000 of these engines are expected to retire from commercial aviation service over the next decade. The supply is quantifiable, the retirement schedule is predictable, and the companies with operational knowledge of aviation hardware were positioned to recognize the secondary market forming around those cores.

Jet.AI was an aviation company with AI tools and capital markets literacy. That combination produced an earlier read on the intersection of retiring aviation hardware and data center power demand than financial analysis alone typically generates.

The competition for aero-derivative turbines has since created cross-sector friction that Alderman & Co. analysts Ryan Kirby and Joseph Lakaj documented in March 2026: aero-derivative units share a near-identical manufacturing base with commercial flight engines, relying on the same specialized castings, high-temperature alloys, and precision forgings. A large data center order for turbines now directly competes with engine deliveries for new commercial aircraft. Boeing and Airbus are both navigating extended delivery timelines driven in part by engine shortfalls. Two industries are pulling on the same supply chain, and the aviation sector is both a contributor to that constraint and, through companies like Jet.AI, a beneficiary of it.

The flyExclusive Transaction and What It Unlocked

The agreement to transfer Jet.AI’s aviation operations to flyExclusive removed the operational complexity that had kept two structurally different businesses inside a single public vehicle.

flyExclusive takes the Citation and HondaJet fleet and the private aviation customer base. The combined platform has the scale to extract returns Jet.AI’s aviation division could not reach independently. Jet.AI shareholders receive flyExclusive (NYSE American: FLYX) equity alongside their retained JTAI position. The post-close version of Jet.AI carries no fleet, no pilots, and no charter operating costs.

What remains in JTAI: the Convergence Compute joint venture with Consensus Core Technologies, targeting one gigawatt of data center capacity across three campuses in North America; a $5 million economic interest in a special purpose vehicle anchored by SpaceX and xAI equity; and the 49.5% economic stake in the AIIA sponsor.

On June 1, 2026, Glass Lewis issued a “FOR” recommendation on the flyExclusive merger. Glass Lewis is one of two proxy advisory firms whose research institutional investors consult as a standard checkpoint before shareholder votes. The special shareholder meeting is scheduled for June 11, 2026. Approval requires an affirmative vote from a majority of all outstanding shares. Institutional participation is essential to clearing that threshold.

Public markets tend to undervalue companies that operate across two structurally distinct businesses. Aviation and AI infrastructure attract different investors on different time horizons. Separating them into distinct listed vehicles removes the valuation friction that a mixed balance sheet creates.

AI Infrastructure Acquisition Corp.

AIIA raised $138 million in its October 2025 IPO. Its mandate is to identify and close a business combination in data center infrastructure or AI, a focus the company describes as “ship to grid.” As of early 2026, management confirmed active engagement with several targets.

The connection to JTAI runs through sponsor economics. SPAC sponsors typically receive 20% of post-IPO equity as founder shares plus warrants exercisable at $11.50. Jet.AI’s 49.5% position in the AIIA sponsor entity means that if AIIA closes a qualifying business combination, nearly half the sponsor economics flow back to JTAI shareholders. The stake was carried at $17.23 million on Jet.AI’s balance sheet as of Q1 2026, and the company reported $13.5 million in cash with no debt.

Winston has positioned the infrastructure bet across two independent paths: an organic buildout through Convergence Compute and an acquisition vehicle through AIIA. The structure means not every outcome depends on a single execution.

Winston’s Background and the Pattern It Reveals

Winston joined Credit Suisse First Boston in 1999 on a telecom research team that Institutional Investor Magazine ranked first, at the start of one of the largest infrastructure capital cycles of the modern era. Five years at Millennium Partners followed, co-managing a $1 billion merger arbitrage and event-driven book through Catapult Capital Management. That discipline produces a specific habit: determine what an asset is worth if the market-moving event does not occur, then price accordingly.

The data center power thesis runs through that same lens. The demand is documented: grid interconnection timelines, turbine manufacturing lead times, and hyperscaler capex commitments are all public record. The question event-driven analysis poses is not whether the demand is real but whether the specific positioning captures the value before it prices in. Winston has spent a career in disciplines that reward being right about that second question.

He founded Sutton View Capital in 2012 after departing Millennium Partners. The firm advised one of the largest academic endowments in the world and co-led successful activist litigation against the Dole Foods board, securing a 35% increase in total consideration for shareholders. The CFA credential, the Institutional Investor ranking, the Columbia MBA: the credentials are institutional. The career decisions have been independent. Jet.AI and AIIA are both built outside established platforms, on conviction about where specific structural conditions point.

Where the Risk Lives

AIIA has a standard SPAC window of 18 to 24 months from its October 2025 IPO. No business combination has been announced. The clock is running, and trust account mechanics create real deadline pressure regardless of whether the acquisition market cooperates on the same schedule.

Convergence Compute has three of four development milestones complete, with power studies and permitting underway across its three campus sites. Construction, equipment procurement, and customer acquisition follow. The financial returns depend on those campuses being built, leased, and stabilized. Each step carries execution risk appropriate to a company of JTAI’s current scale.

The supply constraints that make the thesis credible are also the supply constraints that make execution difficult. Developer competition for turbine delivery slots, permitting capacity, and project financing is intensifying as more capital chases the same infrastructure gap.

The observational logic that runs from aviation AI tools to data center infrastructure holds up as an account of how Winston read the market. Whether Jet.AI can execute against it before the supply advantage narrows is what the next 18 months will determine.

Disclosure: This article discusses Jet.AI, Inc. (NASDAQ: JTAI) and AI Infrastructure Acquisition Corp. (NYSE: AIIA). Readers should conduct their own due diligence before making investment decisions. This piece reflects publicly available information and does not constitute investment advice.

The post Mike Winston on Why Jet.AI Shifted From Aviation to AI Infrastructure appeared first on IT Security Guru.

George Murnane’s One-Question Test for Real AI

7 July 2026 at 10:52

Ask George Murnane how to separate real artificial intelligence from a marketing slogan, and he gives you one question: what does the model predict, and what is its loss function?

George Peter Murnane has spent more than three decades running asset-intensive aviation businesses, 14 of those years as a chief operating officer, a chief financial officer, or both at once. He is now chief executive of Jet.AI Inc. (NASDAQ: JTAI) and a director and CFO of AI Infrastructure Acquisition Corp., the blank-check company that closed an upsized $138 million IPO in October 2025. That résumé sits at the exact junction where capital, operations, and AI claims collide. It also makes him unusually hard to sell to.

The George Murnane filter: name the prediction, name the loss function

The test is deliberately unglamorous. If a company can tell you precisely what its model forecasts and what error it is trained to minimize, the AI is probably real. If the best it can offer is that the technology “makes the experience smarter,” the label is doing work the software cannot.

That distinction matters more in aviation than in almost any other industry, because the cost base is high and the margins are thin enough that a small efficiency gain compounds into real money. Murnane’s filter is a way of routing scarce capital toward the few applications that move those numbers, and away from the many that only move a pitch deck.

Where AI is real in aviation: the AOG math

Start with predictive maintenance, the application Murnane considers genuinely valuable. The economics are not subtle. A single aircraft-on-ground event can cost an operator between $10,000 and $150,000 per hour of downtime, once you add lost revenue, crew rest and overtime, passenger re-accommodation, and the scramble to source a replacement part.

Predictive maintenance attacks that cost directly. By reading sensor data, flight history, and maintenance records, the models flag a deteriorating component before it fails, which lets an operator move an unplanned repair into a scheduled window. A 2022 Deloitte analysis cited by Radome Technologies estimated that predictive maintenance, properly implemented, can cut maintenance costs by up to 30% and reduce AOG events by more than half. Delta cut unscheduled maintenance by more than 30% using predictive engine monitoring.

The use case is specific enough to survive Murnane’s question. The model predicts a component failure. Its loss function penalizes false negatives, the missed failures that ground an aircraft, and false positives, the needless part swaps that waste a maintenance slot. There is a number on both sides of the ledger. Investors have noticed the same thing: the predictive airplane maintenance market is projected to grow from $5.35 billion in 2026 to $18.87 billion by 2034, a compound annual rate above 17%.

Predictive maintenance is not the only application that clears the bar. Crew scheduling optimized against duty-time limits has a defined objective and a hard constraint set written into federal regulation. Dynamic pricing run against forward booking curves predicts demand and optimizes yield. Document automation in SEC filings and merger diligence has a measurable output and a measurable error rate. Each of these can be described in a sentence that names what is being predicted. That is the tell.

The failure modes George Murnane watches for

The opposite of a loss function is an adjective. Murnane’s interviews return repeatedly to two ways companies dress up old or absent technology as AI.

The first is rebranding. A regression model that has been forecasting demand or pricing risk for 30 years gets relabeled “AI” because the term raises a valuation. The math is the same forecast it always was, repackaged under a more valuable label.

The second failure mode is more current and more expensive. A company bolts a large language model onto a workflow without redesigning the workflow underneath it. The result is a chatbot marginally more eloquent than the FAQ page it replaced, sold as a transformation. The model is real, but the value is not, because no one re-engineered the process the model was supposed to improve.

Murnane’s caution here is partly reputational arithmetic. As he has put it, the credibility cost of overclaiming compounds faster than the marketing benefit. For a public company whose name carries the letters “AI,” that is not an abstract risk. Overstate what the software does, and the first product failure under pressure becomes the story.

How Jet.AI uses AI where the value is measurable

Jet.AI gives Murnane a place to apply his own test in public. The company’s software, built when it operated as a private-aviation platform, concentrated AI on functions with a number attached: booking optimization, matching customers to the right operator, and customer communication. Its CharterGPT app and the Ava agentic booking model used natural-language processing to compress a booking process that once ran on phone calls and faxes.

Those tools handle a deliberately narrow set of jobs. Flying the airplane, vetting an operator’s safety record, and resolving a mechanical failure at midnight stay with humans and regulators. The AI sits where its prediction is cheap to measure and its errors are cheap to correct, which is exactly where Murnane argues it belongs.

From booking software to AI data center infrastructure

The most telling application of the loss-function test is the one Jet.AI is now living through. The company has moved away from running aircraft and toward building AI data center infrastructure, describing itself as a technology company focused on data center development across North America, with projects spanning more than a gigawatt of planned capacity.

The reason behind the pivot reads like a case study in Murnane’s own discipline. Jet.AI built genuine AI products, including a large language model agent for private aviation, then ran into a constraint that no amount of marketing could fix: unreliable uptime for the computational resources those products depended on, which occasionally slowed the company’s ability to serve customers. The bottleneck sat below the algorithm, in the power, land, and compute the products ran on.

So the company went after the bottleneck. Based in Las Vegas, with access to land, solar power, and natural gas, Jet.AI signed a letter of intent for a 50-megawatt project on a 120-acre campus with room to scale toward a full gigawatt. The framing Executive Chairman Mike Winston used was almost a rebuke of the category’s usual rhetoric: the move “isn’t a flashy move, but it’s a smart one,” because data centers are “the bedrock of the AI economy” and create value that is “tangible, stable, and meaningful.”

That is the loss-function test pointed at infrastructure rather than software. The prediction is straightforward: compute demand keeps climbing, and the assets that supply it earn against it. The error is measurable in megawatts delivered and uptime maintained. There is a number on both sides.

Why the loss-function test travels

Murnane’s filter works because it is industry-agnostic. It ignores whether a technology looks impressive and asks instead whether anyone can state what the system is optimizing and check the result against reality.

That discipline is the through-line of his career, from pricing aircraft assets at global carriers to evaluating a data center SPAC. The same question that exposes a relabeled regression model also exposes an overhyped acquisition target. In both cases, the executive who can describe the objective function is operating from evidence. The one reaching for “smarter” and “seamless” is operating from hope.

For a sector where roughly every company now claims an AI strategy, the value of a one-question screen is that it is fast and hard to fake. Name the prediction. Name the loss function. If those two answers are specific, the technology is likely doing real work. If they dissolve into adjectives, the only thing being optimized is the marketing.

The post George Murnane’s One-Question Test for Real AI appeared first on IT Security Guru.

Registration Now Open for International Cyber Expo 2026

7 July 2026 at 08:29

Registration is now open for International Cyber Expo 2026, one of the UK’s flagship two-day cybersecurity events which set to return to Olympia London on 29–30 September 2026, bringing together thousands of security professionals, technology providers and policymakers to explore the latest developments shaping the cyber landscape.

With cyber threats at a peak and the convergence of physical and digital security becomes increasingly important, International Cyber Expo has established itself as a key meeting place for the global cybersecurity community. The event provides a platform for organisations to discover emerging technologies, share best practice and discuss the strategies needed to strengthen cyber resilience.

This year’s edition is expected to welcome a diverse audience of CISOs, CTOs, IT directors, government representatives, security architects and risk professionals, alongside leading cybersecurity vendors showcasing the latest innovations in threat detection, incident response, identity management, cloud security, AI-driven defence and critical infrastructure protection.

Visitors will have the opportunity to explore a comprehensive exhibition featuring established technology providers and innovative startups, while benefiting from an extensive conference programme designed to address the challenges facing today’s security leaders. From ransomware and supply chain attacks to artificial intelligence, operational resilience and regulatory compliance, the agenda will focus on the issues currently defining the cybersecurity industry.

One of the event’s major attractions continues to be its thought leadership programme, where industry experts, policymakers and practitioners will share practical insights through keynote presentations, panel discussions and technical sessions. The Global Cyber Summit is designed to provide attendees with actionable advice that can be applied within their own organisations, whether they are responsible for enterprise security strategies or protecting critical national infrastructure.

Networking also remains a central part of the International Cyber Expo experience. With thousands of cybersecurity professionals expected to attend, the event offers opportunities to build new partnerships, connect with peers and engage directly with solution providers in an environment dedicated to knowledge sharing and collaboration.

The continued convergence of cyber and physical security is also expected to feature prominently throughout the event. As organisations increasingly manage interconnected digital and operational environments, collaboration between cybersecurity teams, physical security specialists and government stakeholders has become more important than ever. International Cyber Expo provides a forum for these conversations alongside its co-located event, International Security Expo, while highlighting technologies that support a more integrated approach to organisational resilience.

With registration now officially open, attendees are encouraged to secure their place early and begin planning their visit ahead of what promises to be one of Europe’s most significant cybersecurity events of the year.

To register for FREE, click here

The post Registration Now Open for International Cyber Expo 2026 appeared first on IT Security Guru.

❌
❌