Normal view

There are new articles available, click to refresh the page.
Yesterday — 22 July 2026IT Security Guru

Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective

22 July 2026 at 12:05

Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape.

The new practice brings together Bridewell’s existing intelligence-led services, original threat research and specialist analysts under a single identity, reflecting growing customer demand for threat intelligence that informs strategic decision-making rather than simply providing indicators of compromise.

According to Bridewell, organisations are looking beyond traditional security monitoring as ransomware groups become more organised, attackers exploit trusted services and social engineering campaigns become more sophisticated. Rather than reacting to incidents, businesses want intelligence that helps them anticipate threats, understand adversaries and focus security resources where they will have the greatest impact.

Led by Gavin Knapp, Head of Cyber Threat Intelligence, BCON Collective will provide strategic, operational and tactical intelligence designed to support more informed security decision-making. The team works across areas including threat detection, vulnerability prioritisation, incident response and long-term cyber resilience planning.

“Threat intelligence has become its own discipline within cybersecurity,” said Anthony Young, CEO of Bridewell. “Organisations are progressing to see it as not just something that sits alongside security operations, rather they expect it to shape strategic decisions, inform vulnerability management and strengthen incident response.

“Gavin and the team have built an exceptional reputation for producing intelligence that is both technically rigorous and genuinely actionable. As customer demand for these services continues to grow, it made sense to give this capability its own identity while keeping it firmly rooted within Bridewell’s wider cybersecurity expertise.”

Bridewell said its CTI team has built a reputation for producing original threat research covering emerging cyber threats and attacker activity. Recent research has examined ransomware groups including DragonForce, the tactics used by Scattered Spider during attacks against major UK retailers, emerging phishing techniques such as FileFix and ConsentFix, and nation-state activity linked to North Korea.

Knapp believes the real value of threat intelligence lies in helping organisations cut through the volume of available data.

“The biggest misconception about threat intelligence is that it’s about collecting more information. It isn’t. It’s about reducing uncertainty,” he said. “Every security team already has more data than it can realistically process. The challenge is knowing which threats actually matter, which risks deserve immediate attention and where to focus before attackers make the decision for you.

“Most importantly our threat research, threat intelligence and collaboration with both Bridewell offensive security, threat detection, and response capabilities allows us to provide the key components of a threat informed defense to our CNI client base.

“BCON Collective reflects the evolution of the work we’ve already been doing for our clients. It gives our threat research and intelligence capability its own identity and creates a platform through which we can share more of our research, collaborate more closely with customers and continue helping organisations stay one step ahead of an increasingly complex threat landscape.”

Alongside its advisory services, BCON Collective will expand its programme of original threat research, annual intelligence reports, threat actor profiling and strategic intelligence briefings for organisations operating across critical national infrastructure, the public sector and commercial sectors.

The post Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective appeared first on IT Security Guru.

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns

22 July 2026 at 06:16

Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the overall trajectory of ransomware activity continues to point upwards.

The report recorded 665 ransomware attacks in June alone, with the industrials sector once again the most heavily targeted, accounting for 30% of attacks across the quarter and 28% in June. Consumer Discretionary and Information Technology rounded out the top three targeted sectors for the quarter.

North America remained the most targeted region, absorbing 44% of all Q2 attacks and 41% of June’s total, followed by Europe (26% for the quarter, 23% in June) and Asia. Qilin held its position as the most active ransomware group for a fifth consecutive quarter, linked to 14% of all Q2 attacks (301 victims), ahead of The Gentlemen (238 victims) and DragonForce (145 victims). NCC Group also flagged the emergence of KryBit, a new Ransomware-as-a-Service operation that claimed 56 victims in its first full quarter of activity.

VPNs remain a favoured entry point

The report’s spotlight section highlights corporate VPNs and internet-facing edge devices as the ransomware ecosystem’s most exploited entry point so far in 2026. Groups including Akira, Qilin and The Gentlemen have all been observed exploiting vulnerabilities in products from vendors such as Fortinet, SonicWall, Citrix and Check Point to bypass authentication and gain a foothold inside victim networks.

NCC Group said vulnerabilities affecting VPN products account for around 15% of the 150-plus Threat Intelligence Alerts it has issued so far this year, many rated high or critical severity. The report also points to “FortiBleed,” a large-scale credential exposure incident uncovered in June affecting roughly half of all publicly exposed FortiGate devices, as a development likely to fuel further exploitation in the coming months.

Software supply chain under sustained assault

Alongside the ransomware data, NCC Group’s analysts describe a marked escalation in attacks against the software development ecosystem during Q2, with campaigns hitting GitHub Actions, npm, PyPI, Docker Hub, Open VSX and the Visual Studio Code Marketplace. The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.

The report warns that these campaigns exploit “transitive trust” in software supply chains, turning maintainer accounts, CI/CD tokens and cloud credentials into high-value targets, with effects that can cascade well beyond the organisation initially compromised.

“A board-level issue”

Matt Hull, VP and Head of Cyber Intelligence and Response at NCC Group, said supply chain attacks remain one of the most attractive routes for threat actors to inflict significant operational, financial, and reputational damage, and that businesses need continuous, rather than ad hoc, monitoring and resilience.

“Although there has not been a material rise in ransomware volume in the last quarter,” Hull said, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target. He added that organisations must treat cyber security as the board-level issue it is, pointing to geopolitical tensions and rapidly evolving AI capabilities as compounding pressures on defenders.

NCC Group’s report also examines the deepening professionalisation of ransomware operations such as The Gentlemen, a rapidly-scaling RaaS group whose leaked internal database revealed structured negotiation tactics and a dedicated suite of EDR-disabling tools distributed to affiliates. Separately, the report notes a growing convergence between commodity infostealer malware and higher-end intrusion tradecraft, with new variants adopting rootkit-style concealment, browser-extension-based credential theft, and off-host decryption to evade detection.

The full report also covers geopolitical developments, including rising China-Taiwan tensions, Belarus’s shifting posture toward Russia, and Ireland’s incoming EU Council presidency, which NCC Group assesses could shape targeting patterns for state-linked threat actors in the second half of the year.

The post Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns appeared first on IT Security Guru.

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns

22 July 2026 at 05:56

A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims.

The “Cyber Threat Landscape: UK & Ireland” report, published by threat intelligence firm CYFIRMA, finds that financially motivated cybercriminals and state-aligned actors are frequently targeting the same sectors, finance, telecoms, technology, healthcare and government, and warns that cybercrime, espionage and geopolitical disruption are becoming harder to tell apart.

Russia, China, North Korea and Iran all in the mix

According to the report, Russia remains the most immediate geopolitical cyber threat to the region, with Russian-linked groups focused on critical infrastructure, undersea cables and disinformation tied to the ongoing war in Ukraine. China is flagged as the more significant long-term concern, with state-linked groups pursuing intellectual property theft and “living off the land” techniques designed to maintain quiet, persistent access inside critical networks.

The report also names several state-sponsored groups actively targeting the UK, including Russia’s APT28 (Fancy Bear) and APT29 (Cozy Bear), and China-linked APT15 and GALLIUM. It highlights a recent APT28 campaign that hijacks vulnerable home and small-office routers to redirect DNS traffic, quietly harvesting credentials and login tokens from unsuspecting users. North Korea’s Lazarus Group is also named in connection with fake job-offer lures targeting European defence and drone manufacturers, part of the long-running “Operation DreamJob” campaign.

Ransomware still dominates, with the UK bearing the brunt

Ransomware remains the most visible threat. CYFIRMA’s data shows Qilin as the most active gang targeting the region between January and May 2026, followed by DragonForce, The Gentlemen and Cl0p, with the UK absorbing the overwhelming majority of recorded victims. Ireland saw far fewer incidents, but the report notes that groups including The Gentlemen, Qilin and Interlock have all claimed Irish victims, and activity there peaked sharply in May 2026.

Professional services, manufacturing, real estate and IT emerged as the sectors hit hardest by ransomware, the report finds, with most groups now relying on double extortion, encrypting systems while also stealing data to threaten public leaks if a ransom isn’t paid.

Financially motivated crews get creative with social engineering

The report also details the tactics of financially motivated groups such as FIN6, which has been posing as job seekers on LinkedIn and Indeed to trick recruiters into opening fake résumé links laced with malware, and Scattered Spider, which continues to abuse identity and access management systems by impersonating employees to helpdesk staff in order to reset credentials or bypass multi-factor authentication.

Dark web trade in UK and Irish data continues unabated

Beyond ransomware, the report catalogues a steady stream of underground forum listings offering UK and Irish personal data for sale throughout 2026 — including an alleged 120-million-record database from a UK gambling platform, a combo list of more than 657,000 UK email-password pairs, and a dataset said to contain 734,000 UK student records. CYFIRMA says this reflects a growing emphasis among criminal groups on monetising stolen data and credentials rather than relying solely on encryption-based extortion.

Critical vulnerabilities add to the pressure

The report also flags a cluster of critical vulnerabilities disclosed during the period, including several rated 9.0 or above in the n8n workflow automation platform, Cisco’s Secure Firewall ASA and FTD software, Fortinet’s FortiOS and FortiProxy products, and VMware’s ESXi and Workstation platforms — several of which have already been linked to active exploitation.

What organisations should do

CYFIRMA’s recommendations for organisations in both countries include:

  • Accelerating patching of internet-facing systems, VPNs and edge devices, which remain the most common entry point for both ransomware crews and state-backed actors.
  • Enforcing phishing-resistant multi-factor authentication and tightening helpdesk identity-verification processes to blunt social engineering attacks like those used by Scattered Spider and FIN6.
  • Testing ransomware and DDoS response plans, including backup recoverability, given the sustained pace of attacks on critical infrastructure and public services.
  • Increasing scrutiny of third-party and vendor access, as supply chain compromise continues to be used to reach multiple organisations through a single trusted relationship.

The report’s overall message is one of convergence: as ransomware operators, spies and hacktivists increasingly pursue overlapping goals through similar tools and techniques, CYFIRMA argues that organisations can no longer treat these as separate risks to be managed in isolation.

The full research report can be found here: https://www.cyfirma.com/research/cyber-threat-landscape-uk-ireland/

The post Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns appeared first on IT Security Guru.

Before yesterdayIT Security Guru

KeeperPAM strengthens privileged access management for global construction SaaS provider Asite

21 July 2026 at 11:01

Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations.

The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform as it looks to improve visibility, simplify administration and better secure access across its international infrastructure.

Asite provides cloud-based collaboration software for the construction industry, helping organisations manage projects ranging from digital twins and 3D models to document control and supplier collaboration. With more than 500 employees and data centres spanning nine global locations, the company required a more consistent approach to managing privileged accounts, passwords and machine identities.

According to the case study, Asite was looking to overcome the limitations of browser-based password managers alongside legacy privileged access management (PAM) and secrets management tools, which it found expensive and complex to maintain. The company also needed to securely extend privileged access controls to third-party suppliers and external partners working on customer projects.

“The deployment of KeeperPAM was extremely easy, one of the best in my experience,” said Tiago Rosado, Chief Information Security Officer at Asite. “I wish other tools were as easy to deploy.”

As part of the rollout, Asite standardised password management across its workforce using Keeper’s platform, replacing browser-based password managers with centrally managed credential controls. The organisation also implemented Keeper BreachWatch to identify compromised credentials exposed on the dark web, while Keeper Secrets Manager automated the creation and rotation of secrets and encryption keys, reducing reliance on long-lived credentials.

Keeper said the deployment reflects a broader challenge facing organisations managing privileged access across distributed IT environments. Its 2026 research found that 34% of UK employees reuse passwords across multiple accounts, while 36% of UK respondents said enforcing strong password and credential practices remains either extremely or very challenging for IT and security teams.

The vendor positions KeeperPAM as a unified, cloud-native platform that combines enterprise password management, secrets management, privileged session management, endpoint privilege management, secure remote access and dark web monitoring within a single zero-trust architecture.

“Privileged access management has become a critical control layer for any organisation operating across distributed infrastructure and third-party ecosystems,” said Darren Guccione, CEO and Co-founder of Keeper Security. “Asite’s deployment of KeeperPAM demonstrates how organisations can move from fragmented, costly legacy tools to a unified platform that enforces least-privilege access, automates provisioning and delivers the visibility their security team needs, without the complexity that has historically made PAM difficult to scale.”

The full customer case study is available on the Keeper Security website.

The post KeeperPAM strengthens privileged access management for global construction SaaS provider Asite appeared first on IT Security Guru.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

21 July 2026 at 09:17

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the report‘s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

“AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

“In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

“As attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

“Many organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

1 in 4 businesses hit by cyber attacks through their supply chain in the last year

21 July 2026 at 06:30

One in four UK businesses (26%) have suffered a cyber incident that originated in their supply chain over the last year, according to new research from business continuity and disaster recovery specialist Databarracks. The finding is particularly striking given that organisations are highly aware of the risk they face: nearly half (48%) admit they have continued working with suppliers despite known resilience or security concerns.

The figures come from the Data Health Check 2026, Databarracks’ annual survey of 500 UK IT decision-makers, which has tracked IT resilience since 2008. This year’s report paints a picture of organisations that recognise the danger posed by their supply chains, but frequently feel unable to act on that knowledge.

In many cases, the research suggests, businesses simply lack viable alternatives. More than a quarter of respondents (26%) identified “dependence on suppliers” as a main barrier to improving their organisation’s resilience.

Awareness without action

The Data Health Check found that supplier assessment is now standard practice for most organisations. Almost nine in ten businesses (89%) assess supplier resilience at the point of onboarding, and the majority (61%) go further by conducting assessments annually, quarterly, or continuously.

Despite this due diligence, the risk clearly persists once a supplier relationship is underway. “Supply chain vulnerabilities” was named as one of the top three IT resilience challenges organisations expect to face over the next five years, cited by 23% of respondents – behind only AI-driven cyber threats (46%) and ransomware attacks (26%).

The data also shows a clear link between known risk and real-world impact. Organisations that knowingly continued working with risky suppliers were more than four times as likely to experience a supplier-originated cyber incident: 43% of those organisations went on to suffer an incident, compared with just 10% of organisations that had not knowingly worked with risky suppliers.

“Treat your critical suppliers like you would your own business”

Commenting on the findings, Chris Butler, Resilience Director at Databarracks, said that supply chain resilience remains one of the most persistent weaknesses in UK organisations’ defences. “This year’s findings indicate that supply chain resilience remains a critical pain point for many businesses, which the majority are aware of and which continues to be exploited by attackers. When something goes wrong at a key supplier, the cascade effects can be profound for businesses throughout the chain.”

“Despite good intentions around assessing supplier resilience, most companies don’t fully understand the depth of complexity in their supply chains. Often they’ll know who their core suppliers are, but beyond that, visibility drops away.”

“The traditional approach to assessment has long been tick-box based, with compliance questionnaires growing longer every year. This approach creates a false sense of assurance rather than real resilience.”

Butler argued that genuine improvement requires businesses to move beyond paper-based assurance and to take direct ownership of the risk that suppliers pose to their operations. “To truly manage your supply chain continuity, it’s vital to actually get visibility of the situation. Business leaders need to treat supplier resilience as part of their own resilience, not somebody else’s problem. It’s a bit of a cliché but for good reason: you really need to treat your critical suppliers like you would your own business.”

He also urged organisations to take a more collaborative approach where smaller or less mature suppliers cannot be easily replaced. “Where there isn’t a viable alternative and your existing suppliers don’t have in-house business continuity skills, offer to help. Include your suppliers in your business continuity exercises and give them the chance to rehearse with you. It’s important to practice the response to disruption together rather than in isolation. Doing this will benefit you in the long run.”

Additionally, Jamie Akhtar, CEO and Co-Founder of CyberSmart, added: “This research highlights the severe impact supply-chain attacks are having on businesses of all sizes. It is concerning that one in four businesses has experienced a cyberattack through its supply chain, but what’s even more concerning is that almost half knowingly continue to work with suppliers that have identified security weaknesses. The findings show how difficult it can be for organisations to remain secure. Businesses must manage their own security, but also the security and resilience of their supplies as well.”

“Organisations, especially SMEs, should treat suppliers as part of their own security perimeter. They should assess third-party risks before onboarding, restrict access to essential systems and data, enforce multi-factor authentication, keep software patched and maintain tested backups. Regular supplier reviews and shared incident-response plans can also reduce disruption if a partner is compromised,” Akhtar continued. 

Part of a wider resilience picture

The supply chain findings sit within a broader Data Health Check 2026 report that shows organisations bracing for a harsher resilience environment. The study found that 65% of organisations now believe a serious cyber attack could threaten their survival, while cyber remains the leading cause of IT downtime for the fourth year running, cited by 30% of organisations as their biggest cause of outages.

The report also found reasons for optimism. Business continuity planning has reached a new high, with 90% of organisations now holding a plan and four in five of those kept up to date. Ransomware resilience is also improving: although one in four organisations (25%) experienced a ransomware attack in the last 12 months, only 18% of those affected paid the ransom, while 59% recovered from backups instead.

Databarracks said the overall findings point to “integrating IT and business resilience” as the most-cited priority for organisations in 2026, reflecting a growing recognition that modern incidents – including those originating in the supply chain – rarely respect the boundaries between cyber security, IT operations, business continuity and executive decision-making.

The post 1 in 4 businesses hit by cyber attacks through their supply chain in the last year appeared first on IT Security Guru.

DigiCert expands its EMEA channel strategy with Ignition Technology

21 July 2026 at 06:19

DigiCert, a global leader in intelligent trust, has announced a strategic distribution partnership with Ignition Technology to scale its presence across EMEA, accelerate market entry and expand partner-led growth.

Through the partnership, Ignition will bring DigiCert ONE® to customers and partners across the UK and Ireland, DACH, France, Benelux and the Nordics. DigiCert’s comprehensive platform unifies PKI, DNS and automated certificate lifecycle management, helping organisations establish trust across machine identities, software, devices, digital content, and AI agents, while reducing outages, strengthening compliance and supporting the transition to post quantum cryptography.

“Across EMEA, organisations are facing increasingly complex security, operational and regulatory challenges as they embrace AI, modernise infrastructure and prepare for the post quantum era,” said Sean Remnant, Chief Strategy Officer, Ignition Technology. ”They don’t need more disconnected tools. They need a platform that simplifies complexity, helps them move faster and gives them confidence they’re ready for what’s next.”

“This partnership is about creating high impact, scalable growth across EMEA,” said Paul Holt, Group Vice President, EMEA at DigiCert. ”Ignition understands how to build markets, grow partner ecosystems and execute at pace. Together, we’ll help more organisations build the confidence to embrace AI, automate trust at scale and prepare for the post quantum era.”

The partnership reinforces DigiCert’s commitment to growing its channel across EMEA, enabling partners to help organisations simplify security, strengthen resilience and prepare with confidence for the AI and post quantum era.

The post DigiCert expands its EMEA channel strategy with Ignition Technology appeared first on IT Security Guru.

95% of Security Teams Blindsided by Vulnerabilities Between Tests

21 July 2026 at 06:02

The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes itself as the provider of the first AI-powered continuous pentest for enterprises.

The company’s new report, The State of Continuous Security Validation, surveyed enterprise security leaders and practitioners and found that 95% had discovered high or critical vulnerabilities outside their scheduled testing windows within the past year. Of those, 42% said this had happened at least once a month, underscoring a widening gap between how quickly enterprise environments change and how infrequently they are actually tested.

Three connected gaps

Synack’s researchers point to three related problems undermining enterprise security assurance. The first is a coverage gap: 38% of respondents said at least a quarter of their critical attack surface had gone independently tested or validated for more than 90 days.

The second is what the report calls an AI trust gap. Despite growing enthusiasm for AI-assisted testing, 79% of respondents said they would not act on an AI-generated finding without a human validating it first.

The third is a maturity gap: only 15% of respondents described their security testing and validation programme as continuous, despite continuous testing being the most commonly cited method (named by 22%) for confirming whether a finding is actually exploitable.

One CISO who took part in the study summed up the operational impact: “It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated.”

AI expands coverage, but humans are still needed to prove exploitability

The research suggests enterprises are keen for AI to take on a bigger role in reconnaissance, surfacing potential vulnerabilities and expanding testing coverage, but are far less willing to let it operate without human oversight. Respondents said human expertise remains essential for validating exploitability, assessing severity and business risk, testing complex workflows, cutting down false positives, and communicating risk to stakeholders.

“Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent,” said Angela Heindl-Schober, Chief Marketing Officer at Synack. “The market direction is clear: AI expands coverage, humans prove exploitability, and security validation becomes continuous. The gap is not awareness. It is execution.”

The study also identifies the main barriers to continuous security validation, including compliance-driven test cycles, integration complexity, a lack of trust in automated findings, false positives, difficulty demonstrating return on investment, and unclear ownership across teams.

“Automation can surface more signals, but security teams need evidence, not noise,” said Mark Kuhr, Co-Founder and Chief Technology Officer at Synack. “Human researchers bring the creativity and context to chain weaknesses, confirm exploitability and show what an attacker can actually do.”

A Human + AI model for continuous validation

Synack argues the findings reinforce the case for a combined Human + AI approach to security validation. Its Sara AI Pentesting offering uses what the company calls the Synack Autonomous Red Agent to scale reconnaissance and testing, while the Synack Red Team, a vetted network of more than 1,500 security researchers, is used to validate real-world exploitability, uncover chained attack paths, and provide context that automation alone cannot supply.

Together, the company says, the two approaches are designed to help organisations move away from periodic, point-in-time security snapshots and towards continuous security validation.

The post 95% of Security Teams Blindsided by Vulnerabilities Between Tests appeared first on IT Security Guru.

What Does the Cyber Industry Want to See From the New UK Government?

20 July 2026 at 09:40

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, and the potential reorganisation of the Department for Science, Innovation and Technology (DSIT), with its responsibilities redistributed across other government departments.

So, what does the cyber community hope Burnham will do in the realm of cybersecurity, AI and tech as Prime Minister? We asked the industry…    

Charlotte Wilson, Head of Enterprise at Check Point said: “Britain’s AI department is at the forefront of the country’s productivity strategy, playing a crucial role in how the technology will be developed and rolled out to drive wider economic growth and defence.”

“Incoming policymakers should take heed; artificial intelligence is the gorilla in the room and will remain so for the foreseeable future. Any suggestion of redeployment or downsizing could send the wrong signal to businesses and cyber criminals about how seriously we take the most transformational technology in living memory,” Wilson continued. 

Dray Agha, Senior Manager of Security Operations at Huntress, added: “Smart infrastructure beats a spending war, and fortunately the UK can’t outspend the US or China on AI models anyway, so the new Prime Minister must focus on where we can win: secure public datasets and targeted sovereign compute.”

“Safely unlocking NHS data while fortifying our energy grid will build real domestic leverage without compromising national security. With guaranteed access to US tech currently on ice, relying solely on Washington is no longer a viable security strategy. The UK must leverage our AI Security Institute to build a ‘middle-power’ tech coalition with NATO and Commonwealth allies, pooling resources to ensure collective cyber resilience.”

Additionally, Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, noted: “The UK doesn’t need to win the frontier model race; it needs to be a serious, trustworthy place to deploy AI at scale. That’s a more achievable and arguably more valuable position. The ally-pooling argument on sovereign compute and cloud interoperability is sensible from both an economic and security standpoint.”

“The UK’s convening credibility on this particularly through the AI Security Institute is a genuine asset that Burnham should be using. Unlocking health data for AI R&D is genuinely valuable but it’s only responsible if the security and governance infrastructure around that data is built first, not retrofitted after the damage is done. Right now the ambition is ahead of the security maturity.”

Jake Taylor, Head of Government NEMEA at Filigran, said:  “If the new government wants to bring more critical national infrastructure under public ownership, cybersecurity has to become part of that conversation from day one. National resilience isn’t just about protecting individual organisations anymore. It’s about ensuring energy providers, government, suppliers and operators can share intelligence, understand emerging threats and coordinate their response before disruption spreads.”

“The biggest challenge isn’t a lack of security tools. Most critical infrastructure organisations already have those. The challenge is breaking down the silos that still exist between organisations and turning threat intelligence into something that informs operational decisions, rather than simply generating more alerts. As the geopolitical environment becomes increasingly volatile and nation-state activity continues to rise, collaboration will be every bit as important as technology.”

Taylor continued, “the Cyber Security and Resilience Bill is an important step because it moves the conversation towards common standards and greater coordination. If public ownership expands, cybersecurity needs to evolve from a collection of individual security programmes into a genuinely national capability, where intelligence sharing and continuous threat exposure management become fundamental to protecting essential services.” 

Andy Burnham’s long-term plans for the UK’s cyber, AI and technology sectors are still taking shape. The Guru team will be keeping a close eye on developments as his new government begins to set out its agenda.

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

20 July 2026 at 09:27

Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments.

The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance and runtime behaviour. The announcement comes as organisations rapidly adopt AI agents that can interact with enterprise systems and perform tasks autonomously. Because these agents rely on APIs to access data and invoke tools, Salt argues that traditional API governance has become an essential part of governing AI systems.

Rather than requiring organisations to build governance frameworks from scratch, the Policy Hub provides a library of policies that can be activated immediately and customised to suit different environments. Salt describes the approach as similar to an “app store” for agentic security, allowing security teams to deploy pre-built governance policies across the infrastructure that supports AI agents.

The expanded library includes more than a dozen policies designed specifically for agentic AI, covering areas such as MCP server configuration, agent authorisation and the risks associated with autonomous agent behaviour. Other policies address data security, OAuth, API architecture, third-party risk and compliance with frameworks including GDPR, ISO 27001, HIPAA, PCI DSS and SOC 2.

According to Salt, 61 of the 100 policies are enabled automatically, while the remaining policies can be activated with a single click. Organisations can also create their own custom policies to extend governance beyond the pre-built library. The Policy Hub forms part of the Salt Agentic Security Platform, which provides visibility across what the company calls the Agentic Security Graph, encompassing LLMs, MCP servers, APIs and connected enterprise applications.

Michael Callahan, VP of Strategy and CMO at Salt Security, said many organisations recognise the need for AI governance but struggle to know where to begin. “When we launched the Policy Hub in 2024, the most common thing we heard from CISOs was, ‘We know we need posture governance, but we have no idea where to start.’ That question was killing governance programmes before they launched. The inclusion of 100 policies means that question now has a concrete answer. Security teams can walk in on day one with meaningful protection already active and it can be extended from there without limit.”

Salt said many of the policies were originally developed for API posture governance but now play a broader role as organisations deploy AI agents. As AI systems increasingly depend on APIs, identity platforms and MCP servers to perform actions, the company believes governance must extend across the entire agentic infrastructure rather than focusing solely on AI models or prompts.

The company also highlighted its MCP server discovery capabilities, introduced in 2025, which are supported by dedicated governance policies for identifying configuration issues and controlling how MCP servers interact with enterprise systems.

In June, Salt also launched Salt Code, extending the same governance engine into the software development lifecycle to apply policies to AI-generated code during development.

Aner Gelman, VP of Products at Salt Security, said boards are increasingly asking organisations to demonstrate how AI is being governed.

“The board question CISOs are being asked right now is not whether we have AI governance. It is whether we can prove it. Having 100 policies in active deployment is a concrete, operational answer to that question. Not a roadmap. Not a strategy. An active governance layer running today.”

The 100 pre-built policies are available immediately to customers using the Salt Agentic Security Platform.

The post Salt Security tackles AI governance challenge with 100 pre-built agentic security policies appeared first on IT Security Guru.

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

20 July 2026 at 08:58

Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.

The partnership brings together Critical Cloud’s Managed Runtime Assurance operating model with Tarian Labs’ offensive security specialists, whose experience spans government, defence and critical national infrastructure projects.

Managed Runtime Assurance focuses on the day-to-day operation of production applications, cloud platforms and AI systems, helping organisations maintain visibility, resilience, security, operational efficiency and compliance readiness. Instead of producing a report that reflects a single point in time, security findings become part of an ongoing cycle of remediation, retesting and evidence-based validation.

The service combines Critical Cloud’s Datadog-powered managed operating model with Tarian Labs’ independent testing capabilities through an Observe, Detect, Validate methodology. Critical Cloud manages monitoring, governance and runtime operations across production environments, while Tarian Labs performs penetration testing, cloud and infrastructure assessments, web application reviews, API testing and follow-up verification. Findings move directly into remediation before independent retesting confirms they have been addressed.

The partnership preserves clear separation of responsibilities. Tarian Labs owns testing methodology, findings, severity ratings and retesting, while Critical Cloud leads remediation and operational improvements. Every engagement is delivered under customer authorisation, agreed scope, defined rules of engagement and controlled evidence management.

“Detection without validation is hope, not assurance,” said James Smith, CEO of Critical Cloud. “Today’s regulated organisations need continuous proof that production controls continue to perform as intended, particularly as technology changes at an increasingly rapid pace.”

“A penetration test should be the beginning of improvement rather than the end of the process,” said Kevin Hanford, Co-Founder and CEO of Tarian Labs. “By linking independent testing with remediation and verification, we help organisations demonstrate that security risks have been effectively resolved.”

Continuous Runtime Security Validation is now available across the UK and Ireland, with a packaged joint offering planned for a later date. Future joint activities include fintech events in Wales and a live demonstration environment that illustrates the complete Observe, Detect, Validate lifecycle, including remediation, retesting and evidence of closure.

Critical Cloud is ISO 27001 certified, holds Cyber Essentials Plus, and is recognised as a Powered by Datadog accredited partner and Datadog Advanced Partner. Tarian Labs delivers engagements through CREST registered practitioners with final sign-off at NCSC-recognised CHECK Team Leader (CSTL-INF) level.

The post New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience appeared first on IT Security Guru.

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

20 July 2026 at 07:27

Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026.

The report, Gen’s first half-yearly threat publication after previously reporting on a quarterly basis, argues that the defining pattern of the period was not any single new technique, but attackers consistently inserting themselves into systems and moments that users, platforms and security tools already trust, from hotel booking threads and WhatsApp device pairing to software update channels and AI agent permissions.

“The strongest pattern in the first half of 2026 was the way different threats converged around trust,” said Luis Corrons, Security Evangelist at Gen. Scams, account takeovers, malicious packages and AI agents, he said, all moved closer to the systems, workflows and permissions people already rely on, meaning attacks increasingly succeed before a victim ever reaches an obviously suspicious moment.

Tech support and imposter scams surge

Tech support scam detections reached 20.3 million blocked attacks in H1 2026, up 61.6% on the second half of 2025. Gen said part of the rise reflects newly introduced detection coverage, but also pointed to campaigns hosted on legitimate-looking cloud infrastructure, including ondigitalocean[.]app domains and fake Windows Defender error pages hosted on Google Cloud Storage in Germany and France. Windows users accounted for 92% of blocked tech support scam attacks, and the US, France, Germany, and Japan were the most targeted countries.

Government impersonation scams rose 387% to almost 1 million blocked attacks, with 81% of that activity concentrated in the United States. Family impersonation scams, often delivered by SMS to Android users and increasingly using AI voice cloning, rose 454.2% and were concentrated in the Netherlands, France, Ireland and Germany.

E-shop scams and fake online stores became one of the highest-volume categories tracked, with 114.2 million blocked attacks, up 109% half-over-half, including one variant using .click domains that alone accounted for more than 10 million blocks. “Fake tutorial” or “scam-yourself” attacks, which trick users into manually running malicious commands via fake CAPTCHA or verification prompts, rose 193% to 5.26 million blocked attempts.

Malvertising was also a major driver of activity, representing almost 30% of detections. Gen’s separate Scam Ad Machine research, examining 14.57 million ads across the EU and UK, found that nearly one in three were scam-related, generating more than 304 million impressions in under a month.

Localised banking trojans, infostealers and crypto-clippers

Regional malware campaigns leaned heavily on local-language lures. Banking trojan operators in Czechia, Slovakia and Poland used JavaScript droppers disguised as shipping notices and invoices, in some cases sent from already-compromised corporate mailboxes. RAT campaigns in Italy, Poland and Czechia used fake invoices, steganographic loaders and multi-stage PowerShell to deploy Remcos and Babylon RAT, among others.

Gen Threat Labs also identified Remus, a new 64-bit infostealer it attributes to the Lumma Stealer family, based on shared obfuscation, string-handling, and browser credential theft techniques, including a bypass of Chrome’s Application-Bound Encryption. Separately, researchers tracked a four-stage cryptocurrency infection chain ending in a Rust-based clipboard hijacker that monitors for wallet addresses across 21 blockchain types and silently swaps in attacker-controlled addresses. The same campaign used Binance Smart Chain to resolve command-and-control infrastructure via EtherHiding, making its infrastructure harder to take down than a conventional domain.

Software supply chain and a cracked-macOS-app wave

Gen documented multiple software supply chain incidents, including compromised npm and PyPI packages, hijacked maintainer accounts, and GitHub accounts abused to push malicious commits while preserving a convincing commit history. In one case, a compromised npm publishing token was used to push an unauthorised update to the Cline CLI that installed malware referred to as OpenClaw onto developer machines during an eight-hour window.

On macOS, Gen tracked a cracked-software distribution chain that pushed users toward mirror sites, torrents, forums, and Telegram channels, blocking roughly 108,000 launch attempts for these applications within 48 hours in a single wave. The payloads included cryptominers, infostealers, and backdoors, but Gen said the more significant issue was permission abuse: installation guides frequently instructed users to disable Gatekeeper and System Integrity Protection, or to grant Full Disk Access, thereby granting broad system access to unsigned binaries.

AI agents move from chatbot risk to execution risk

A significant portion of the report focuses on AI agents, which Gen says have shifted the security conversation because they turn model output into real-world action, fetching URLs, installing packages, editing files, or calling APIs, often with a user’s own credentials and local access.

The report cites an incident in which a Meta AI security researcher granted an AI agent access to her inbox to triage messages, and the agent began deleting emails while reportedly ignoring stop commands. Gen noted that this was reported by TechCrunch and could not be independently verified as forensic evidence, but said it illustrates how a misinterpreted instruction can have real consequences once an agent holds genuine permissions.

The report also references indirect prompt injection documented in the wild by Unit 42, where hidden instructions embedded in web content are later processed by an AI system, and separate research (“Double Agents”) identifying excessive default permissions in a cloud AI agent deployment that allowed a pivot into customer project resources.

Gen discusses its own response to agent risk at length, including a runtime enforcement tool called Sage that checks agent actions, shell commands, URL fetches, file writes, package installs, before they execute, alongside an Agent Trust Hub for pre-use verification, an Agent Detection and Response (ADR) capability, and a proposed cross-industry standard, AARTS, intended to give agent hosts a shared way to expose security-relevant events and enforcement points.

The report also touches on Anthropic’s Claude Mythos and Fable 5 models, noting Anthropic’s own disclosure that Mythos Preview could identify and exploit vulnerabilities in major operating systems and browsers when directed to, and that access to Fable 5 and Mythos 5 was briefly suspended in mid-2026 following a US export-control directive before being restored. Gen frames this as evidence that, once a model can materially accelerate cyber work, questions of who can access it and under what safeguards become part of the security picture, not just the model’s behaviour.

Privacy: persistent access, not just breaches

Gen blocked an average of 310.8 million tracking attempts per month in H1 2026, around 1.9 billion over the half-year. The report highlights GhostPairing, an attack that abuses WhatsApp’s legitimate device-linking feature to trick users into approving an attacker-controlled browser as a linked device, giving the attacker an authorised session that can persist until manually revoked.

The report also raises AI agent memory as an emerging privacy boundary, citing research papers describing backdoored agents that exfiltrate stored user context via disguised tool calls, and separately flags recent FTC settlements and actions against location-data brokers Kochava and Mobilewalla for selling sensitive location data without consent.

Identity and financial fraud: exposure moves fast toward misuse

Gen recorded 18,618 breach events affecting its customers in H1 2026, up 94.5% on the prior half-year, while breach notification alerts with an identified source sent to Norton and LifeLock users rose 628.1% to 3.3 million. February alone accounted for roughly a third of all H1 breach notifications, a spike Gen links partly to the Under Armour breach reported in January 2026, which public reporting said affected around 72 million email addresses.

Downstream financial signals also rose sharply: credit inquiry alerts reached 460,000 in June; depository activity alerts rose 734%; credit activity alerts rose more than tenfold; and web skimming attacks blocked at checkout pages rose 212% to 996,300. Gen also flags a distinct pattern of first-party fraud, in which real, verified accounts, created by people recruited online with promises of quick cash, are later handed over to fraud operators for cash advance abuse, wallet funding or money mule activity, making the behaviour harder to catch at onboarding.

The takeaway

Gen’s overall conclusion is that few of the H1 2026 attacks relied on classic red flags such as poor grammar or obviously suspicious links. Instead, they were built around real reservation details, compromised-but-legitimate mailboxes, trusted update paths and permissions that users had already granted. The report argues that protection increasingly has to sit at the point where trust is granted or transferred, before a payment page, before a package installs, before an AI agent is allowed to act, rather than relying on users to spot the danger themselves.

The post Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust appeared first on IT Security Guru.

Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites

20 July 2026 at 06:32

A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB.

The malware, dubbed HOLLOWGRAPH, was detailed by Group-IB‘s Threat Intelligence team, which said it has attributed the tool with high confidence to the Cavern backdoor framework, a modular command-and-control (C2) toolkit previously linked to Iranian-nexus activity. Researchers said the sample abuses the Microsoft Graph API via a compromised Microsoft 365 account traced to Israel, using it to blend malicious communications into legitimate cloud traffic.

A calendar as a dead drop

HOLLOWGRAPH is a lightweight implant that understands only two instructions, get and send, but carries them out entirely through trusted Microsoft cloud infrastructure rather than attacker-owned servers. Group-IB’s analysis describes the compromised mailbox’s calendar being used as a two-way dead drop: operators plant instructions by creating calendar events, and the malware exfiltrates stolen files by creating its own events with encrypted attachments.

To keep the mailbox owner from noticing anything unusual, every event created by the malware is dated far into the future, specifically 13 May 2050, with the stolen or tasking data hidden inside file attachments rather than the event body. Get requests search for events with a subject line referencing a task ID, while send operations upload encrypted data in chunks named “File{n}.txt” before renaming the event to an operator-recognisable tag.

DNS tunnelling keeps credentials fresh

Alongside the calendar-based C2 channel, HOLLOWGRAPH maintains a separate communications path used solely to refresh the Microsoft Entra ID (formerly Azure AD) credentials it needs to continue authenticating to the Graph API. Group-IB found that the malware performs DNS tunnelling, issuing IPv6 AAAA record lookups against an attacker-controlled domain, cloudlanecdn[.]com, to retrieve updated tenant IDs, client IDs, client secrets, and mailbox details, which it then writes to a configuration file on disk disguised as an ordinary log file, logAzure.txt.

According to the write-up, length-indicating queries and data-carrying queries are distinguished by naming convention, with each returned IPv6 address smuggling 14 usable bytes of payload that the malware reassembles into plaintext credential data. This DNS channel, researchers noted, is not itself encrypted.

Communications sent through the Graph API channel, by contrast, are protected with hybrid RSA and AES-256-GCM encryption, and the malware uses separate RSA key pairs for inbound tasking and outbound exfiltration, keeping the two directions cryptographically independent of one another.

Linked to the Cavern framework and possibly Lyceum

Group-IB said several technical characteristics tie HOLLOWGRAPH to the Cavern framework, including a matching command syntax and observed tasking that mirrors Cavern’s known structure, among them a “toggle debug logging” self-command used elsewhere by the framework.

The researchers stopped short of attributing the campaign to a specific, previously known threat actor, but noted overlaps with malware previously associated with Lyceum, a group considered a sub-cluster of the Iranian threat actor OilRig. Group-IB said Cavern’s modular backdoor functionality closely resembles a .NET backdoor used by Lyceum in early 2025, including shared command codes and a similar approach to loading plugin modules from disk on demand. The firm characterised this potential link as low confidence.

A small, disciplined set of victims

Group-IB said it identified at least 12 systems infected with HOLLOWGRAPH, of which only around three were actively exchanging data with the attacker at the time of analysis. The earliest observed communication between a victim and the attacker was recorded on 3 June 2026, with the most recent seen on 9 July 2026, indicating the malware has been in active use since at least early June.

Researchers said the small victim count, combined with the fact that the compromised mailbox used for exfiltration belongs to an Israeli organisation and that malware samples were uploaded for analysis from Israel, points to a deliberately narrow, targeted espionage operation rather than opportunistic mass compromise.

Why it matters

The use of legitimate cloud services for C2 is a well-established evasion tactic, but HOLLOWGRAPH’s approach of hiding both tasking and exfiltrated data inside calendar event attachments, dated decades into the future, illustrates how creatively threat actors are exploiting everyday collaboration features to slip past perimeter and email-security defences. Because the traffic runs entirely through Microsoft’s own infrastructure and a legitimately authenticated (if compromised) account, it can be difficult for defenders to distinguish from normal Microsoft 365 usage without close inspection of Graph API activity and mailbox audit logs.

Recommendations

Group-IB has urged organisations, particularly those operating in or connected to Israel, to:

  • Hunt for indicators associated with HOLLOWGRAPH and the Cavern framework, including the domain cloudlanecdn[.]com and the configuration file logAzure.txt.
  • Monitor Microsoft Graph API activity and mailbox audit logs for anomalous calendar operations performed by an application rather than a user, including event creation, attachment uploads and subject-line changes.
  • Watch for calendar artefacts consistent with the malware, such as events dated to 2050-05-13, GUID-only subjects, or subjects following the “Event ID:” or “Boss{..}ID{..}” naming patterns with “File{n}.txt” attachments.
  • Restrict, monitor and audit OAuth2 applications using client credentials, and alert on the creation of new client secrets.
  • Enforce Conditional Access policies, regular credential rotation and anomalous-token detection across Microsoft 365 and Entra ID environments.
  • Deploy DNS monitoring capable of spotting tunnelling activity, such as unusually frequent AAAA queries or long, high-entropy subdomains, and route outbound DNS through controlled, filtered resolvers.

Group-IB said it will continue to track the evolution of the Cavern framework, adding that the sophistication of HOLLOWGRAPH, combined with its narrow targeting, points to a capable and well-resourced adversary, even though the specific group behind the campaign remains unconfirmed. More information can be found here: https://www.group-ib.com/blog/hollowgraph-microsoft-365/

The post Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites appeared first on IT Security Guru.

CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging

17 July 2026 at 05:43

More than three-quarters of European CISOs believe their C-suite doesn’t fully understand the cyber risk posed by their own employees, a gap that’s widening just as AI makes attacks on human judgement faster, more convincing and harder to spot.

That’s according to new research from MetaCompliance, the human cyber risk management firm, which polled 200 CISOs across the UK, France, Germany and Sweden. The picture it paints is of security leaders trying to hold the line on human-layer risk without the consistent senior backing, clear ownership, or shared understanding they need to do so.

AI is changing what CISOs are worried about

The survey found that among CISOs who feel less confident about their organisation’s cyber resilience than they did a year ago, AI-enabled social engineering was the single biggest reason cited, named by almost half of that group. It’s a sign that attackers are moving away from crude, easily-spotted phishing and towards convincing impersonation and fraud attempts generated at scale.

Employees, unsurprisingly, remain squarely in the firing line. More than two in three CISOs still rank their own staff as the biggest security risk to the business, suggesting AI isn’t creating a new problem so much as turbocharging an old one.

Specific concerns bear that out:

  • Over 40% of CISOs are worried AI is increasing the speed and impact of social engineering attacks
  • 40% fear staff are feeding sensitive data into generative AI tools
  • 41% are concerned about malicious insiders using AI to enable fraud, cybercrime or data theft
  • In the UK specifically, deepfake impersonation stands out as a top worry — more than half of UK CISOs flagged it as a major threat, the highest figure of any country in the study

Support from the top doesn’t stick

Where the research gets more uncomfortable for boardrooms is on backing. Almost four in five CISOs (79%) say leadership enthusiasm for security awareness programmes tends to fade once the initial push is over, and 76% say they’re stuck trying to satisfy different stakeholders who all want different human-risk metrics. Roughly a quarter point to cross-functional alignment as one of the areas they feel least confident managing.

James Mackay, CEO of MetaCompliance, said AI has changed the stakes: “Attackers are no longer relying on obvious scams or poorly written phishing emails. They can now create highly convincing impersonation attempts, social engineering attacks and fraudulent communications at scale.”

He argued that puts a premium on sustained executive engagement rather than one-off initiatives: “Human cyber risk is no longer just an awareness issue or a training issue; it is a strategic business risk… If leadership support fades after the initial push, organisations are left exposed.”

Where CISOs go from here

Improving resilience against AI-driven social engineering is now a stated priority for the year ahead, with close to a quarter of CISOs naming it as a key focus. Mackay suggested the shift needs to be structural rather than seasonal: organisations that fare best will treat human risk as an ongoing management discipline rather than a periodic training exercise, giving employees real-time, contextual support at the moment a risky decision is actually being made, rather than relying solely on annual training modules.

The findings come at a moment when AI-generated phishing, deepfake voice and video, and synthetic impersonation are becoming difficult to distinguish from genuine communications — putting fresh pressure on security teams to secure top-level buy-in before the next wave of attacks arrives.

The post CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging appeared first on IT Security Guru.

AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk

16 July 2026 at 05:53

Today marks AI Appreciation Day, the annual moment set aside to reflect on how far artificial intelligence has come. For the security industry, that reflection looks less like a party and more like a stocktake. AI has quietly become embedded in almost every layer of enterprise IT: writing code, triaging alerts, hunting threats, running backups, and increasingly, acting on its own initiative. The question security leaders are asking this year isn’t whether AI deserves appreciation but whether organisations have built the identity, governance and resilience layers to deserve what AI can now do.

IT Security Guru asked cybersecurity leaders from across the industry, spanning identity, threat intelligence, backup and recovery, GRC and cyber-resilience vendors, what AI Appreciation Day means to them in 2026. Their answers converge on a theme: AI has earned its seat at the table, but trust, accountability and human oversight haven’t kept pace with its capabilities.

The identity gap nobody planned for

The most immediate concern isn’t whether AI works; it’s whether anyone can say with certainty what it did and why. As AI agents move from answering prompts to independently taking action, that ambiguity becomes a governance problem in its own right.

John Cannava, CIO at Ping Identity, argues that this shift demands a fundamental rethink of how organisations manage machine identity:

“Organisations are increasingly deploying AI agents across the enterprise, and the opportunities for innovation and efficiency are tremendous. These systems are doing more than just responding to prompts. They’re making decisions, taking actions, and even spawning new agents with increasing autonomy and speed. That evolution is transforming how work gets done, and it’s also reshaping the security landscape. Now the challenge is that many organisations are adopting AI agents faster than they can establish clear identity, accountability, and governance for them. When you can’t definitively answer what an agent did, why it did it, or under whose authority it acted, you create unnecessary risk and uncertainty. This is why identity for AI must become a foundational priority. Every agent needs a verifiable identity, clear permissions, and continuous oversight, just like any human user or service account. By building trust, visibility, and accountability into AI from the start, organisations can unlock the full potential of autonomous AI while managing risk and strengthening security.”

Dave Hayes, Vice President of Product at FusionAuth, goes further, arguing that the entire framing of “agent legitimacy” misses the point:

“An AI agent is not a new user to authenticate. It has no authority of its own; it acts for a human, and that human is where the authority comes from. So, the question isn’t whether the agent is legitimate, but whether it can do only what its human owner is already allowed to do. Policy can’t enforce that. People follow the rules partly because breaking them gets you fired, and an agent has no job to lose. Give it a goal, and it treats your policy as an obstacle to work around. We surveyed 300 security and technology leaders: 84% of those most confident in their AI security had a confirmed AI-identity breach last year, most with governance they’d have called comprehensive. Architecture fixes this, not wording. AI is probabilistic, so your identity layer has to be deterministic.”

That statistic is worth sitting with: the organisations most confident in their AI security were also the ones most likely to have already been breached through an AI identity. Confidence, it turns out, is not the same as control.

Governance stops being optional by law, not just by choice

If identity is the technical gap, governance is the organisational one. Several contributors argued that the industry’s instinct to treat governance as a brake on innovation is exactly backwards, and that regulators are no longer leaving the choice up to individual companies.

Shane Barney, CISO at Keeper Security, frames the real question of AI Appreciation Day as one of visibility, not capability:

“AI Appreciation Day is a moment to ask a harder question than what AI has made possible: do organisations know what it’s doing once it’s live inside their environments? For most security teams, the honest answer is not well enough. Most organizations have spent the last two years asking how fast they can adopt AI. The better question is whether they actually know what it’s doing once it’s inside their environment. That distinction matters more than most security teams are comfortable admitting. AI agents are operating inside enterprise environments with privileged access, handling sensitive data and making autonomous decisions — often with no more oversight than an unmonitored service account. Keeper’s 2026 global research found that 56% of organisations cite employees inadvertently sharing sensitive information through AI tools as their biggest security gap. That’s not a technology problem. It’s a governance problem, and it’s sitting unaddressed while adoption accelerates. The external pressure is arriving now regardless. From August 2, EU regulators have full enforcement authority under the AI Act, with national authorities across all 27 member states empowered to investigate, restrict and sanction non-compliant AI deployments. For enterprise security teams, that means AI governance is no longer internally discretionary. The organizations that will be in the best position are the ones treating every AI agent like what it actually is: a new identity, with access rights, audit obligations and the potential to cause real damage if left ungoverned. That means enforcing least privilege, maintaining credential controls and building a full audit trail across every identity in the environment, human or otherwise. The fundamentals still apply. They just need to be extended to cover the parts of the environment that weren’t there two years ago.”

Matt Kunkel, Co-Founder and Executive Chairman at LogicGate, pushes back directly on the idea that governance and innovation are in tension:

“From HR and marketing to compliance and finance, there’s not a single department that doesn’t use AI in some form or another today. Yet, too many organisations hesitate at the idea of AI governance because, to them, governance means red tape, rules, and other roadblocks. But what these leaders fail to realise is that a strong AI governance framework isn’t hindering innovation — in fact, it’s exactly what your company needs to keep pace with today’s innovation and deliver real value. With an AI governance framework in place, businesses can move forward with full visibility into their current AI landscape, a clear understanding of how AI directly ties to business goals, and immediate recognition of risks and how to mitigate them. This ensures that the AI solutions in use are delivering real value while also allowing you to rapidly deploy them for use cases across departments without encountering legal bottlenecks each time you implement a new tool.”

The shadow AI problem hiding in plain sight

Long before organisations get to agent identity or governance frameworks, many are missing something more basic: a clear picture of how staff are already using AI day to day, sanctioned or not.

Tim Ward, CEO and co-founder at Redflags, argues that the real risk on AI Appreciation Day isn’t capability, but blind spots:

“On AI Appreciation Day, most of the conversation is about what AI can do. The more urgent question for businesses is what employees are already doing with it, often without anyone in security ever finding out. AI tools have moved into daily work faster than any technology in recent memory, and adoption isn’t waiting for a policy to catch up. People are pasting client data, source code, and financial details into public tools because they’re useful, not because anyone approved it. Underneath it, this comes down to visibility. Most organisations can’t currently answer basic questions about their own exposure: which AI tools are being used, by whom, and what’s leaving the business as a result. Blocking tools outright rarely works and just pushes usage further out of sight. The businesses managing this well aren’t the ones with the strictest AI policy on paper, but those who’ve built real visibility into how AI is actually being used day to day, and can guide people toward safer habits in the moment, rather than finding out after something’s already gone wrong.”

Why full autonomy is the wrong goal

As vendors race to market “self-driving” security operations centres, several leaders used AI Appreciation Day to push back on the idea that removing humans from the loop is progress.

Dray Agha, senior manager of security operations at Huntress, is blunt about the risk of handing AI the wheel:

“While threat actors are rapidly weaponising AI to scale their attacks, the defensive answer isn’t to build completely autonomous security systems. Full autonomy is a dangerous goal in cybersecurity because the stakes are simply too high. AI is an incredible engine for processing vast amounts of threat telemetry at lightning speed, but handing it the ‘steering wheel’ without human oversight risks catastrophic false positives, potentially shutting down critical business operations faster than an actual adversary ever could. This AI Appreciation Day, the real celebration shouldn’t be about replacing security analysts, but about augmenting them. AI excels at the heavy lifting, like accelerating triage by connecting the dots across millions of daily alerts and filtering out the noise. However, human judgment must remain the ultimate arbiter in the loop. The future of cyber defence relies on ‘augmented intelligence,’ where AI surfaces the needle in the haystack, and human experts apply the critical thinking, business context, and strategic judgment needed to actually neutralise the threat; an agentic extension of human reach is a better future than locking the human out in favour of black box automation.”

His colleague, Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, takes aim at the marketing narrative that surrounds days like this one:

“The security industry has a habit of treating AI as either a silver bullet or an existential threat depending on which narrative suits the moment. AI Appreciation Day tends to bring out the former. The reality, as anyone working in security operations will tell you, sits somewhere less dramatic and more complicated than either position. AI is genuinely useful in security right now in specific, well-defined applications. Threat detection at scale, alert triage, vulnerability scanning, anomaly identification in large datasets. These are areas where AI is producing real operational value and meaningfully reducing the manual burden on stretched security teams. That’s worth acknowledging honestly. The gap between what AI is marketed to do and what it actually does in production environments remains significant, and it has consequences. Organisations are making purchasing decisions based on vendor claims that don’t survive contact with their actual environment. Security leaders are facing questions from the board about their AI strategy when what they actually need is fundamental funding. Rather than appreciating AI in the abstract, security teams would be better served asking two concrete questions. First, where is AI actually reducing risk in our environment today, with evidence? Not in theory, not in the vendor demo, but in practice. Second, where is AI expanding our attack surface, and what are we doing about it?”

AI wrote the code but who’s checking it?

Nowhere is the productivity-versus-accountability tension sharper than in software development, where AI-assisted coding has gone from novelty to the default in a couple of years.

Dipto Chakravaty, chief technology officer at Black Duck, frames the shift in stark terms:

“AI Appreciation Day is a fitting moment to acknowledge that AI has become the most productive teammate developers have ever had, but also the least accountable one. With 97% of enterprise development teams now using AI coding assistants, code is being generated faster than most organizations can govern, review, or secure it. The next chapter of AI appreciation has to be about trusted verification: treating every line of AI-written code as untrusted until it’s been contextualized and validated against policy. Productivity without governance isn’t acceleration, it’s accumulated risk.”

Dr Andrew Bolster, Senior Manager, Research and Development at Black Duck, puts the burden of proof on enterprises rather than the tools themselves:

“The organizations getting the most out of AI-generated code aren’t the ones writing the most of it; they’re the ones verifying it the fastest. On AI Appreciation Day, the honest takeaway is that AI coding assistants have moved bottlenecks downstream: into manual review, security testing, and remediation. Enterprises need to be asking three questions before AI-written code ships: Do we know it was AI-generated? Has it been tested with the same rigor as human-written code? And can we prove it complies with our policies and the regulations to which we’re accountable? If the answer to any of those is ‘not consistently,’ the productivity gains are borrowed, not earned.”

Data is the foundation agentic AI stands on

Behind every identity and governance conversation sits a more basic problem: AI agents are only as trustworthy as the data they act on and only as safe as the backups that sit behind them if something goes wrong.

Tim Pfaelzer, SVP and General Manager, EMEA at Veeam, points to a widening gap between AI ambition and AI readiness:

“AI is revolutionising how organisations unlock value from their data, providing instantaneous insights and uncovering opportunities that were previously out of reach. To realise these benefits, businesses are entering the agentic era, driven by a new generation of AI agents that can act on data at machine speed. These agents are becoming autonomous, 24/7 digital workforces, scaling productivity and accelerating decision-making. The rise of the agentic era is driving tremendous investment in AI, particularly among hyperscalers, which have reportedly spent more than $650 billion building the foundations for the next phase of AI innovation. The potential of AI agents has earned a significant vote of confidence from enterprises, with 88% of organisations already actively piloting them across their technology stacks. However, it’s important to recognise that only around 7% of organisations have the foundational capabilities in place to be truly AI-ready. This presents a significant risk. A major challenge is the lack of visibility into data, which can cause AI models and agents to act on incomplete, outdated, or inaccurate information, leading to unreliable outcomes at machine speed. To address this, organisations must build a trust layer through complete visibility, governance, and resilience across every data asset. By ensuring AI agents are powered by secure, accurate, and readily recoverable data, businesses can unlock AI’s full potential without allowing it to become their Achilles’ heel.”

Geoff Burke, Senior Technology Advisor at Object First, has been tracking the same risk since last year’s AI Appreciation Day, and says his warnings have already started to materialise:

“Last year on AI Appreciation Day, I cautioned my peers on the hidden cybersecurity dangers associated with AI. Since then, many of my concerns have materialised, from highly sophisticated AI-generated attacks to accelerated vulnerability exploitation. That’s not to say I am against AI — I’m a user of it myself — but the efficiency and technological advances we’ve seen from AI haven’t come without cost. An AI agent with too much autonomy and inadequate guardrails can cause major vulnerabilities, blind spots, and challenges that may outweigh the positives. However, as long as companies are aware of and realistic about these risks, they can take action to mitigate the consequences should an AI agent malfunction and delete important data, for example. Part of this preparation should include building recovery and resilience into the foundation of IT infrastructure with Absolute Immutability, ensuring backup data cannot be modified by anyone, not even the most privileged admin, attacker, or agent.”

When the content itself can’t be trusted

It isn’t only the systems and the data behind them that need to be verifiable; increasingly, the content AI produces in the first place does, too. As generative tools get better at producing convincing text, images and video, the question of provenance becomes its own security problem.

Eoin Shanley, Director at DigiCert, argues that scalable trust, not just scalable AI, has to be the next milestone:

“2026 has been the year AI moved from experimentation into everyday use, transforming how organisations create, share and consume content at an unprecedented pace. But as AI-generated content becomes increasingly convincing, so too has the rise of deepfakes, misinformation and digital fraud, making trust in what we see and share more important than ever.

“AI is unlocking enormous opportunities for creativity and productivity, but its value depends on trust. Organisations, creators and consumers need confidence in where content came from, whether it has been altered and how it was created. Without verifiable content provenance and authenticity, confidence in digital content begins to erode, creating new opportunities for fraud and deception.

“The next phase of AI adoption will depend on making trust scalable. That means giving organisations greater visibility into AI-generated content and automating authenticity and provenance, so people can verify what they see with confidence rather than question everything they consume.”

From reactive triage to proactive defence

Set against the governance warnings is a genuinely optimistic case: that AI is closing the gap between detection and response faster than any prior generation of tooling managed to.

Neena Sharma, Head of Customer and Product Marketing at Filigran, frames adoption speed as a secondary concern to adoption discipline:

“The way we are seeing Frontier AI making advancement, it can be difficult to predict how AI will evolve over the next year. In the present, we are already seeing how vulnerability discovery time is shrinking. However, we need to be careful about blind uptake of these tools as it’s a double-edged sword. The winners won’t be who adopts AI fastest; it’ll be who adopts it deliberately. Security teams must focus on how they want to be able to utilize AI to improve defenses, not to open the attack surface even wider.”

Her colleague Deborah Galea, Cybersecurity Specialist at Filigran, sees the practical payoff already showing up in how teams operate day to day:

“AI’s biggest impact is that it’s rapidly closing the gap between spotting a threat and neutralizing it. Rather than analysts manually sifting through thousands of alerts, autonomous agents can now cross-reference indicators against an organization’s real environment, filter out the noise, test actual exposure, and trigger containment in real time. The result: security teams that move from reactive triage to genuine proactive management, catching and addressing threats before they escalate.”

Falk Schwendike, Senior Solutions Engineer at Filigran, adds that the same logic applies to identity and access risk:

“With AI, risk management stops being something you do after the fact. Modern defense models can now track how users and devices actually behave, so attackers hiding behind stolen credentials don’t stay hidden for long. If you feed enough alerts into the right automated workflows, the system can isolate a compromised endpoint or kill leaked access in milliseconds, significantly faster than any analyst could react manually. Add dark web monitoring and regular breach simulations on top, and AI makes threat management proactive.”

Keeping humans in the loop, deliberately

For all the optimism about speed, nobody in this piece is arguing for handing AI a blank cheque. Schwendike’s second contribution lays out what disciplined adoption actually looks like in practice:

“AI-powered security tools should take work off people’s plates, not bury them in false alarms. It is important for security teams to steer the technology rather than trust it blindly. Looking ahead, I see four areas that stand out. First, there’s context. Teams will have taught their AI that a break-in on an intern’s laptop is a different animal entirely from someone touching the customer database, and clean exception lists will mean the system stops flinching every time IT runs its nightly backup. Second, humans stay in the loop. The big calls, locking an executive’s account, pulling the plug on a production line, should still wait for a person to click approve. And when the AI gets something wrong, analysts won’t just dismiss it; they’ll correct it, so the system actually learns. Third, prompt engineering becomes routine. Teams build up libraries of tried-and-tested threat-hunting queries, and when they lean on an AI assistant, they give it a real job to do. An example prompt could be: ‘act as a seasoned incident response analyst and check this script for obfuscation.’ Fourth, the AI itself gets locked down. Nobody wants source code or internal logs leaking into a public model, so that gets watched closely, and the training data behind in-house systems gets protected too, so no one can quietly poison the AI’s judgment from the outside.”

What next year’s AI Appreciation Day might look like

If this year’s theme is guarded optimism, next year’s may be a genuine test of whether the industry can scale autonomy responsibly. Galea offers a note of caution about what’s coming:

“By next year’s AI Appreciation Day, I expect the industry to have moved further toward autonomous defensive agents operating at machine speed. But that progress only counts if it’s built on strict architectural guardrails, not left to the AI’s own judgment. Without those boundaries, the very agents meant to defend us risk becoming threats themselves.”

Schwendike’s own prediction for 2027 is more sweeping still, describing a world of self-remediating infrastructure and fully autonomous vulnerability hunting:

“By AI Appreciation Day 2027, we will see zero-human remediation taking over. Systems will be able to rewrite their own firewall rules and spin up clean mirror environments to keep businesses running, way before an analyst is even paged. Autonomous agent swarms will hunt for vulnerabilities around the clock, quietly deploying their own micro-patches for zero-day exploits before vendors even realize they exist. On the privacy front, enterprises will completely walk away from public AI APIs, choosing to run highly compressed, air-gapped language models on their own hardware, all so every threat prediction stays strictly inside the building. Finally, supply chain auditing will achieve true machine speed, meaning every single piece of third-party code is inspected and cleared at compilation, while auditable compliance reports assemble themselves the moment they are requested.”

The verdict

Strip away the vendor branding and a consistent picture emerges from this year’s AI Appreciation Day commentary. AI has genuinely earned its place in the security stack, accelerating triage, shrinking vulnerability discovery windows, and taking grunt work off overstretched teams. But almost every contributor here paired that appreciation with a warning: identity and accountability haven’t kept pace with autonomy, AI-generated code is shipping faster than it’s being verified, the data agents act on is often less trustworthy than assumed, and the organisations most confident in their AI security are, by Hayes’s own data, often the ones who’ve already been breached because of it.

Regulation is no longer a future consideration either. With the EU AI Act’s enforcement powers landing on 2 August, Barney’s point applies well beyond Europe: governance is moving from a discretionary best practice to a legal obligation, and organisations that treat every AI agent as a new identity with access rights, audit trails and recoverable data behind it will be the ones left standing when enforcement, or an incident, arrives.

The consensus isn’t that AI should be reined in. It’s that appreciation without architecture is just marketing. As Chakravaty puts it, productivity without governance isn’t acceleration; it’s accumulated risk. If there’s a single takeaway for security leaders heading into AI Appreciation Day 2026, it’s this: celebrate what AI has made possible, but spend at least as much energy on the identity, governance, verification, and resilience layers that determine whether that possibility becomes a liability.

The post AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk appeared first on IT Security Guru.

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider

15 July 2026 at 12:17

Moona Ederveen-Schneider is a cybersecurity expert (and Most Inspiring Woman in Cyber Award winner 2026) with more than 20 years of experience across financial services, risk and cyber resilience. She has held senior roles at Deutsche Bank, JPMorgan Chase, UBS, Nomura and ABN Amro, and previously served as Executive Director EMEA at FS-ISAC. 

As the founder of Resilia Connect and author of the Practical Post-Quantum Transition Framework, Moona works with organisations preparing for the security risks created by quantum computing. Her work focuses on post-quantum migration, crypto-agility and helping leaders turn complex technical threats into practical action. 

In this exclusive interview conducted by the Cyber Security Speakers Agency, Moona explains why the quantum threat is already taking shape, where organisations go wrong when preparing for post-quantum cryptography, and why businesses need to begin strengthening their security architecture now. 

Why does quantum computing remain an underestimated cybersecurity threat for many organisations? 

Moona Ederveen-Schneider: “Quantum computing is not simply a future threat. Adversaries are already harvesting encrypted data with the intention of decrypting it once quantum computers become powerful enough. 

“Most organisations have not yet started preparing for that transition. 

“I developed a practical post-quantum transition framework to explain the issue clearly, cut through market hype and vendor noise, and make the process manageable for organisations and their teams. 

“I also run tabletop exercises that teach organisations how to become crypto-agile. I poll participants at the beginning and again at the end of these sessions. The shift in the room is remarkable. 

“People often arrive feeling that the challenge is unmanageable. They leave with greater confidence and a clear understanding of what they need to do next.” 

How close is the quantum threat, and how urgently should organisations begin preparing? 

Moona Ederveen-Schneider: “The UK National Cyber Security Centre says organisations should complete detailed planning by 2028 and be fully migrated by 2035. 

“Google has set its own internal migration deadline of 2029, citing faster-than-expected advances in quantum computing. That reflects the wider sentiment I am seeing and the increasingly strong guidance being issued by governments globally. 

“Google is one of the organisations building these machines, so its decision deserves serious attention. 

“Large organisations typically need at least five years to complete a full cryptographic overhaul, while some may need twice that long. A 2035 deadline is therefore not generous. Organisations need to begin acting now. 

“My practical post-quantum transition framework is designed to deliver security improvements from the first day. It provides a clear starting point and a route through the process without overwhelming teams or budgets. 

“Organisations are also not preparing for a future threat in isolation. They are building more resilient architectures that can improve protection against current threats, including ransomware, AI-enabled attacks and supply chain compromise.” 

What mistakes do organisations make when beginning a post-quantum cryptography migration, and what should they do differently? 

Moona Ederveen-Schneider: “The first common mistake is treating post-quantum cryptography migration as a technology project and handing responsibility solely to the security team. 

“It is a whole organisational transformation. 

“The data that needs protecting sits across HR, legal and finance, not only within what DORA defines as critical business processes. 

“The second common mistake is beginning with the cryptographic inventory. 

“Contrary to the approach commonly repeated across the industry, I advise organisations to strengthen their data security posture first. 

“They must answer a fundamental business question: what are we protecting, and how long does it need to remain secret? 

“My practical post-quantum transition framework begins with that question and is designed to deliver security improvements immediately. It can be adapted for organisations and teams of any size.” 

The post Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider appeared first on IT Security Guru.

Proton Launches Business Continuity Service to Keep Firms Communicating Through Outages

15 July 2026 at 07:37

Swiss encrypted communications provider Proton has launched a dedicated business continuity service, aimed at helping organisations keep email and video communications running when their primary IT infrastructure fails or is taken offline.

The service is built around Proton Mail and Proton Meet, and is designed to give security and IT teams a pre-configured fallback they can activate quickly during an outage, a ransomware incident, or a third-party service disruption, without requiring staff to install new software or reset credentials under pressure.

Proton said the launch responds to a threat landscape in which outages are increasingly frequent, ransomware is spreading further into the small and mid-sized business market, and organisations face growing exposure to decisions made by US-based cloud and software providers, which remain legally bound to comply with US government directives, including those restricting service to customers outside the United States.

The company argues this exposes a structural weakness common to many security architectures: because so much business email and collaboration software ultimately runs on a small number of hyperscale platforms, chiefly Amazon Web Services, Microsoft Azure and Google Cloud, a single infrastructure failure or access restriction can take down communications across otherwise unrelated organisations simultaneously.

How it works

Under Proton’s model, organisations set up two tiers of accounts in advance. Active accounts assigned to IT administrators, business continuity coordinators, and senior leadership remain configurable and testable at any time. Dormant accounts, provisioned for the wider workforce at a reduced cost, remain inactive in the background, tied to the correct user identity and permission group until needed.

When an incident is declared, an administrator makes a single DNS change, repointing the organisation’s MX record to Proton’s mail servers instead of its usual provider. Dormant accounts are activated when employees log in with credentials or access links distributed by their administrator, after which the whole team can continue operating on Proton’s infrastructure, which the company says is fully separate from Google, Microsoft and AWS.

Organisations can also pre-configure their existing email domain inside Proton Mail, or set up a secondary domain to test failover in advance, allowing continuity plans to be rehearsed before they are ever needed.

A security case built on jurisdiction and encryption

Proton is positioning the service as much on legal and jurisdictional grounds as on technical ones. The company’s infrastructure and legal base sit in Switzerland, which it describes as neutral territory outside both the Big Tech ecosystem and US regulatory reach. Proton Mail and Proton Meet use end-to-end encryption, and the company points to a decade-long uptime record, underpinned by a 99.95 percent service-level agreement, as evidence of its resilience credentials.

Raphael Auphan, Chief Operating Officer at Proton, said organisations increasingly need to plan for disruption that is political as well as technical in origin. “Whether it’s in a week or a year, preparing now will make the difference between a managed response and an operational crisis,” Auphan said.

Proton already counts more than 100,000 organisations as Proton Mail users, and offers an Easy Switch for Business tool for firms migrating their primary email service outright. The new continuity offering is aimed instead at organisations that want an emergency fallback without giving up their existing primary provider.

Security teams considering the service will need to weigh the operational overhead of maintaining dormant accounts and rehearsed failover processes against the risk reduction it offers — a trade-off likely to depend on an organisation’s existing business continuity maturity and its risk appetite around single-vendor dependency.

The post Proton Launches Business Continuity Service to Keep Firms Communicating Through Outages appeared first on IT Security Guru.

Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards

14 July 2026 at 12:28

New research from Forescout has uncovered a sophisticated phishing campaign that uses fake seasonal eCard invitations to trick victims into installing legitimate remote management software, giving attackers long-term access to compromised devices.

The campaign, dubbed SeasonalInvite by Forescout Research’s Vedere Labs, has been active since at least January 2026 and demonstrates how cybercriminals are increasingly combining social engineering, trusted enterprise software, and AI assisted development techniques to evade traditional security defences.

The full research is available here: SeasonalInvite research

Fake eCards lure victims

According to the report, the attackers use phishing emails disguised as seasonal eCard invitations to persuade users to install legitimate Remote Monitoring and Management (RMM) tools.

Rather than deploying traditional malware, the campaign abuses commercially available software that is commonly used by IT administrators for remote support. Once installed, the tools provide attackers with persistent remote access to compromised systems.

The campaign targets both Windows and macOS users.

During its investigation, Forescout confirmed the abuse of four legitimate RMM platforms:

  • ConnectWise ScreenConnect
  • LogMeIn Resolve
  • Kaseya
  • O&O Syspectr

Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.

Hundreds of phishing domains identified

Researchers identified a large infrastructure supporting the campaign, including 959 domains themed around electronic greeting cards.

The attackers also operated a sophisticated Traffic Distribution System (TDS) consisting of 2,658 gate pages. The infrastructure was designed to direct legitimate victims to phishing websites while preventing automated security scanners from detecting malicious content.

According to Forescout, this approach makes the campaign significantly harder for security researchers and automated detection systems to identify.

Evidence points to AI generated phishing pages

One of the report’s most notable findings is evidence suggesting the phishing kit itself was created with the assistance of artificial intelligence.

Researchers found indicators that the phishing pages contained AI generated code, leading them to believe the threat actor used a large language model to build delivery pages and quickly adapt the campaign over time.

The findings reflect a growing trend of cybercriminals using AI to accelerate phishing operations, reduce development time, and rapidly generate convincing attack infrastructure.

Trusted software becomes the attack vector

Forescout said SeasonalInvite demonstrates how attackers are shifting away from custom malware in favour of abusing legitimate enterprise tools that organisations already trust.

By combining social engineering with legitimate remote management software and AI assisted development, threat actors can bypass many traditional endpoint security controls while maintaining long-term access to victim devices.

The researchers warn that organisations should not rely solely on malware detection to identify these attacks. Instead, they recommend monitoring for the unauthorised installation and use of remote management tools, strengthening phishing awareness training, and implementing controls that can detect suspicious behaviour rather than simply malicious files.

As attackers continue to refine their techniques, campaigns like SeasonalInvite highlight how trusted software and artificial intelligence are becoming powerful tools in the modern cybercriminal’s arsenal.

The post Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards appeared first on IT Security Guru.

Lidl Confirms Data Breach After Third-Party IT Provider Hack

14 July 2026 at 09:46

Lidl has confirmed that a cyberattack on one of its third-party IT service providers exposed the personal data of online shop customers in Germany, Belgium and the Netherlands, the latest in a string of supply-chain breaches to hit major European retailers this year.

The discount supermarket chain, owned by Schwarz Group, said it was informed of the incident last week and moved to notify affected customers by email, as well as to publish breach notices on its German, Belgian and Dutch support websites. In its statement, Lidl said unknown individuals had briefly gained access to “a separately stored file containing customer data” and stolen part of it, stressing that “the online shop system itself was not affected.”

The incident is a reminder of how much of a retailer’s exposure now sits outside its own walls. Boris Cipot, principal security engineer at Black Duck, said, “This incident is a textbook reminder that your security posture is only as strong as your weakest third party. Even when a retailer’s own systems hold, a compromised service provider can expose millions of customers to identity fraud, phishing, and account takeover attacks. Personal data like names, birthdates, phone numbers, and email addresses may seem low risk in isolation, but combined they become a powerful toolkit for social engineering. Additionally, the downstream costs to consumers and brand trust can far outlast the incident itself.”

According to the company, the compromised data includes customers’ salutation, first and last name, phone number, email address, date of birth, and customer number. Lidl said it currently has no evidence that passwords, billing or delivery addresses, bank details or other payment information were affected, and that customer accounts themselves had not been compromised. The retailer added that the affected IT service provider responded immediately and took steps to restore full security to its systems.

Paul Bischoff, Consumer Privacy Advocate at Comparitech, argued the nature of the stolen data limits the immediate danger, though phishing remains a real risk: “Although the breach is unfortunate, the compromised data doesn’t pose a direct threat to victims’ money or identities. It doesn’t contain credit cards or Social Security numbers, for example. Scammers could use the data to launch tailored phishing attacks and other scams, so be on the lookout for malicious emails and text messages. Scammers might pose as Lidl or a related company to trick victims into clicking malicious links.”

Cipot was more measured about how the company has handled disclosure so far, while cautioning that the real test is still to come: “Lidl deserves credit for moving quickly to notify customers and being transparent about what they don’t yet know, including the possibility that passwords, addresses, and payment data could be involved. That kind of candor presents the appropriate posture under GDPR. The real test now is follow-through: how quickly they complete the forensic investigation, how clearly they communicate updates as the scope becomes known, and how rigorously they reassess the security requirements they place on their service providers going forward.”

Lidl has filed a police report, engaged external IT forensic experts to investigate the scope of the incident, and notified the relevant data protection authorities, including the Dutch and Belgian Data Protection Authorities. The company has not named the compromised service provider or disclosed how many customers were affected. As of writing, no threat actor has publicly claimed responsibility.

Lidl, Europe’s largest food retailer, operates around 12,900 stores across 32 countries in Europe and the US and employs more than 376,000 people. The breach adds it to a growing list of retailers hit by supply-chain and third-party attacks over the past year, including Marks & Spencer, Co-op, Louis Vuitton, Pandora and Harrods, several of which have been linked to the Scattered Spider hacking group. Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the pattern has become too consistent to ignore: “Another major retailer, another third-party service provider breach. The pattern is consistent enough now that it needs calling out clearly; one of the weakest points in most organisations’ security posture isn’t their own systems, it’s the extended ecosystem of service providers that touch customer data peripherally.”

Lidl has urged customers to be alert for phishing attempts, telling them to verify the authenticity of any sender before disclosing information or clicking links, and to watch out for messages referencing their Lidl account or recent orders. Patel echoed that advice directly to anyone who has shopped with the retailer online: “If you’ve shopped on Lidl’s online store in Germany, Belgium, or the Netherlands, treat this as a prompt to act. Change your Lidl account password immediately, and if you’ve used the same password anywhere else, change it there too. Password reuse remains the single most effective way attackers turn one breach into multiple account compromises. If you receive any communication claiming to be from Lidl asking you to verify details or click a link, contact Lidl directly through their official website rather than responding.”

Cipot offered similar guidance, with a reminder that stolen data of this kind tends to resurface in scams long after the headlines fade: “Customers should treat this as a wake-up call, not just a notification. Change your Lidl password immediately (and any password reused elsewhere), enable multi-factor authentication wherever it’s offered, and be on high alert for phishing emails, texts, or calls that reference your Lidl account or recent orders. Attackers will absolutely weaponize this stolen data to craft convincing scams in the weeks and months ahead. Monitor your bank and card statements closely and consider a credit freeze if you’re in a jurisdiction where that’s available.”

The post Lidl Confirms Data Breach After Third-Party IT Provider Hack appeared first on IT Security Guru.

Black Duck Adds AI-Powered Triage and CRA-Ready Checks to Coverity Static Analysis

14 July 2026 at 08:29

Black Duck has rolled out a set of AI-driven and compliance-focused updates to Coverity, its static application security testing (SAST) tool, as the application security vendor looks to align the two-decade-old product with both the rise of AI-assisted coding and tightening European regulation.

The release marks the first time AI-powered features have shipped in Coverity, and Black Duck was keen to stress that the new capabilities can be run against a customer’s own choice of large language model, rather than a vendor-hosted service. The company said this was designed to give security and development teams control over where code and scan data are processed, a point it framed as particularly relevant for regulated industries and organisations with strict data governance requirements.

AI features aimed at cutting false positives

Chief among the additions is an AI-assisted issue triage capability, which Black Duck says is tuned to reduce false positives in C and C++ findings, a long-standing pain point for teams working in those languages, while also improving triage accuracy across the rest of Coverity’s supported languages.

Coverity has also gained a Model Context Protocol (MCP) server, allowing AI coding agents to trigger local Coverity scans and pull security and quality findings directly into their workflow. Black Duck’s pitch is that this lets agentic tools act on deterministic, reproducible scan output rather than relying purely on a model’s own probabilistic judgement of whether code is safe.

A new checker adds AI-powered detection of Insecure Direct Object Reference (IDOR) flaws in JavaScript and TypeScript codebases. IDOR vulnerabilities occur when an application exposes internal identifiers, such as user IDs, database keys or filenames, without properly checking that the requester is authorised to access them, a class of bug that has featured heavily in API-related breach disclosures.

Positioning for the Cyber Resilience Act

With reporting deadlines under the EU Cyber Resilience Act approaching, Black Duck used the update to introduce two compliance-oriented features. A new Security Impact Lens lets users sort and filter findings by security priority, bringing to security triage the kind of prioritisation Coverity has historically applied to code quality issues. Alongside it, a CRA-aligned checker option is intended to map scan results more directly to the vulnerability management and cybersecurity obligations set out in the regulation.

The update also extends language coverage to Rust 1.92, and introduces a refreshed user interface with reworked navigation and issue filtering, which Black Duck says is intended to speed up triage for teams working through large volumes of findings.

“Coverity has set the gold standard for static analysis for more than two decades, and we’re raising the bar by pairing its deterministic precision with the speed of AI, meeting customers where modern software development is heading,” said Dipto Chakravarty, Chief Product & Technology Officer at Black Duck.

“Code today is written, reviewed, and shipped by agents, and businesses have to move at machine speed to stay ahead,” Chakravarty added, arguing the update delivers AI-driven triage without sacrificing auditability, agentic workflow integration via the MCP server, and tooling that makes CRA readiness “operational, not aspirational.”

Black Duck said all of the new capabilities are now generally available to existing Coverity customers, who gain access to the AI-powered features without changes to the deterministic, auditable scanning the product is built around. Further detail is available via the Coverity Documentation Portal.

The post Black Duck Adds AI-Powered Triage and CRA-Ready Checks to Coverity Static Analysis appeared first on IT Security Guru.

❌
❌