Samsung Officially Launches Galaxy Z Fold8 Ultra, Fold8, Flip8, Watch Ultra2 and Watch9

Posted in Commentary with tags on August 7, 2026 by itnerd

Samsung Electronics today announced that the new Galaxy Z series and Galaxy Watch lineup are beginning to roll out worldwide. Galaxy Z Fold8 Ultra, Fold8, Flip8, Watch Ultra2 and Watch9 are available through carriers, retailers, Samsung.com and Samsung Experience Stores, with sales beginning August 7 in select markets and expanding globally.

Strong early demand reflects growing excitement for Samsung’s latest Galaxy Z series, with pre-orders for the new lineup having increased by more than 30% compared with the previous generation. Graphite was the most popular colour overall for Galaxy Z Fold8 Ultra and Galaxy Z Fold8, while Pink led pre-orders for Galaxy Z Flip8. Among Samsung.com pre-order customers aged 15 to 34, exclusive colours Green Shadow, Pistachio and Mint emerged as the top choices for Galaxy Z Fold8 Ultra, Fold8 and Flip8, respectively.

The New Galaxy Z Series: Three Distinct Foldable Experiences

Built on seven generations of foldable innovation and consumer insight, the new Galaxy Z series gives users more choice than ever, with three distinct experiences engineered to fit different needs.

Galaxy Z Fold8 introduces a fresh form factor built around the way people explore, discover and immerse themselves in their favourite content. Its display ratios are designed to move naturally with users throughout the day – from quick interactions like messaging, browsing and short-form video on the wider cover screen to more immersive viewing, reading and gaming on the 4:3 main display. With Gemini Notebook, users can bring together notes, images, recordings, files and documents in one workspace to collect, organize and develop their ideas. At just 201 g, it is Samsung’s lightest Galaxy Z Fold yet, while Samsung’s new Flex Titanium technology helps support a slimmer display structure with impressive strength and reduced crease visibility over time.

Galaxy Z Fold8 Ultra brings Galaxy’s renowned Ultra standard to foldables, combining a larger workspace with an upgraded camera system and performance built for demanding creative workflows. Its expansive 8-inch main display opens up more room for multitasking, while Now Nudge helps users move from conversation to action by suggesting relevant next steps across supported apps.

The 200 MP main camera now supports High Dynamic Range (HDR) in 200 MP mode for richer detail, colour and clarity. A new 50 MP ultra-wide camera adds greater flexibility for wider scenes and macro shots, helping users capture more from one device. Across Galaxy Z Fold8 Ultra, Galaxy Z Fold8 and Galaxy Z Flip8, Dual Recording captures both the action and the user’s reaction, while My FanCam automatically tracks and reframes a selected subject.

Galaxy Z Fold8 Ultra also features a 5,000 mAh battery, 45 W Super Fast Charging and an expanded graphite cooling structure – all in Galaxy’s slimmest Z Fold design yet, measuring just 4.1 mm when unfolded and weighing 215 g.

Galaxy Z Flip8, Samsung’s sleekest Flip ever released, is built for expression and quick interaction on the go. Its reimagined FlexWindow brings apps, insights, actions and assistance directly to the cover screen. Now Brief surfaces personalized information based on users’ schedules, routines and interests. Users can also access Gemini from the FlexWindow through side-key activation or natural voice requests, making it easier to complete connected actions on the go. Galaxy Z Flip8 further enhances Samsung’s signature Flip camera experience with a 50 MP camera, ProVisual Engine and FlexCam experiences that make it easier to capture, preview and share polished photos and videos from flexible angles.

Galaxy Watch Ultra2 and Galaxy Watch9: Effortless Health Management From the Wrist

Galaxy Watch Ultra2 and Galaxy Watch9 extend the Galaxy experience to the wrist, helping users turn daily health data into more meaningful, actionable guidance through effortless everyday wear. Both devices are powered by the Snapdragon Wear® Elite Platform and are designed to support continuous health tracking with improved performance, comfort and battery life.

Galaxy Watch Ultra2 is built for outdoor adventures and high-performance users who need long-lasting endurance, reliability and precise tracking. Available in a 47 mm size, it features an 800 mAh battery, a display with up to 5,000 nits of brightness, shock-resistant titanium casing and dedicated tracking modes for outdoor sports, including Trail Run. It is also rated IP69K and 10 ATM and certified to EN 13319.

Galaxy Watch9 is designed as an everyday health companion for wellness-conscious users who want to build healthier habits through continuous activity and sleep tracking. Available in 40 mm and 44 mm sizes, Galaxy Watch9 features a lightweight aluminum casing, a comfortable design for 24/7 wear, a display with up to 3,000 nits of brightness and health features such as Vitals, Heart Health Score, Daily Cardio Load, Fitness Index and Hearing.

Together with the new Galaxy Z series, Galaxy Watch Ultra2 and Galaxy Watch9 expand Samsung’s AI ecosystem, bringing connected companion experiences across phone and wrist.

Availability

Starting August 7, Galaxy Z Fold8 Ultra, Fold8 and Flip8 will be available through carriers, retailers, Samsung.com and Samsung Experience Stores in 106 markets worldwide.

Customers who purchase a new Galaxy Z 8 series device will receive a six-month trial of Google AI Pro, including 5 TB of cloud storage, valued at $161.94. With expanded access to Google’s AI models, users can enhance productivity and creativity on their foldable devices.

Switching to Galaxy is now easier than ever, thanks to a more seamless migration experience across a wider range of devices. With the updated Smart Switch, iOS users can scan a QR code on their current device and wirelessly transfer data without downloading an additional app. Smart Switch can also transfer more types of data, including passwords and passkeys, call history, accessibility settings and eSIM information, helping reduce the time needed to set up a new device. With new compatibility between Quick Share and AirDrop, users can also share files seamlessly between iOS and Galaxy devices in both directions.

Galaxy Watch Ultra2 and Galaxy Watch9 will also be available through carriers, retailers, Samsung.com and Samsung Experience Stores in 106 markets worldwide starting August 7.

Galaxy Z Fold8 Ultra, Fold8, and Flip8 are available in a range of colours, including Violet Shadow, Lavender and Pink, respectively — with additional options available exclusively on Samsung.com. Galaxy Watch Ultra2 is available in 47 mm, while Watch9 is offered in 40 mm and 44 mm. Colour, size, connectivity option, model and availability may vary by market, carrier, or retailer.

Customers who purchase a Galaxy Watch Ultra2 or Galaxy Watch9 can access exclusive subscription trial benefits, including a 60-day Strava trial valued at $29.98 and a two-month iFIT trial valued at $19.98. Together, these benefits help users track workouts from the wrist and extend their fitness experiences through partner apps. Terms, eligibility and availability may vary by market.

To give users peace of mind after upgrading, Samsung Care+ offers comprehensive protection with fast repairs for accidental damage, extended warranty coverage and certified expert support at home and abroad. With One UI 9, the new Warranty and care section in Settings also gives users a clear view of their enrollment status, coverage details

Kyndryl introduces new agentic modernization services-as-software scaled through Kyndryl Bridge

Posted in Commentary with tags on August 6, 2026 by itnerd

Kyndryl today introduced its Agentic Modernization services-as-software, which is built using the Kyndryl Agentic AI Framework and is scaled through Kyndryl Bridge. Services-as-software is an emerging model for delivering services through software-driven automation, intelligence and scalable digital workflows.

Kyndryl has codified its trusted mission-critical and engineering expertise, together with capabilities from AI ecosystem partners, into pre-defined agentic workflows that help customers unlock business outcomes, de-risk and accelerate their modernization objectives, while maintaining enterprise guardrails and cost visibility throughout their AI adoption journey.

The announcement comes as organizations race to scale AI but are challenged to achieve business value from their investments. Kyndryl’s recent survey of 1,100 business and technology leaders found that while 77% of executives say generative AI has already been scaled across multiple functions of their organization, only 32% report experiencing one of their top desired outcomes. Organizations cannot reliably adopt AI on aging technology estates; modernization is the prerequisite foundation and has become a top priority and a growing area of technology spend. 

Run on the Foundation of Kyndryl Bridge 

Since its launch in 2022, Kyndryl Bridge has become the trusted foundation for managing and modernizing mission-critical and regulated technology environments for more than 1,400 customers. Kyndryl Bridge generates more than 16 million AI insights each month and has demonstrated a reduction in IT incidents by up to 50%.

As organizations adopt AI-powered workflows, Kyndryl Bridge serves as the robust enterprise-grade technology foundation, for deploying and managing mission-critical AI across hybrid IT estates, with well-established controls for cost visibility, security and regulatory requirements. Kyndryl Bridge also provides agentic memory management for customers, helping them preserve and evolve critical institutional knowledge and operational context to support continuous modernization.

Scaling modernization outcomes with services-as-software

Kyndryl’s services-as-software helps customers execute modernization programs of any size or complexity in radically compressed timelines and at significantly lower cost by scaling pre-built agentic workflows — making specialized skills less of a constraint. 

This approach also enables customers to adopt new frontier models and tools as they become available, based on their business requirements, cost, performance and governance needs, without locking them into a specific technology stack. As a result, modernization programs can be delivered with greater consistency, repeatability, quality and predictable outcomes for every customer.

Expert-guided, agent-orchestrated continuous modernization  

Anchored in Kyndryl’s decades of experience managing and modernizing mission-critical systems, pre-defined enterprise-grade agentic modernization workflows support a broad range of infrastructure, application and business transformation initiatives across distributed and mainframe environments, public, private cloud and network infrastructure, software development and IT operations. These AI workflows orchestrate autonomous AI agents across the modernization lifecycle, helping accelerate activities such as discovery, code analysis, dependency mapping, target-state design, code generation, testing and validation. 

Kyndryl’s pre-defined agentic modernization workflows also reduce the effort and costs required to experiment with AI and accelerate modernization by giving customers a proven, reusable foundation for generating consistent, high-quality outcomes at scale.

Kyndryl experts and customer teams remain central to the process, providing human oversight, governance and accountability. With Kyndryl’s Agentic Modernization services-as-software, organizations can transform legacy environments faster and more consistently, into modern, AI-ready environments with greater speed and confidence.

Customers are already seeing results:  

  • A global car rental company is transforming its software development lifecycle with Kyndryl AI agents, autonomously refactoring legacy code and reducing hours of manual effort to minutes while improving code quality, consistency and maintainability.
  • At a global reinsurer, the starting point was a decades-old mainframe environment with millions of lines of code and a shrinking pool of in-house expertise. Kyndryl Agentic Modernization services-as-software helped analyze and reimagine the legacy estate, accelerating the transition to a cloud-native architecture and enabling data center exit timelines to be reduced by 50%.
  • A global financial services organization has deployed Kyndryl Agentic Modernization services-as-software across its engineering teams worldwide to accelerate modernization using AI-powered operational insights and pre-defined agentic workflows. 

Learn more about Kyndryl’s Agentic Modernization services-as-software.

Zero-click browser hijacks show AI agents need identity governance, not just patches

Posted in Commentary with tags on August 6, 2026 by itnerd

Zenity’s new research on Claude in Chrome and ChatGPT Atlas shows how a single malicious email or X comment can hijack an AI agent across every authenticated session it holds, from Gmail to Slack to Amazon, without the user clicking anything. Both Anthropic and OpenAI were notified months ago, and one issue was closed as merely “informative.” That response gap is the real story: this is being treated as a product bug when it’s actually an unmanaged identity problem.

The AI Governance Institute has a good write up about it here: Unpatched Zero-Click Prompt Injection Hits ChatGPT Atlas and Claude Browser Agents | AI Governance Institute

Justin Beals, CEO & Founder of Strike Graph, an AI-native GRC and compliance automation platform writes:

“This research confirms what a lot of security teams suspected but couldn’t prove: agentic browsers don’t just introduce new bugs, they collapse the boundaries that most of our controls depend on. Same-origin policy has been a foundational assumption in web security for decades. An agent that spans every authenticated tab a user has open erases that assumption by design, not by accident.

What’s missing from the response so far is the governance question, not just the technical one. Zenity reported these issues to Anthropic and OpenAI months ago, and one was closed as ‘informative.’ That tells you the industry still treats this as a product defect to patch rather than a new identity category to govern. An AI agent acting inside a user’s live session, across Gmail, Slack, Amazon, and X, is not a feature bug. It’s an unmanaged identity with standing access to everything that user can touch.

Organizations deploying agentic browsers need to treat them the way they’d treat any privileged third-party integration: continuous monitoring of what the agent does under that identity, tight scoping of what sessions it can touch, and evidence, not vendor assurance, that those controls actually hold. Until agent activity gets pulled into identity governance the same way a contractor’s access would be, this pattern will keep repeating with a different agent and a different headline.”

This is yet another area that requires your attention as AI related threats can come from anywhere and anything quite literally.

Cyberattack disrupts operations at North Carolina Ports

Posted in Commentary with tags on August 6, 2026 by itnerd

North Carolina Ports is recovering from a cyberattack that disrupted operations at the Port of Wilmington, Port of Morehead City and the Charlotte Inland Port.

The organization said it detected the attack on August 4 and immediately activated its Cybersecurity Contingency Plan to contain the incident. As a result, gates at all three facilities opened late on August 5, and officials warned customers and truck drivers to expect operational delays.

North Carolina Ports said the breach has been contained and recovery efforts are underway with support from the North Carolina Department of Transportation, the North Carolina Department of Information Technology and the U.S. Coast Guard.

Denis Calderone, CTO, Suzu Labs:

“We’ve been tracking port cyberattacks over the last few years. Nagoya went down for two days in July 2023. DP World stranded 30,000 containers in Australia for three days in November 2023. The Port of Seattle lost administrative systems for weeks after an attack in August 2024. It’s good to see in this case that NC Ports’ incident preparedness seems to have paid off. They activated their contingency plan the very same night of the attack and were processing manually by the next morning.

“That said, the attack itself is the signal every port operator in the country should be paying attention to. This is the fourth significant port cyberattack globally in three years. Port terminal operating systems, automated gate processing, crane control networks, these are all systems that have been rapidly digitized over the last decade, and attackers have clearly noticed. NC Ports handles 4.4 million tons of cargo annually and supports nearly 90,000 jobs across the state. A longer outage at a facility like that doesn’t just delay trucks, it backs up supply chains across the Southeast and beyond.

“The Coast Guard’s maritime cybersecurity rule went into effect in July 2025, and what we’re seeing in NC Ports’ response maps directly to what that regulation is trying to produce: a designated cybersecurity contingency plan, rapid detection, coordinated response with federal partners. The problem is that most MTSA-regulated port facilities don’t have to submit their full Cybersecurity Plans until July 2027. We’re in the gap period right now, and attacks are not waiting for compliance deadlines.

“For any port operator watching this: the playbook hasn’t changed but the urgency has. Segment your OT networks from your IT environment. Make sure your terminal operating system can’t be reached from the same network segment as your email. Test your manual gate processing procedures with actual crews, not just on paper. Inventory every communication path into your control systems, including the cellular links and the vendor remote access channels. And don’t wait for the 2027 Cybersecurity Plan deadline to do the work. NC Ports has been investing in this kind of preparedness for years and it paid off this week. If your port can’t replicate that response tomorrow, you’re already behind.”

This is going to be more of a thing given the state of play. By that I mean Iran or other cyber threats as it is a safe assupmtion that if you are not under attack now, you will be.

Major Wall Street firms targeted in wave of cyberattack attempts 

Posted in Commentary with tags on August 6, 2026 by itnerd

Hackers have launched a series of sophisticated cyberattack attempts targeting major Wall Street financial firms, including Point72 Asset Management, Citadel, Millennium Management and Two Sigma Investments with attackers attempting to gain access to internal information systems through voice phishing (vishing) and other social engineering techniques, according to Bloomberg.

Point72 notified investors that it was investigating the incident but said there were no initial indications that client information had been compromised.

   “Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,” a Two Sigma spokesperson said in a statement.

The Financial Industry Regulatory Authority (FINRA) has contacted member firms regarding the recent attempted cyberattacks. Earlier this year, FINRA launched its Financial Intelligence Fusion Center, a secure platform for sharing cyber threat intelligence and coordinating responses to increasingly sophisticated cyber and fraud threats targeting financial services firms.

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

“These attacks demonstrate that social engineering remains one of the most effective ways to bypass technical security controls. As attackers increasingly leverage AI and publicly available information to make vishing campaigns more convincing, organizations must strengthen identity verification processes and ensure employees are trained to verify requests rather than simply trust a familiar voice. The firms’ rapid detection also shows why layered defenses and intelligence sharing are critical for stopping these campaigns before they become breaches.”

Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:

“Modern phishing campaigns often start with publicly available information and can be combined with previous data exposures to build a targeted profile on potential victims. AI can analyze massive amounts of data quickly to build profiles that would take a skilled human days or weeks. AI has lowered the barrier for cybercrime. What once required years of experience can now be done with very little effort or technical knowledge. Humans are the weakest link in both data incidents and social engineering and as voice impersonation become more convincing, we will reach a point where we cannot trust what we hear or what we see.

   “Cybersecurity is no longer only about protecting networks and endpoints. It’s increasingly about protecting decision making and the primary defense starts with education and changing the culture of data protection. AI powered social engineering is designed to manipulate human judgment, and organizations must recognize that their workforce is now a primary attack surface. When the goal of cyber criminals if financial gain it is only logical that investment firms that manage sensitive financial information are attractive targets.”

You have to assume that you’re a target. Thus you need your defences are set up to repel that threat. Otherwise, you need to assume that you are going to get pwned. It is that simple.

Guest Post: Why are hackers suddenly obsessed with America’s water systems?

Posted in Commentary with tags on August 6, 2026 by itnerd

By Stefanie Schappert

Cyberattacks on water and wastewater systems have surfaced across at least 12 US states since July 26th.

The FBI and CISA are increasingly pointing to the CyberAv3ngers, an Iranian-linked threat group backed by the Islamic Revolutionary Guard Corps (IRGC).

And while fresh attacks are being reported daily by local municipalities across the country, the bigger question isn’t where or when the next strike takes place – it’s why America’s water infrastructure has become such an attractive target in the first place.

Water is the perfect target

Water occupies a unique place in America’s critical infrastructure. Every community depends on it, and unlike many other public services, there is no alternative if the systems providing it are compromised. 

And creating uncertainty around an essential public service can be just as valuable as causing the disruption itself. 

Attackers don’t have to poison a water supply or leave an entire city without service to achieve an effect. They just have to make people wonder:

  • Is my drinking water safe?
  • Could someone shut off my town’s water?
  • How vulnerable is the infrastructure I rely on every day?

Even an unsuccessful attempt at disruption can shake public trust – and with headlines that stretch across the internet, the psychological effect can reverberate across an entire nation.

Built to be breached 

Over 50,000 drinking water and wastewater systems operate across the US, many serving small communities with limited cybersecurity resources and insecure technology. 

Many facilities still rely on internet-connected industrial control systems for remote management, creating a large and diverse attack surface.

CyberAv3ngers have found the perfect weakness in these systems: unpatchable PLC devices.

The programmable logic controller (PLC) is essentially an internet-facing computer used to automate facility operations, serving as one of the main components of SCADA systems across critical infrastructure. 

CyberAv3ngers – at first just a hacktivist group – began zeroing in on Unitronics PLC devices back in 2023, simply because its software was made in Israel.

By 2025, CyberAv3ngers had expanded to target the more commonly used Rockwell Automation PLCs, exploiting an authorization bypass vulnerability that can never be patched. 

Defenders have little recourse, while the FBI warns operators to proactively rely on defense-in-depth security measures in the absence of a permanent fix.

The water playbook evolves 

CyberAv3ngers first gained attention by defacing Israeli-made PLCs with pro-Iran messages before evolving into an IRGC-linked threat actor that developed its own strain of industrial malware, IOControl.

According to researchers, that malware has now been disseminated to at least 60 Iran-affiliated hacking groups, making threats against our water supply far less predictable. 

Instead of tracking one actor’s tactics, techniques, and procedures (TTPs), system defenders may be facing dozens of groups capable of utilizing the same underlying toolkit to modify and deploy new iterations of the malware. 

And that can leave security teams in the dark about what to look out for and how to harden systems against any one threat.   

Researchers have also documented the group’s recent use of AI tools – specifically ChatGPT – for code debugging and research, suggesting that CyberAv3ngers and its targeted malware could become even more sophisticated and stealthy as they continue to evolve. 

ABOUT THE EXPERT

Stefanie Schappert, a senior journalist at Cybernews, is an accomplished writer with an M.S. in cybersecurity, immersed in the security world since 2019.  She has a decade-plus experience in America’s #1 news market working for Fox News, Gannett, Blaze Media, Verizon Fios1, and NY1 News.  With a strong focus on national security, data breaches, trending threats, hacker groups, global issues, and women in tech, she is also a commentator for live panels, podcasts, radio, and TV. Earned the ISC2 Certified in Cybersecurity (CC) certification as part of the initial CC pilot program, participated in numerous Capture-the-Flag (CTF) competitions, and took 3rd place in Temple University’s International Social Engineering Pen Testing Competition, sponsored by Google.  Member of Women’s Society of Cyberjutsu (WSC), Upsilon Pi Epsilon (UPE) International Honor Society for Computing and Information Disciplines.

Lumma Stealer Campaign Tied to The Odyssey Piracy Downloads to Deliver Malware

Posted in Commentary with tags on August 6, 2026 by itnerd

Bitdefender has published research detailing an active campaign that leverages the popularity of The Odyssey to target those searching for pirated copies and distribute Lumma Stealer malware in the process.

Key findings include:

  • Malicious .exe files are disguised as 1080p and Blu-ray movie downloads, with icons spoofed to look like VLC Media Player. Since Windows hides file extensions by default, victims can’t easily tell it’s a program and not a video.
  • Once executed, Lumma Stealer harvests browser passwords, authentication cookies, saved payment data, and cryptocurrency wallets, and can hijack active sessions even when multi-factor authentication is enabled.
  • The campaign is nearly identical to a 2025 operation that abused Mission: Impossible – The Final Reckoning torrents, showing attackers simply recycle the playbook around whatever film is dominating search traffic.

You can read all the details here: https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer.

NVIDIA-led alliance proposes AI cybersecurity incident reporting framework

Posted in Commentary with tags on August 5, 2026 by itnerd

NVIDIA and the Open Secure AI Alliance have proposed a new industry framework called Shared AI Findings Exchange (SAFE) to standardize how organizations report and share AI-related cybersecurity incidents.

Published through the Linux Foundation as a Request for Comments, the guidelines are intended to help organizations share information on AI attacks, vulnerabilities and near misses to improve collective cyber defenses.

The alliance also announced new open-source contributions, including AI security models, datasets, evaluation tools and research designed to improve the security of AI systems and agents.

NVIDIA said the Open Secure AI Alliance has grown to more than 120 member organizations, including technology companies, cybersecurity firms and open-source foundations collaborating to develop shared AI security tools and best practices.


Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity,
 Suzu Labs had this to say:

“SAFE is required because AI agent failures don’t fit existing vulnerability disclosure. When a model finds and uses access it shouldn’t have reached, there’s no patch to issue and no vulnerability identifier to publish. Agent failures are often behavioral and non-deterministic, with no signature to match and no fix to deploy.

“Aviation’s safety reporting system has been running since 1976, the financial sector’s threat-sharing body since 1999. Both protect reporters from liability and operate at industry speed. AI threats outpace government coordination, making private-sector self-organization the right model.

“Identity is the piece that makes the rest of the defensive stack enforceable. The alliance’s work on agent identity and access controls lets organizations verify what an agent is before it acts. SAFE adds information sharing on top of that identity and runtime layer. Together, organizations learn from each other’s agent failures fast enough to defend proactively.

“The highest value will come from near-misses. Breaches make headlines, but an agent that probes a boundary and fails never gets published. That behavioral pattern is exactly the intelligence other organizations running similar systems need, and SAFE creates the channel for sharing what would otherwise stay invisible.”

Jeremiah Fowler, Researcher for Black Hills Information Security, Inc. follows with this:

“I believe this is a positive step in the right direction. Organizations that experience AI related attacks gain valuable insights that could help protect others but only if that information is shared. Establishing a framework for responsible information sharing promotes transparency, peer review, and independently evaluated security findings. The more organizations that contribute real-world evidence, the more effectively we can identify emerging attack patterns, common vulnerabilities, and evolving threats while reducing duplicated defensive efforts that waste valuable time and resources.

“As AI becomes increasingly integrated into everyday life, business operations, and critical infrastructure, developing standardized security guidance now is a proactive investment rather than waiting to retrofit a defense after incidents occur. Sharing information about unsuccessful attacks is just as valuable as documenting confirmed compromises, because near misses can often expose weaknesses, configuration issues, or emerging attack tactics before they evolve into critical security incidents. I used to always say “it is not if you will have a data incident, it is when you will have a data incident”.  AI has supercharged the threat landscape in ways we couldn’t have imagined just a few years ago. Reporting and sharing AI related cybersecurity incidents is a great first step. I am happy to see organizations take the initiative instead of waiting around for regulators or lawmakers.”

Standards are good. But I will have to see this in action to get an idea of how well this works. Because there’s nothing worse than a standard that nobody uses.

The White House Has Lots Of AI Related News For You

Posted in Commentary with tags on August 5, 2026 by itnerd

The White House has finalized its voluntary cybersecurity framework for frontier AI models, giving leading AI developers a process to submit advanced models for government security evaluations before public release. The framework is intended to address the growing cybersecurity risks posed by increasingly capable AI systems (after recent testing incidents involving frontier models).

Zach Wasserman, co-founder, Fleet Device Management (and one of the creators of OSquery) had this to say:

“The White House is focused on whether frontier AI models are safe. Enterprises must consider whether AI can safely operate inside their own environments. A model can perform well in testing but still create risk if it’s connected to production systems without the right controls. Before AI is managing thousands of endpoints, organizations need an operating model where every change is version controlled, auditable and easy to roll back.

The takeaway from the recent OpenAI and Anthropic testing incidents is that autonomous systems need guardrails. We’ve spent years building software development processes around code review, version control and rollback. AI making infrastructure changes should follow the same principles. Infrastructure as code gives AI a safe, structured way to make changes while keeping people in control.

Our recent research found that almost half of organizations are prioritizing AI automation, but fewer than a third are prioritizing infrastructure as code. That’s a problem because AI is only as safe as the systems it’s allowed to change. AI also shortens the time between finding a vulnerability and acting on it, whether that’s patching it or exploiting it. Organizations relying on manual processes simply won’t keep up.”

Also with The White Houre, they have told AI developers it will not include open-weight AI models in its new voluntary cybersecurity testing program, according to Reuters.

The policy was discussed during a White House meeting with representatives from Meta, Google, Nvidia, OpenAI and Anthropic, according to sources familiar with the discussions. Open-weight models, such as Meta’s Llama and Nvidia’s Nemotron, make their core model weights publicly available, unlike closed models from OpenAI and Anthropic.

The voluntary testing program is intended for advanced AI models with sophisticated cyber capabilities and follows recent disclosures that AI systems from OpenAI and Anthropic breached other organizations during controlled security evaluations.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“The US government already knows how to test open-weight models for cyber capability. Before Moonshot released Kimi K3’s weights on July 27, AISI and NIST ran a joint evaluation of its offensive capabilities, measuring exploit development, code execution, and network intrusion performance. That methodology works. The White House chose not to apply it.

“Publicly disclosed incidents that prompted this framework all involved closed-model companies. OpenAI’s models exploited Artifactory vulnerabilities to escape a test environment, then compromised Hugging Face through a separate attack path. Claude models gained unauthorized access to three companies during security evaluations. Under these guidelines, Meta and Nvidia walked out of the August 4 briefing with zero obligations while OpenAI and Anthropic accepted a voluntary pre-release review of up to 30 days.

“Kimi K3 trails US frontier models on cyber tasks today, but in a simulated enterprise attack it completed a full intrusion chain in one of ten attempts, against an intentionally vulnerable network, with initial access provided. China has made open-weight release a strategic priority, and each generation closes ground on the previous one. A framework that categorically exempts open weights has no mechanism to adapt when that gap narrows.”

I would give everything a read because if you use AI related anything, you are affected.

July Ransomware Attacks: Up 19% from June Says Comparitech

Posted in Commentary with tags on August 5, 2026 by itnerd

With ransomware attacks plaguing businesses and individuals around the world, Comparitech have released their Ransomware Roundup for July 2026, finding that last month saw nearly 26 ransomware attacks per day. 

The research looks into attacks by sector, most prolific groups and attacks by country.

Key findings include:

  • 799 attacks in total — 51 confirmed attacks (confirmed by the entity involved)
  • Of the 51 confirmed attacks:
    • 31 were on businesses
    • 10 were on government entities
    • 3 were on healthcare companies
    • 7 were on educational institutions
  • Of the 748 unconfirmed attacks*:
    • 657 were on businesses
    • 24 were on government entities
    • 50 were on healthcare companies
    • 16 were on educational institutions

You can find the full research here: https://www.comparitech.com/news/ransomware-roundup-july-2026/

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech:

“If we needed a reminder of how dominant a threat ransomware attacks remain, July’s figures provide us with just that. Figures reached the third-highest level in the last 17 months and The Gentlemen and Qilin continued to add hundreds of victims to their data-leak sites. We’ve already logged over 100 victims during the first four days of August 2026, too. 

July also saw some of the year’s most significant ransomware attacks. This includes the attack on the Romanian government’s land registry agency, which saw an entire database being wiped, the crippling attacks on AnMed and Fairlife in the US, and the attack on The Craneware Group, which looks set to have resulted in an extensive data breach. 

These attacks highlight how ransomware groups hit organisations in various different ways — taking down key systems, stealing troves of data, and even deleting massive datasets. Never has it been more important for organisations to ensure they’re carrying out regular backups (and backups of their backups!) so they can reset systems and restore data as quickly as possible if the worst does happen.”

I would put aside some time to give this a read as it will help you to structure your defenses.