Finite State Joins DEF CON 2026 with AI Offensive Security and RAISE Act Sessions and a Hands-On Manufacturing Incident Response Challenge

Posted in Commentary with tags on July 31, 2026 by itnerd

At DEF CON 2026, Finite State will speak at two sessions focused on emerging cybersecurity challenges, including AI-driven security testing, IoT vulnerabilities, and the impact of new AI regulations. The company will also host the Factory Floor MVP Incident Response Challenge, a hands-on competition where participants investigate simulated attacks against a manufacturing environment.

WHO:

Larry Pesce, VP of Services, will discuss how AI is transforming security testing and vulnerability discovery, including where AI excels and where it falls short, and a practical blueprint for building AI-assisted security testing workflows in his session, “Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM.”

Joshua Marpet, Senior Product Security Consultant, will explore emerging AI regulations through a security researcher’s lens, including where the legislation strengthens transparency, where critical gaps remain, and what security professionals should understand in his session, “AI Safety Theater: What the RAISE Act Regulates, and What It Does Not.”

WHEN & WHERE:

DEF CON 2026, Las Vegas Convention Center | Las Vegas, NV

Speaking Sessions:
Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM
Friday, Aug 7 | 12:30-1:15 PM, at IoT Village, Stage 3

AI Safety Theater: What the RAISE Act Regulates, and What It Does Not
Saturday, Aug 8 | 5:00-5:30 PM, at Creators Stage 1

Factory Floor MVP Incident Response Challenge:
Friday, Aug 7 and Saturday, Aug 8 | 1:00-3:00 PM, at AppSec Village

Participants will step into the role of a defender responsible for protecting a modern manufacturing environment as they investigate active cyberattacks across industrial control systems, engineering workstations, sensors, historians, and connected infrastructure.

For more information on the Finite State sessions and challenge, visit: https://finitestate.io/events/defcon-2026.

Endra opens in New York, San Francisco, and London to break the engineering bottleneck holding up construction

Posted in Commentary with tags on July 31, 2026 by itnerd

Every building eventually runs into the same constraint: the engineering capacity required to make it real. As the world races to build data centers, electrify infrastructure, and meet net-zero demands by 2030, the bottleneck is becoming impossible to ignore. Endra was built to remove it.

Endra, the Stockholm-based AI company, today announced its expansion into the United States and the United Kingdom, with a North American headquarters in New York, a West Coast office in San Francisco, and an UK office in London. The expansion follows Endra’s $50 million Series A led by Andreessen Horowitz earlier this year and sets the stage for Epoch, the company’s launch event in Las Vegas this September.

The constraint inside every major building project

MEP engineering sits behind every major building project. Engineers calculate loads and flows, size systems, place thousands of devices, route cabling, ductwork, and piping, coordinate across disciplines, and produce the documentation contractors price and build from. When MEP slips, the whole project slips.

The pressure on that workflow is accelerating. Data centers, hospitals, electrified buildings, dense urban developments, and net-zero mandates all add engineering complexity. At the same time, the industry is facing a shortage of qualified MEP engineers and cannot train new engineers fast enough to keep up. Endra’s view is that engineering firms do not need another drafting tool. They need a way to scale their expertise.

What Endra is building

Endra is a purpose-built AI platform for MEP engineering, built for enterprise consultancies. The platform ingests standard building model files, integrates with BIM tools like Revit, and reconstructs each building in a detailed 3D environment. From there, it automates system design, device placement, routing, model generation, and compliance-ready documentation across 3D and 2D deliverables. A code-compliant electrical design for a 500,000-square-foot commercial building that traditionally takes around two months can be completed in less than a day.

A new phase of global expansion

The US is now the centerpiece of Endra’s growth strategy. Co-Founder and President Anton Juric is leading the company’s US go-to-market expansion. Endra is already in active engagement with engineering consultancies across the country, including several of the world’s largest engineering firms.

In parallel, Endra is deepening its presence in the United Kingdom. Its London office serves major engineering consultancies and acts as a strategic hub for enterprise customers across Europe and the Middle East. The company is actively hiring across engineering, sales, and customer success in New York, San Francisco, and London, pacing toward 100 employees globally as it scales its offices over the next twelve months. Open roles are listed at endra.ai/careers.

Winning the US and UK is as much an engineering challenge as a commercial one. Hadla Bergman, who joined Endra from Swedish autonomous freight pioneer Einride, is one of the world-class engineers making the platform native to these markets — local codes, standards, and design workflows — and will work hand in hand with the new teams, first and foremost in the US.

What comes next: Epoch

The expansion sets the stage for Epoch, taking place in Las Vegas on September 14, 2026. At Epoch, Endra will bring together leading engineers and innovators to unveil its electrical module and set out its vision for AI-native MEP engineering, with speakers including chess grandmaster Garry Kasparov. More information is available at endra.ai/epoch.

Endra’s ambition is to make MEP engineering the place where the future of construction begins. The company is building toward a world where every major building is designed with the speed, precision, and intelligence the next era of infrastructure will demand.

Anthropic AI Models Escaped Testbed And Attacked Three Companies 

Posted in Commentary with tags on July 31, 2026 by itnerd

Bad news for those who rely on AI for pretty much anything. Anthropic has reported the following:

we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.”

The BBC has more:

US technology firm Anthropic says its AI models hacked into the systems of three organisations on their own, during a private security experiment.

The models found a weakness in what was supposed to be an isolated test environment and connected to the internet.

It comes just days after rival OpenAI said that its models had breached the systems of other companies, including AI tools hub Hugging Face.

John Strand, Owner, Black Hills Information Security (https://www.blackhillsinfosec.com/):

“The fact that Anthropic reportedly only detected this after the OpenAI breach, and only after reviewing logs after the fact, is negligent and raises serious questions about their security posture. Organizations running frontier AI models should have continuous detection capabilities, active network threat hunting, and monitoring designed to identify attempts to escape containment in real time. Waiting until after an incident to discover suspicious behavior is not an acceptable security strategy.”

Ryan McCurdy, VP, Liquibase (https://www.liquibase.com/):

“The Anthropic and OpenAI incidents shouldn’t be viewed as isolated failures. Together they point to a broader shift in enterprise AI. As AI agents move beyond generating content to taking actions across production systems, governance can no longer depend on continuous human oversight alone. Every major technology transition has forced enterprises to move governance closer to where operational risk is introduced. AI is no different. Organizations need visibility into what AI changed, confidence that those changes comply with policy, and governance that operates at the speed of autonomous software delivery. The question isn’t whether AI will become more capable. It’s whether enterprise governance evolves just as quickly.”

Nick Mo, CEO, Ridge Security (https://ridgesecurity.ai/):

“First, these incidents prove that we cannot rely on frontier AI companies to self-police. As we are seeing across the industry, that approach is clearly failing.

“Second, we cannot allow a handful of model providers to gatekeep how AI is used for defense. When vendors over-police their platforms, we end up with an asymmetrical cybersecurity landscape: bad actors freely leverage advanced AI for malicious purposes, while legitimate defenders are constrained by vendor guardrails. To level the playing field, enterprises need access to open-weight and open-source models paired with purpose-built offensive cybersecurity toolkits like agentic offensive platform to proactively identify threats and protect themselves.

“Finally, this raises a serious legal question. Hacking corporate networks is a crime. Why should unauthorized breaches be excused with a PR blog post simply because an AI pulled the trigger?”

Lydia Zhang, President, Ridge Security (https://ridgesecurity.ai/)

“In my opinion, AI can benefit society in countless ways. I don’t understand why frontier AI models are making cybersecurity such a major area of competition.

“Cybersecurity is a highly specialized field. Offensive security capabilities should be left to dedicated cybersecurity companies that have spent years building security guardrails and developing deep domain expertise.

“For enterprises, I believe self-hosted open-source models are the right approach. By combining the strong reasoning and language capabilities of open-source models with enterprise-grade security controls, cybersecurity vendors can deliver safe, controlled, and effective agentic solutions for organizations to use.”

Should you feel safe? No? Should you take control of your AI and put as much as you can between it and the outside world? Yes. Should you make sure that you can’t get pwned by a rouge AI? Absolutely. The question is if you will do all of these things and more. I say you should and quickly.

Form.io Launches E-Sign+

Posted in Commentary with tags on July 31, 2026 by itnerd

Form.io, the enterprise data platform trusted by government agencies and regulated industries, today announced Form.io E-Sign+, that enables certifiable digital signatures to be embedded directly into applications. E-Sign+ eliminates the need to route users, data, and signature workflows through a separate, costly third-party service. For organizations operating under strict governance and compliance requirements, this product introduces a digital signature solution that operates entirely within the security boundaries of an enterprise, a radical departure from legacy third-party, document based solutions.

Enterprise signature workflows have long depended on costly external platforms — document-centric services that sit outside the application and outside the organization’s own governance controls. Every signature captured that way means data leaving the environment where it’s managed, secured, and audited, plus another vendor relationship to maintain. As enterprise applications take on more responsibility for security and compliance natively, treating signatures as a separate, outsourced step no longer fits.

Signatures, Native to the Enterprise Stack

E-Sign+ captures signatures directly against submission data inside a self-hosted technology stack, and cryptographically verifies that the signed data hasn’t changed since signing. Rather than exporting a document to a signing platform and importing the result back, organizations sign where the data already lives — inside their own environment, governed by their own controls.

With E-Sign+, organizations gain:

  • Self-hosted signature creation: Keep signature workflows and signature data inside the organization’s own environment, never a third-party platform.
  • Cryptographic verification: Confirm that signed submission data has not been altered after signing, with the signature automatically invalidated if protected data changes.
  • Consolidated infrastructure: Remove the high cost and complexity of a separate signature vendor and disconnected document workflow.
  • Full ownership: Maintain control of data, signature records, APIs, and cryptographic key strategy.
  • PDF support without PDF dependency: Continue producing signed PDFs where needed, without the burden of a document based solution.

Because E-Sign+ runs inside the customer’s own application, the signature stays bound to the data it signs even preparing for when those applications eventually take on AI and agentic workflows, where an unbroken chain of custody for data becomes essential.

The shift is the same across every regulated industry. A government agency capturing citizen consent, a bank recording a loan disclosure, a law firm executing a contract, an insurer documenting a claims authorization: instead of exporting data to an external signing platform, each workflow captures the signature directly as part of the submission data already being collected within its own application. If anything changes after signing, the signature is automatically invalidated, preserving integrity without data ever leaving the organization’s environment.

Availability

E-Sign+ is available now as a licensed add-on for Form.io enterprise deployments. Organizations new to Form.io can contact the team to discuss requirements and free trial.

Contact Form.io: https://form.io/contact-us/

Learn more: https://form.io/e-sign-plus/

CosmosEscape exposes cloud tenant-isolation risk

Posted in Commentary with tags on July 31, 2026 by itnerd

Wiz Research is reporting that a vulnerability chain it named CosmosEscape could have provided cross-tenant access to Microsoft Azure Cosmos DB accounts, including private and network-isolated databases.

According to Wiz, the vulnerability could have enabled full read and write access to customer databases across the service. Microsoft has fully remediated the issue and reported finding no evidence of customer impact. No customer action is required.

Waseem Ahmed, Head of Engineering at Secure.com:

“A cross-tenant flaw in a shared cloud database is significant even after it is patched, because it breaks the core promise cloud infrastructure is built on: that customers on the same platform stay isolated from each other. Wiz assessed this one could have reached any customer’s data across the Cosmos DB service, which sits under thousands of Microsoft customers and the data behind their applications, chatbots, and AI features. When one flaw can touch everyone’s data at once, the blast radius is the whole platform. That is why this is news, not a footnote.

“The reason it is not a catastrophe is timing. A security firm found it before attackers did, and Microsoft says it is fully fixed with no evidence of exploitation. Serious potential, contained outcome.

“Microsoft fixed this on its side, and unlike some past Cosmos DB incidents, there is nothing for customers to install or rotate. But nothing to patch is not the same as nothing to learn.

“Cloud-side flaws like this typically receive no CVE and are fixed quietly, which means customers often cannot determine whether they were exposed. That is why researcher disclosure matters. It is also why assuming the next one gets caught before attackers do is not a security strategy.

“If you hold sensitive data in Cosmos DB, review your access logs and treat this as a prompt toward real defence in depth, private endpoints, least-privilege access controls, and application-layer encryption, rather than relying entirely on the provider’s perimeter. The patch closes this door. It does not tell you what posture you should have had while it was open.”

Beau Bullock, Director of Emerging Threats and Advanced Testing at Black Hills Information Security:

“The researchers here identified a critical vulnerability that would have allowed an attacker to access virtually any Microsoft Cosmos DB account belonging to Microsoft’s customers, including Microsoft’s own Cosmos databases used by services like Entra ID, Teams, and more. What the researchers found was essentially a ‘master key’ that could have been used to retrieve access keys across customers and tenants, providing full read and write access. The researchers also demonstrated how it was possible to query Cosmos DB’s internal account directory to enumerate databases and precisely target organizations by tenant or subscription ID, making it much easier for an attacker to find and access data belonging to specific customers.

“This issue is related to something many people fear when they think about the shared nature of cloud services and just how segmented they actually are. This is not the first time a lack of boundaries between cloud provider customers has been demonstrated, and it likely will not be the last. Microsoft patched the issue and stated that it found no evidence of unauthorized exploitation, but the biggest takeaway is that organizations using cloud services cannot completely protect themselves from vulnerabilities in the underlying provider infrastructure that could allow cross-customer access.”

John Carberry, Solution Sleuth at Xcape Inc.:

“While it is true that no action is required by customers, this story has gained attention because a short attack path led to a multi-tenant compromise. This is alarming because it means internal security boundaries were ineffective and the broader architecture is lacking.

“The issue is very serious because a relatively simple attack path led to the compromise of the control plane in that multi-tenant environment.

“This was a sandbox escape facilitated by AI. Such attacks will continue and are likely to become less novel over time as LLMs and AI evolve. It is an opportunity to recognize a case where transparency in disclosure can benefit the entire industry. Lessons learned can be applied to other cloud environments and distributed multi-tenant architectures. The severity of this issue has more to do with fundamental flaws in the architecture of this fabric. When security depends on an unscoped, god-mode key for all tenants, we can expect these attack chains to become common. This is cause for alarm.

“Customers have nothing to do in terms of incident response, but they should remain aware that even when data is stored in the cloud, they still have a responsibility to understand the risks involved in such hosting.”

Cosmo DB appears to not be your friend at this point. Maybe you should examine your logs and look for intrusions. Because it is better to be safe than sorry.

NCSC urges network device makers to improve forensic capabilities 

Posted in Commentary with tags on July 30, 2026 by itnerd

The UK’s National Cyber Security Centre (NCSC) is urging network device manufacturers to embed stronger “forensic observability” into their products to help organizations detect, investigate and respond to cyberattacks. 

New guidance, developed with international partners, calls on vendors to improve the collection and preservation of forensic data to support incident response and recovery. 

The guidance outlines 31 recommendations across areas including logging, time synchronization, event recording, forensic data collection and secure storage. NCSC said network devices are increasingly targeted by sophisticated threat actors, making it critical for organizations to have sufficient forensic evidence to determine how a compromise occurred and what systems were affected. 

Donald McFarlane, Advisory Board Member, Xcape, Inc Had this comment: 

“Government guidance is increasingly acknowledging that cybersecurity is about more than prevention, and that it requires enabling rapid investigation, containment, and recovery for when prevention fails. Forensic observability should be viewed as a core design requirement for network infrastructure, not an optional feature. 
 
“Network devices have historically prioritized forwarding packets over recording evidence. Today, defenders need trustworthy, tamper-resistant forensic data to determinewhat happened, what was affected, and how to recover. You can’t investigate what you didn’t record. 
 
“It’s also worth viewing this alongside the recent Five Eyes guidance on preparing critical infrastructure to operate while intentionally isolated from external dependencies during a major cyber incident. Those recommendations aren’t in tension: organizations must be prepared to operate independently during a crisis, but collective defense still depends on sharing high-quality telemetry, forensic evidence, and threat intelligence before and after an incident. Resilience requires both the ability to stand alone and the ability to learn together.” 

Denis Calderone, CTO, Suzu Labs follows with this: 

“We generally love the direction this guidance is heading. What the NCSC is really asking for is EDR-level telemetry on network devices, and I’d argue that it’s long overdue. This incorporates devices that sit on the perimeter.  These devices are the way into the target, the way attackers exfiltrate data out of the targets and are often the internal boundary that must be traversed while moving from zone to zone and internal network to network.  In short, they see an awful lot, and that’s the data you need when working a real incident. The telemetry they could be providing about attacker movement, tooling, and data flows between environments is invaluable for an investigation. During incident response it’s not uncommon for the handlers to request log data, only to find that it falls short of their needs. 

“If I had a nickel for every time I’d heard “oh, we weren’t collecting that log data”, or “it only goes back 2 days”, well, I’d have a lot of nickels. This could allow us to maybefinally see the early promises of SIEM come true, where all events were going to be perfectly correlated across all layers of the stack. If vendors actually deliver on this guidance, we may end up with meaningful telemetry from the network infrastructure flowing into the same correlation engines that are already processing endpoint and cloud data. You could trace lateral movement across zone boundaries, identify what tools the attacker used, and quantify how much data moved between segments. That changes the quality of an investigation completely.  

“There’s a lot in this, but one thing I really do like is the emphasis on log shipping and the recommendation that devices should alert administrators when remote logging is disabled or misconfigured. That’s a simple thing that would catch a lot of problems early, including attackers who disable logging as one of their first moves after compromise. It would be great to correlate all the data in an intelligent way, but just having the data there at all is a huge plus over what we often find during actual incidents. 

“It’s also worth noting that this isn’t just a UK initiative. CISA, the FBI, and the Australian, Canadian, and New Zealand equivalents all co-authored the underlying guidance back in February 2025, and NIST currently has nothing this specific for network devices. This is currently the most detailed framework out there for what manufacturers should be building, and it has Five Eyes backing.  

“The one concern I’d flag is telemetry overload, particularly around capturing all DNS queries on a busy network device. That’s a lot of data, and organizations that are already managing high SIEM costs and alert fatigue need to think carefully about how they consume and operationalize this without drowning in it. That said, the volatile data collection recommendations are excellent. Capturing the running state of a device during an incident, process trees, memory maps, network connections, and particularly the CAM tables and DHCP lease tables, that’s the kind of data that can completely change an investigation. Knowing which MAC addresses were on which switch ports and which IPs were leased at the time of compromise could be a real game changer during an actual incident.” 

Josh Marpet, Senior Product Security ConsultantFinite State: 

“The NCSC has put out a security posture recommendation. Network devices should be able to log, secure, and be forensically available for examination, for both volatile and static data. 

“Why? Because for so long, network device manufacturers built the cheapest hardware they could, to be competitive in price. But that means that firmware is squeezed into flash too small to back itself up, hardware doesn’t have the space to store logs, or have the capability to be attached to a forensic duplicator. 

“The NCSC is asking manufacturers to make sure that network devices, long the target of cybercriminals and rogue nation-states, can perform basic security hygiene and has the basic security and compliance capabilities to make it simpler and faster for enterprises to perform incident response, disaster recovery, and be a modern mature workplace. 

“None of it is extraordinary, most of it is fundamental steps. Rich log data, solid logs of all major events, protection of keys, physical protection of protected hardware modules (TPM, HSM, etc), and the ability to do remote logging and maybe even local logging. 

“Again, nothing crazy. Fundamental security, especially for a device that traffics all of the data from the enterprise. Good ideas. Solid guidance. Manufacturers! Follow it!!!” 

Basic logging and a basic security posture… Sounds like a very good idea to me. This should be copied elsewhere as the UK seems to have a few good ideas.

White House cites quantum supply chain as major challenge 

Posted in Commentary with tags on July 30, 2026 by itnerd

A White House official said fragmented and underfunded supply chains remain one of the biggest obstacles to advancing U.S. quantum technologies. 

Speaking during an industry webinar, Brad Blakestad, director of the National Quantum Coordination Office, said quantum computing, sensing and networking each rely on different hardware platforms and components, creating multiple interconnected supply chains that are difficult to secure and scale. 

Blakestad said the quantum industry is nearing broader commercialization but lacks sufficient private-sector funding to build resilient supply chains. He pointed to the Trump administration’s recent quantum executive order, which calls for strengthening domestic quantum supply chains through research, manufacturing and private-sector collaboration, while warning that securing future quantum encryption capabilities remains another key challenge. 

Donald McFarlane, Advisory Board Member, Xcape, Inc. had this comment: 

“The national security implications extend well beyond today’s research pipeline. If a cryptographically relevant quantum computer becomes practical, strategicadvantage won’t come from building the first one: it will come from being able to manufacture, deploy, sustain, and improve them at scale. This is as much about surge capacity as it is about supply chains. 

“The administration’s emphasis on domestic quantum manufacturing reflects that reality. The United States has long excelled at fundamental research, but technological leadership ultimately depends on the ability to translate breakthroughs into resilient domestic production. The relevant question isn’t simply whether we can build a sufficiently capable quantum computer, it’s whether we can rapidly build many of them, along with the cryogenic infrastructure, control electronics, specialized manufacturing, and skilled workforce needed to support them. 

This planning should already be well under way. Building surge capacity for quantum technologies can’t begin after a breakthrough has occurred. The industrial base, manufacturing capability, and supporting infrastructure must be developed in parallel so they are ready when they’re needed, not years later. 

“Leadership in quantum won’t be determined solely by scientific discovery; it will also be determined by who can industrialize, scale production, and sustain operational capability when national security demands it. 

Aaron Colclough, VP of Operations, Suzu Labs adds this comment: 

“Blakestad’s right that this isn’t one supply chain. Computing, sensing, and networking pull different parts, and even within computing the machines are built different ways, with different parts. That means several intertwined bills of materials to secure and scale, not a single national stack. 

 “The June order tries to fix that by mapping the supply chains, cutting manufacturing friction, and incentivizing the buying of parts. But that only works if there’s money and the order doesn’t invent a budget by itself. 

“Encryption is the part most companies can act on now. You don’t need a working quantum computer to start swapping out today’s public-key crypto for NIST’s post-quantum algorithms. Find where you encrypt and sign today, then plan the cutover. Waiting for “Q-day” is how you leave old traffic sitting around for someone to decrypt later.” 

Resilient supply chains are a today problem. Thus every organization needs to treat them as such today.

Claude Was Down But It Is Back Up At The Moment

Posted in Commentary with tags on July 30, 2026 by itnerd

Claude was down yesterday for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a “529 Overloaded” message, including in Claude and tools that rely on its API. It is currently up according to this:

Claude Status

But you should check to see if it is up for you. There’s also a story on this here:

Claude AI Recovering After Widespread Outage on Wednesday – CNET

Commenting on this story is Jamie Beckland, CPO at APIContext:

“AI has gone from an experimental productivity tool to an essential part of the working day with remarkable speed. When Claude fails, it no longer means someone cannot play with a chatbot—it can stop developers writing code, support teams answering customers and automated workflows completing critical tasks.

That makes Anthropic’s repeated availability problems over recent months increasingly consequential. Persistent outages risk weakening Anthropic’s position in those enterprise architecture decisions.

By observing our public monitoring, it becomes clear that this is not solely an Anthropic problem. No AI provider is perfectly reliable when subjected to today’s extraordinary and unpredictable demand. Enterprises therefore need to treat AI services like any other critical third-party infrastructure: monitor them independently, understand their real-world performance, and build fallbacks so the failure of one model does not bring an entire workflow to a halt.”

If AI is part of your workflow, you should take outages into account. Otherwise you might find yourself high and dry so to speak.

iOMedia Group and Tumeryk Partner to Advance Human-Controlled AI for Ethical Journalism

Posted in Commentary with tags on July 30, 2026 by itnerd

iOMedia Group Ltd today announced a strategic partnership with Tumeryk, bringing together two organisations committed to ensuring that artificial intelligence is deployed responsibly, transparently and under meaningful human control within professional news organisations.

The partnership combines iOMedia Group’s AΩχ (Alpha Omega Chi) governance platform for journalism with Tumeryk’s expertise in AI security, governance and operational oversight, creating a powerful framework for trusted AI in editorial environments.

As news organisations worldwide seek to harness artificial intelligence while protecting editorial standards, legal compliance and public trust, the collaboration aims to demonstrate that AI should enhance journalists – not replace them.

AΩχ has been developed by iOMedia Group with the backing of Innovate UK and with assistance from The Alan Turing Institute. Rather than allowing AI to operate autonomously, AΩχ places editorial governance at every stage of the newsroom workflow, ensuring that journalists remain responsible for editorial decisions while benefiting from AI’s speed and productivity.

Under the partnership, Tumeryk’s AI governance and assurance capabilities will complement AΩχ’s newsroom workflow, helping publishers gain greater visibility, control and confidence over how AI systems operate in live editorial environments.

The partnership reflects a shared belief that trust in journalism can no longer depend solely on the reputation of a publisher. In an AI-powered world, trust must also be earned through transparent processes, accountable decision-making and continuous human oversight.

By combining editorial workflow governance with AI assurance, iOMedia Group and Tumeryk intend to provide publishers with an integrated approach that supports innovation while meeting the highest standards of ethics, compliance and operational resilience.

The collaboration will focus on helping broadcasters, publishers and digital news organisations deploy AI safely across news gathering, production, publishing and multi-platform distribution without compromising editorial independence or accountability.

As AI rapidly transforms media worldwide, the companies believe governance will become as important as the technology itself. Their shared vision is a future in which every AI-assisted story can be produced with clear accountability, transparent oversight and human editorial control.

Why governance matters now

The need for governance has been underscored by the security incident disclosed by OpenAI and Hugging Face on 21 July 2026. During an internal cyber-capability evaluation, OpenAI models operating with reduced cyber refusals were involved in a compromise of Hugging Face infrastructure. OpenAI said the incident combined state-of-the-art cyber capabilities and warranted a joint investigation and stronger defensive safeguards.

AI does not become trustworthy simply because it is instructed to “do the right thing”. The incident illustrates a wider issue: as AI systems become more capable, persistent and agentic, instructions alone cannot provide sufficient assurance that they will remain within their intended boundaries.

The answer is not to limit innovation. It is to build safeguards that make AI accountable, transparent and subject to meaningful human control. This is the principle behind AΩχ.

By embedding governance, oversight, auditability and human accountability into AI-assisted workflows, AΩχ is designed to support human decision-making rather than permit technology to operate beyond it. In journalism, where trust is fundamental to democracy, governance must become part of the technology itself – not an afterthought.

AI wrote exploit scripts against 12,500 domains and found live targets

Posted in Commentary with tags on July 30, 2026 by itnerd

Security firm Silent Push used Claude Opus 5 to write exploitation scripts against 12,500 domains, then filtered the results down to several hundred genuinely exploitable dangling DNS records. It’s a known bug class, a DNS record still pointing at a cloud resource that’s since been deleted, letting an attacker reclaim it, but Silent Push demonstrated it against real, named organizations.

You can read more here: Welcome to Danglegeddon – Silent Push

John Watters, Chairman & CEO, iCOUNTER had this to say:

“Silent Push used Claude Opus 5 to write exploitation scripts against 12,500 domains and came back with several hundred workable targets. These are real organizations, not lab conditions: a dangling Azure blob storage record tied to U.S. government infrastructure that could bypass .gov trust filters, an unassigned Société Générale Azure resource, exposed developer credentials and API keys at Ford, and a stale record at Eli Lilly. Silent Push projects losses in the hundreds of billions across pharmaceutical companies alone if this class of vulnerability gets weaponized at scale.

Security teams need to treat domain inventory as something that gets maintained continuously, not set up once and forgotten. That means tracking every DNS record they’ve created, including the orphaned ones pointing at cloud resources that were deleted months or years ago and never cleaned up. Most organizations have no idea how many of those records exist in their own environment, and Silent Push just showed exactly what an attacker can do with the ones they find.

What used to take a nation-state’s intelligence apparatus, mapping thousands of domains, cross-referencing DNS history, and building exploitation infrastructure by hand, now runs as an automated pipeline. An AI model did the reconnaissance, filtered the noise, and handed back a ranked target list touching banking, government, manufacturing, and pharma in a single pass. The skill and headcount required to run a globally coordinated infrastructure attack just dropped by an order of magnitude.”

If you haven’t been attacked by AI, you’re going to be. Of that there is no doubt. The question is will you be ready to defend against an AI attack.