❌

Reading view

There are new articles available, click to refresh the page.

Next-Level Test for Secure Transportation Vehicle

9/11/26
SECURE TRANSPORTATION
Enable IntenseDebate Comments:Β 
Enable IntenseDebate Comments

With rockets propelling it down the sled track at Sandia National Laboratories, a semitrailer loaded with mock nuclear weapons slammed into a barrier. It took mere moments to complete the second and final full-scale crash test of the Mobile Guardian Transporter, a next-generation system that will carry nuclear weapons and other sensitive materials for the Department of Energy’s Office of SecureΒ Transportation.

read more

4 Ways Organisations Create Non-Human Insider Risk

As AI agents become embedded across business operations, they are also creating a new category of insider risk. Unlike traditional insiders, these non-human identities can act at machine speed, operate continuously and access multiple systems without direct human oversight.

The danger rarely stems from one obvious security failure. Instead, it emerges when several weaknesses overlap. Here are four common ways organisations inadvertently create non-human insider risk:

1. Persistent access

Long-lived API keys, OAuth tokens, service accountsΒ and standing privileges give agents constant access long after it is needed.

2. Excessive privilege

Many agents can read, write, modify, approve, deleteΒ or deploy far more than their actual tasks require.

3. Untrusted input

Agents consume information from emails, support tickets, documents, chat conversations, websites and repositories. If attackers can influence those inputs, they may also influence the agent’s decisions.

4. Limited behavioural monitoring

Many organisations can tell that an AI agent performed an action. Far fewer can determine whether that action actually made sense. Logging tells us what happened, understanding whether it should have happened is a different challenge altogether.

You can read the full blog from Erich Kron, CISO Advisor at KnowBe4. Stay tuned for part 2 where Erich will reveal what security teams should do to stay secure.

The post 4 Ways Organisations Create Non-Human Insider Risk appeared first on IT Security Guru.

Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair

UK cybersecurity specialist Core to Cloud has appointed former Currys Group CIO Andy Gamble as Chair of its Advisory Board as the company looks to accelerate the growth of its managed security services.

Gamble brings nearly 30 years of board-level technology leadership and will work with Core to Cloud on its strategic, advisory and commercial direction across the UK enterprise and mid-market sectors.

His appointment adds further experience to the company’s Advisory Board, which includes senior security leaders from major UK organisations.

From cybersecurity buyer to advisor

Gamble spent six years as Group CIO and Chief Transformation Officer at Currys PLC, where his responsibilities included large-scale technology transformation and cyber risk.

His career has also included senior CIO positions at Dyson, Sony Electronics and Essentra PLC. That experience means Gamble has spent much of his career on the customer side of the cybersecurity market, buying and managing the types of services Core to Cloud now provides.

β€œI spent the better part of three decades as a buyer of cybersecurity services, and the experience left me with a clear view of where the market falls short,” Gamble said.

β€œMost organisations understand that cyber risk is real. Far fewer have a security function that can communicate that risk clearly at board level, or a partner that moves fast enough to keep pace with the threat.”

Gamble said Core to Cloud stood out because of its focus on proactive security, adding that he intends to help the business scale its model as a challenger to conventional managed security service providers.

Supporting Core to Cloud’s next stage of growth

Based in Cirencester, Core to Cloud works with more than 150 organisations across sectors including the NHS, retail, financial services and critical national infrastructure.

Its services span Managed Detection and Response, Third-Party Cyber Risk Management, Security Assurance, Dark Web Monitoring and Threat Intelligence, and Cyber Crisis Simulation.

James Cunningham, CEO and Founder of Core to Cloud, said Gamble’s experience at the intersection of technology, risk and commercial strategy would bring a new perspective to the company.

β€œHe understands what good security looks like from the inside and brings a depth of experience and perspective that will be hugely valuable as we continue to grow,” Cunningham said.

β€œWe have an ambitious business, a strong customer base and services we genuinely believe in. Having Andy chair our board will help us build on those foundations, challenge our thinking and accelerate the next stage of Core to Cloud’s growth.”

The post Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair appeared first on IT Security Guru.

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here.Β 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

❌