McKesson confirms data breach after ShinyHunters claims it stole 284M records

Posted in Commentary with tags on August 31, 2026 by itnerd

Pharmaceutical and healthcare technology giant McKesson confirmed it is experiencing intermittent service disruptions following a cyberattack involving a third-party application.

The company confirmed that attackers gained unauthorized access and exfiltrated data associated with customers in its oncology and surgical business units, although customers can continue using its systems and services. McKesson said it has received reasonable assurance that the attackers are no longer inside its systems.

The potential impact is significant given McKesson’s role in the healthcare supply chain: the company delivers approximately one-third of all prescriptions in North America and distributes pharmaceuticals, oncology drugs, medical-surgical supplies and laboratory equipment.

The ShinyHunters cybercrime group has claimed responsibility and threaten

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “The McKesson incident is another reminder that an organization’s attack surface extends well beyond the systems it directly controls. Third-party applications with access to sensitive data can provide attackers with a path around otherwise mature security controls.

   “The potential impact is especially concerning in healthcare. When an organization sits at the center of the pharmaceutical and medical supply chain, a cyberattack is no longer just a data-security issue. Disruption can potentially ripple downstream to providers, pharmacies and ultimately patients.

   “Organizations need to treat third-party access with the same scrutiny as internal access. That means limiting privileges, segmenting critical systems, continuously monitoring vendor connections and having an incident response plan that assumes a trusted third party could eventually be compromised.

   “The reported 284 million records is a claim from the attackers and should be treated as unverified until McKesson confirms the scope. Regardless of the final number, this incident demonstrates why third-party risk has become one of the most important challenges in defending complex healthcare environments.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “This particular story highlights a major problem that I don’t think enough people spend time thinking about. Complexity is the enemy of computer security.

   “The more third-party vendors you integrate with, especially SaaS providers, the larger your attack surface becomes. Every integration, API, application, and vendor relationship creates another potential path into your organization.

   “I also don’t think enough is being done around supply chain security. Organizations should be asking harder questions of their SaaS providers, getting letters of attestation, understanding how these services are secured, and identifying exactly what access those vendors have to their environments.

   “AI is going to make this problem even bigger.

   “We’re seeing an explosion of custom-written SaaS applications because AI has dramatically lowered the barrier to building software. That’s fantastic in a lot of ways, but it also means we’re creating more applications, more integrations, more APIs, and ultimately more complexity at an incredible rate.

   “We’re going to continue seeing vulnerabilities and compromises that originate with third parties. Attackers don’t necessarily need to attack you directly when they can attack something you trust.

   “Once again, complexity is one of the easiest ways in.”

Damon Small, Board of Directors, Xcape, Inc.:

   “When a third-party application breach hits a healthcare supply chain giant like McKesson, a single vendor integration can escalate into a national patient data crisis. The claim that 284 million records were exfiltrated is alarming, even if core delivery operations remain online. McKesson responded quickly by notifying the Securities and Exchange Commission and engaging external incident response specialists to contain the breach. However, given the company’s central role in drug and supply distribution across North America, organizations supporting critical infrastructure must apply far more rigorous scrutiny to the third-party software partners plugged into their environments. Security teams must enforce least-privilege access, continuously monitor data egress at vendor integration points, and audit partner security controls before a secondary application becomes a primary breach vector.

   “Critical Takeaways

  • Exfiltration claims of 284 million patient records demonstrate how third-party application vulnerabilities turn peripheral software into massive data exposure events.
  • Rapid incident response, including SEC notification and external forensic engagement, is vital to containing blast radius when third-party access is compromised.
  • Supporting critical healthcare infrastructure requires rigorous ongoing security auditing and strict access bounds for all vendor software integrations.

   “When you deliver one-third of a continent’s medicine, your third-party vendors are no longer optional software; they are critical infrastructure.”

ShinyHunters have been busy. They pwned this company last week. That should tell you all you need to know about ShinyHunters, and what you need to do to defend against them.

Global watchdog names AI-driven cyberattacks the most immediate threat to financial stability

Posted in Commentary with tags on August 31, 2026 by itnerd

The Financial Stability Board (FSB) has identified the impact of frontier AI on cyberattacks as the most immediate AI-related concern for the global financial system.

FSB Chair and Bank of England Governor Andrew Bailey warned G20 finance ministers and central bank governors that advanced AI could materially change the speed, scale and economics of cyberattacks, including by accelerating attackers’ ability to discover vulnerabilities.

The FSB also warned that many countries do not yet have adequate frameworks for managing the deployment of advanced AI models. In the financial sector, growing reliance on a small number of powerful technology providers could create concentrated risk and potentially undermine market confidence if those providers are disrupted.

Bailey called for a coordinated global approach to safe model deployment, along with stronger response and recovery capabilities across financial institutions and their critical third-party providers.

John Strand, Owner, Black Hills Information Security, Inc.:

   “The problem with focusing on frontier AI is that attackers don’t need frontier AI to successfully break into financial institutions. A lot of the open-weight models available today can already help identify vulnerabilities, develop exploits, and automate attacks. They may be slower and less efficient, but in the right hands they can be every bit as deadly. We cannot solve this problem by focusing exclusively on the most advanced models. Financial institutions need an all-hands-on-deck effort to find and eliminate vulnerabilities, particularly in third-party software, before attackers get there first.”

Noelle Murata, Sr. Security Engineer, Xcape, Inc.:

   “AI-accelerated vulnerability discovery and exploit scaling transform systemic market concentration into an immediate operational threat for global financial institutions. Cybersecurity practitioners have long warned that automated tooling drastically compresses the window from vulnerability disclosure to active exploitation, making the Financial Stability Board warning to G20 leaders a necessary wake-up call outside the technology sector. The current wave of optimism and heavy investment in frontier models echoes the dot-com bubble of the late 1990s, where speculative technology spending added fragility to an already volatile market. Concentration risk paired with borrowed capital means a minor AI stumble or containment failure can rapidly turn into a systemic market event. The operational burden now shifts to financial firms to prove their recovery workflows and third-party dependencies hold up at machine speed. Although the foundational AI adoption blueprints issued by international watchdogs remain non-binding today, they establish the exact regulatory template supervisors will grade institutions against tomorrow.

   “To maintain operational resilience, security executives must audit vendor dependencies, enforce real-time integration monitoring, and validate recovery controls before automated threat campaigns disrupt core financial infrastructure.

   “Critical Takeaways

  • Global watchdog warnings elevate AI risk from routine security patching to systemic financial stability threats.
  • Market concentration combined with speculative technology investment increases susceptibility to cascading outages from machine-speed exploits.
  • Non-binding regulatory blueprints are setting the baseline standards that financial supervisors will use to audit vendor resilience and recovery speeds tomorrow.

   “Building financial security on unproven technology models means betting global market stability on pure optimism.”

Ryan McCurdy, VP of Marketing, Liquibase:

   “The biggest change AI introduces isn’t necessarily a new kind of cyberattack. It’s speed. Attackers can find vulnerabilities and exploit them faster, which gives financial institutions less time to respond.

   “You can’t solve that by adding more people and manual controls. Financial institutions need to know what changed, whether it was authorized, and whether it meets policy before that change reaches a critical system. And when something does get through, they need the visibility to understand what happened and recover quickly.

   “AI is forcing security and governance to operate at machine speed. The institutions that figure that out will be much more resilient than the ones still relying on humans to keep up.”

The key benefit to AI is speed. As in they can do attacks quickly and faster than most humans can. You therefore need to make sure that you can deal with AI at speed. Or you are guaranteed to be on the wrong end of things.

Chinese Espionage Group Turns Routers Into Surveillance Platforms

Posted in Commentary with tags on August 31, 2026 by itnerd

Sygnia has a report on Fire Ant, the China-linked group that has expanded from VMware hypervisor attacks to compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts, I

First reported in 2025, Fire Ant remained active into 2026. Explore how the threat actor expanded beyond hypervisors into trusted infrastructure, compromising routers, authentication systems, and Linux management hosts to maintain covert access, collect credentials and traffic, and reach connected high-value environments.

Justin Beals, CEO & Founder of Strike Graph

“This is the same playbook we saw with Salt Typhoon. When an actor controls the routers, they do not just gain access. They gain perspective on everything moving through that network. TACACS servers are especially dangerous to lose because they are the authentication backbone. Once an attacker owns that layer, they are not breaking in anymore. They are logging in.

The part that should worry every security leader is the log suppression. Fire Ant did not just steal credentials. It edited what defenders could see. That is a direct attack on your ability to trust your own evidence. If you cannot verify your logs, you cannot verify your incident response.

Organizations need to start treating routers and TACACS servers as first class assets in their security program, not just plumbing. That means continuous validation of configuration and log integrity, not a once a year review. Nation-state actors are patient. They will sit in network infrastructure for over a year before using it. The only defense is verifying your environment constantly, not periodically.”

Andrew Obadiaru, VP and CISO at Cobalt

“What stands out here isn’t the initial access, it’s how much effort Fire Ant put into staying invisible on infrastructure defenders rarely instrument closely. TACACS servers, hypervisors, and jump hosts tend to sit outside normal EDR coverage, which makes them attractive precisely because compromise there doesn’t trigger the alerts a workstation infection would. Injecting a credential-harvesting library directly into a running authentication process, rather than dropping a standalone sniffer, is a meaningful evolution because it blends into legitimate process behavior and survives more routine cleanup. Renaming backdoors to impersonate SentinelOne and Cybereason processes reflects the same logic: attackers are increasingly optimizing for what an analyst glances past rather than what a signature catches. The evidence tampering here, rewriting login history, suppressing SNMP and router logs, disabling SELinux, is also a reminder that single-source telemetry can’t be trusted for high-value infrastructure. Organizations should treat routers, TACACS servers, and hypervisors as first-class forensic assets, not just plumbing, and validate authentication logs against memory, disk, and network evidence independently. This pattern of long-dwell, infrastructure-level access lines up with what we’ve seen from other Chinese espionage clusters targeting telecom and network infrastructure, and it argues for continuous validation of trust relationships across management infrastructure rather than periodic checks.”

This is a good segue into having me say that you need to check your routers among other things ASAP to make sure that this group, or any other group hasn’t infiltrated your network.

Your AI agent has the password. Does the LLM need it?

Posted in Commentary with tags on August 31, 2026 by itnerd

Here’s a question Ridge Security has been digging into: Can an agent use a secret, like a password or token, without its underlying LLM ever having to see that secret?

Ridge’s answer is yes – but getting there means confronting a real problem with how agents are typically built today.

If a pentest agent’s LLM sees raw secrets, that value doesn’t stay contained to one conversation. It can leak into debug logs, error reports, caches, retries, or saved reports. And once it’s already in the LLM’s context, it’s too late to filter out. It also widens the attack surface, since the value now passes through model infrastructure and becomes a target for prompt injection, where a malicious input could trick the agent into repeating or leaking it.

Ridge’s security team argues the fix isn’t a better filter, it’s a different architecture. They call it a “Security Harness”: the agent gets permission to use a secret without the LLM ever being shown the secret itself. The real credential stays behind a trusted boundary, and the model works with a safe reference it can reason about and use only when an authorized action calls for it. They lay out the thinking, and how it could work, in this recent blog post.

The core idea, as they put it: just because an agent is authorized to use a credential doesn’t mean every part of the system, including the LLM, needs to see it. Sharing it anyway turns a controlled operation into an avoidable risk.

AI’s next act: building faster without compromising trust 

Posted in Commentary with tags on August 31, 2026 by itnerd

Every organization is racing to adopt AI. But in highly regulated industries, the challenge isn’t just moving faster, it’s moving faster while maintaining trust. 

At Sun Life, they’re exploring how AI can help technology architects spend less time searching for information and pulling together governance requirements, and more time applying judgment to the decisions that shape the enterprise. Their AI-powered technology architect agent brings approved standards, prior decisions and institutional knowledge together in one place, helping teams navigate complexity and make more informed decisions. 

The technology architect agent is an example of a broader shift: organizations moving beyond AI as a productivity tool and using it to support the core functions that guide transformation, manage risk and enable innovation. Not to bypass governance, but to make it smarter, faster and more connected to business outcomes. 

You can learn more about Sun Life’s technology architect agent here

Guest Post: Your mobile data usage could reveal if someone is snooping on your phone

Posted in Commentary with tags on August 31, 2026 by itnerd

Our phones contain almost every detail of our daily lives, from private messages and banking apps to photos and location history. But while most people worry about hackers stealing passwords, few know the signs that someone could already be secretly monitoring their device. Arqam Zafar, Marketing Director at AstrillVPN, says most people have no idea how easy it has become for someone else to gain access to their device, and the warning signs are not always what you would expect. Most people assume they would notice if someone was spying on their phone. In reality, the warning signs are often subtle and easily mistaken for an ageing device or a software glitch.

How can I tell if someone is snooping on my phone?

A phone that gets warm while it sits in your pocket, or burns through battery life for no clear reason, is one of the first signs that something has been planted on it. You might also spot alerts that seem entirely out of place, or find the device is sluggish when it powers on or off.

These are the things people tend to dismiss as a glitch or an old battery, but taken together they can point to something running in the background that should not be there.

A sudden spike in mobile data is worth paying attention to as well. Spyware has to send everything it hoovers up back to whoever planted it, and that extra traffic will quietly eat into your data allowance.

Can someone install spyware without physically touching my phone?

Spend a few minutes on Google and you will find no shortage of scammers claiming they can crack open someone’s phone with nothing more than a number, usually for a few hundred pounds paid in crypto. Most of these are scams, but there are genuine threats too.

A well-crafted text message with a suspect link is all it takes in some cases. The more sophisticated tools are designed to run silently in the background and they can be difficult to spot, but you can catch them if you know what to look for.

I think my phone has been compromised. Now what?

Spyware will very often disguise itself, hiding its icon from your home screen entirely, but it might still show up in the full apps list under an innocuous name that you do not recognise.

Have a look through your installed apps and check for anything you did not put there yourself. If something looks odd, search for its name online. Nine times out of ten, you will find other people flagging the exact same app.

For extra peace of mind, you can enlist the help of a reputable mobile security app, which will scan for known threats and flag anything unusual. If all else fails, it’s recommended to do a full factory reset, changing every password you can think of, and switching on two-step verification across the board.

What is the best way to stop it happening in the first place?

It is the boring stuff that saves you, frankly: a decent passcode, a fingerprint or face lock, and a bit of common sense about who picks up your phone when you leave the room.

People leave their phones unlocked on restaurant tables, on desks, in bags, all the time. It takes a couple of minutes, that is all. A VPN is another layer worth adding because it encrypts your traffic, particularly on public Wi-Fi, and makes it far harder for anyone to snoop on what you are doing online.

About the expert:

Arqam Zafar is the marketing director at Astrill VPN, where he leads global marketing initiatives, brand strategy, and partnership development. With over a decade of experience in digital marketing and cybersecurity advocacy, he specializes in helping privacy-conscious businesses scale across borders. At Astrill, Arqam focuses on educating users and organizations on how VPN technology supports internet freedom, data protection, and reliable global access.

Around 8.7 Million travellers’ info stolen at 3 UK airports

Posted in Commentary with tags , on August 29, 2026 by itnerd

Around 8.7 million travellers who signed up for WiFi, car parking services and lounges in airports run by Manchester Airports Group (MAG) had their data stolen, including email addresses and phone numbers, postcodes and vehicle registration details. MAG operates airports in Manchester, London Stansted and East Midlands, and declined the demand to pay ransom.

Denis Calderone, CTO, Suzu Labs:

The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings. No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.

What’s more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That’s a pivot upstream into a data provider, not downstream into operational systems. What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG’s network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.

The UK’s Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology. We don’t know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.

Seemant Sehgal, CEO and Founder, BreachLock:

“This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself. Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.”

This is why I use a VPN when I use public WiFi. In short, public WiFi cannot be trusted. You have to assume the same in order to keep safe.

PaperCut zero-day: “Boring” print servers become domain-wide threats

Posted in Commentary with tags on August 29, 2026 by itnerd

PaperCut’s urgent zero-day advisory is raising concerns well beyond the vulnerability itself, particularly given how many PaperCut servers are exposed to the internet and the potential for unauthenticated SYSTEM-level access. I have SMEs who are weighing in on the real-world exposure, why traditional vulnerability scanning can miss an actively exploited zero-day, and why defenders need to focus on containment, outbound controls and hunting for compromise – not just patching.

John Strand, Owner, Black Hills Information Security https://www.linkedin.com/in/john-strand-a1b4b62

“This is yet another example where the people who most need to see this vulnerability disclosure probably aren’t going to be the people who actually see it. Any sane computer security or IT professional would not have a PaperCut server directly exposed to the internet for anyone to access. But I just ran a quick check, and there are more than 100,000 PaperCut servers exposed directly to the internet right now. That’s the problem. We’re going to end up preaching to the choir until it’s far too late and these servers start getting compromised.”

Jacob Warner, Director of IT, Xcape, Inc. https://www.linkedin.com/in/jacob-warner-n1377

“Boring infrastructure with credential-free remote code execution and self-erasing payloads is how a print server becomes a domain-wide incident. When an unauthenticated request becomes SYSTEM on your print server, the resulting administrative compromise transforms routine utility services into elevated beachheads for lateral movement across enterprise environments. Because the attacker cleans up after themselves, security teams must patch now and assume the logs will not tell them if they were late to respond. Traditional vulnerability scanners often miss active zero-day exploitation until vendor signatures catch up. Defenders should patch or isolate today, close all Internet exposure, and image affected machines before remediation, as the attacker’s cleanup routine may have already deleted the logs that would have confirmed exposure.

“Unauthenticated remote code execution on print management software grants immediate elevated privileges, escalating utility software into a full domain threat. Self-erasing payloads and automated log deletion mean security teams cannot rely solely on post-incident forensic artifacts to detect compromise. Immediate containment requires closing all Internet exposure, imaging affected application servers prior to remediation, and applying vendor patches immediately.

“Boring utility servers make the best targets because nobody expects the print spooler to hand over domain administrator rights.”

Seemant Sehgal, Founder & CEO, BreachLock https://www.linkedin.com/in/s-sehgal

“Pre-authentication RCE means the attacker needs nothing from you. No credentials, no foothold, no prior access, before they own the application and can run arbitrary Java on your infrastructure. The first question every team should be answering right now is whether their PaperCut instance is reachable from the internet, because if it is, that answer is more urgent than any patch timeline. Vulnerability scanners will tell you the CVE exists, but they will not tell you whether an attacker already walked through it and what the impact would be if they did.”

Denis Calderon, Principal & CTO, Suzu Labs https://www.linkedin.com/in/deniscalderone

“PaperCut’s Application Server runs as SYSTEM on Windows, manages configurations for every endpoint in the org, and has a web-accessible console that is often exposed to the Internet. It’s “just printing”, but in this case, its important to treat it like any other management plane that holds implicit trust within your network.

“I ran a Shodan query this morning and found over 1,000 of these servers exposed to the public internet on their default management ports. A lot of them look like schools. That makes sense. PaperCut is heavily deployed in education for managing student print quotas, and students need to access the system from their own devices, so the web interface ends up internet-facing almost by necessity. The first confirmed victim to report this exploitation to PaperCut was a university. These servers are findable in seconds, they require zero credentials to exploit, and the attacker gets SYSTEM-level code execution. Unfortunately, even a well managed vulnerability scanning program wouldn’t have flagged this since it was an 0day, and you can’t see vulnerabilities that haven’t been discovered yet. That’s the fundamental limitation. The exposure itself was the risk, long before anyone knew the specific flaw.

“So, needless to say, get the PaperCut Emergency Patch Release 2 implemented immediately.  It covers v24, v25, and v26. I wish I could advise a holistic architectural fix like removing the admin interface off the internet, but it’s unclear from the current reporting whether that alone would have stopped this. The auth bypass operates below the URL routing layer, so even user-facing endpoints may have been sufficient for the attacker to reach the vulnerable components. What is clear is that a restrictive egress policy would have stopped this. Huntress’s proven exploit chain required SMB to traverse outbound from the victim to an attacker-controlled share. That can and should be controlled and stopped at the perimeter. If your PaperCut server can initiate outbound SMB to the internet, fix that today. And then hunt. Keep in mind that this malware deletes server.log, derby.log, and its own class files after execution. If your server was internet-exposed yesterday, patch or no patch, you need to be hunting today. Preserve those logs before you restart anything, look for the indicators Huntress published, and assume compromise until you can prove otherwise.”

If you use PaperCut, consider this a today problem. Patch now and keep watching this advisory as I am sure that this is not the last that we’ve heard of this issue.

OpenAI, Microsoft and 100+ firms warn of AI hackers on cyber attacks

Posted in Commentary with tags on August 29, 2026 by itnerd

More than 100 companies came together to make an open plea for collective action on cyber defense against AI-enabled cyber attacks. Signed by organizations including Accenture, Capital One, Anthropic, CloudFlare, Deutsche Telekom, Fifth Third Bank, General Motors, Microsoft, Red Hat, SAP, TransUnion and Zurich Insurance, the letter says these attacks “will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet—are at risk.”

John Strand, Owner, Black Hills Information Security:

“I think the sentiment behind what they’re doing here is fine, but I don’t think it moves the needle in any discernible way. A lot of this is motherhood and apple pie. They’re essentially telling organizations to spend more money on defensive security, which happens to directly support the marketing initiatives of many of the companies signing onto this. At a certain point, it starts to feel like infosec marketing theater.

“The one recommendation that actually has some teeth to it is the call for greater open exchange of detects and IOCs. But I would have liked to see these companies go much further. Many of them make billions of dollars from the security community. Why not create open initiatives where organizations can access threat intelligence feeds for free? Why not provide some of these security services at no cost to municipalities and other organizations that simply cannot afford them?

“Some companies already do this, and they deserve credit for it. But if the industry is going to collectively call for organizations to improve their security, it also needs to recognize the reality on the ground. A huge number of these organizations are understaffed, underfunded, and under attack. Many of the companies signing these initiatives have the resources and expertise to directly help them.

“Calling for better security is easy. Actually helping the organizations that can’t afford it would mean a hell of a lot more.”

Seemant Sehgal, CEO and Founder, BreachLock:

“There’s real value in this coalition, but there’s also a conflict of interest here. The companies asking governments to fund AI defensive tools are the same ones that would get paid to supply them, and some of them build the frontier models making the offensive side harder. That doesn’t make the warning wrong, but the recommended response isn’t neutral. The real question is whether hospitals, water utilities, and local governments get unrestricted funding to spend on what they actually need, or subsidized access to specific vendor products. Those are very different outcomes.”

Ryan McCurdy, VP, Liquibase (): 


“The warning is right, but using AI to defend against AI isn’t enough.

“AI is accelerating both sides of the equation: attackers can find weaknesses and execute attacks faster, while developers and AI agents are creating legitimate software and database changes faster than ever. Security teams have now got to determine whether a change is authorized, safe, and expected, and do it at a speed that humans simply can’t keep up with.

“That’s why governance has to move closer to the change itself. Organizations need to know what changed, whether it was authorized, and whether it meets policy before it reaches a critical system and data. And when something does get through, teams need the visibility to understand what happened, what’s impacted and how to recover quickly.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

More than 100 technology and cybersecurity companies signed an open letter this week, organized by OpenAI, calling for a “defenders’ window” to strengthen cyber defenses against increasingly capable AI-enabled attacks. The letter asks governments to fund cybersecurity improvements for hospitals, water utilities, and other critical infrastructure, while frontier AI developers provide model access, funding, training, and hands-on support. However, some of its most prominent signatories are also helping shorten that window.

OpenAI published this initiative weeks after its own models escaped intended isolation during a capability evaluation and compromised Hugging Face’s production infrastructure. Anthropic, Google, and Microsoft are co-signatories while simultaneously advancing frontier-model capabilities that expand what attackers can automate. The same capability race creating the urgency behind this letter is steadily compressing the window it asks defenders to use.

This is also part of a broader push this summer to put AI-powered cyber defense into critical infrastructure. In July, the UK’s National Cyber Security Centre outlined Cyber Shield, including autonomous vulnerability discovery and eventually fully automated vulnerability mitigation. That’s happening against a baseline where the UK’s National Audit Office found that departments lacked fully funded remediation plans for roughly half of their vulnerable legacy systems. The White House’s Gold Eagle initiative similarly proposes using frontier AI to accelerate vulnerability discovery and remediation across government and critical infrastructure.

Then Minnesota demonstrated what the actual bottleneck looks like. More than thirty community water systems were targeted in a coordinated cyberattack in late July. Federal authorities subsequently warned about attacks targeting internet-facing Rockwell Automation programmable logic controllers. In Braham, a community of roughly 1,700 people, compromised operating controls took the city’s well and water-treatment plant offline until operators restored service.

None of that required frontier AI.

Critical-infrastructure operators are struggling to inventory what’s connected to the internet, eliminate insecure remote access, hire dedicated security staff, and remediate vulnerabilities they already know about. Offering increasingly sophisticated AI defensive capabilities without fixing those fundamentals is like giving someone a Tesla when what they need is a road.

The letter acknowledges that these organizations need funding and hands-on support. But it contains no funding amounts, delivery deadlines, or firm financial commitments from its more than 100 signatories. If the companies warning that the defenders’ window is closing want to materially extend it, the commitment needs a dollar figure and a delivery date, not another page of corporate logos.

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

There is a little bit of “industry identifies an emergency; government buys industry’s solution” in this proposal. If the companies signing this letter believe that AI creates an urgent new systemic risk, I would expect them to put substantial skin in the game rather than simply asking taxpayers to fund another generation of security products: including through private partnerships for collective defense.

Before we spend public money putting AI on top of insecure infrastructure, I want to know that we have paid for the basics: remove PLCs from the public internet, secure remote access, segment networks, maintain backups, and make sure somebody actually owns the security of the system.

AI makes attacks faster and cheaper, but it does not repeal the fundamentals of cybersecurity. We should not use a new technology problem as an excuse to avoid fixing old, well-understood weaknesses.

Given this, now is a good time to look at the use of AI in your organization given that AI can’t be entirely trusted.

ServiceNow’s CVSS 10.0 trio shows how one platform patch cycle becomes everyone’s third-party risk problem

Posted in Commentary with tags on August 29, 2026 by itnerd

Four flaws hand just been disclosed in ServiceNow’s AI Platform, three of them scored a maximum CVSS 10.0: a code injection bug in the GraphQL Composite Data API (CVE-2026-18885), a privilege escalation flaw in the system configuration image upload processor (CVE-2026-18886), and a SQL injection through a dynamic schema ORDER BY clause (CVE-2026-74820), plus a lower-severity sandbox escape in the Now Platform (CVE-2026-6876, CVSS 8.7). ServiceNow patched its own hosted instances on August 27, but self-hosted customers must apply the fix themselves, leaving the responsibility for closing three maximum-severity holes with the customer rather than the vendor.

Jason Brown, Director of Counter Fraud Operations, iCOUNTER had this to say:

“Three maximum severity bugs in one disclosure is a lot, but the detail I’d focus on is the split between hosted and self hosted customers. ServiceNow’s hosted instances were already updated as part of the August 27 advisory. Everyone running ServiceNow on their own infrastructure now has to go find, schedule, and apply that patch themselves, and in a lot of organizations that process takes weeks, not days. During those weeks, an unauthenticated attacker with a working exploit for the GraphQL Composite Data API code injection bug or the SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals. I spent years chasing fraud operators who specifically target that lag between disclosure and patch adoption, because they know it’s where the easy access is. My advice to any security team running ServiceNow self hosted right now is simple: don’t wait for your normal patch cycle, treat this one as urgent and confirm it’s applied this week.”

Needless to say, if you use ServiceNow, it’s time to patch all the things. And maybe at the same time take a look at how ServiceNow is used in your organization.