What the latest Lazarus attack says about the limits of EDR

Posted in Commentary with tags on August 14, 2026 by itnerd

Two experts get into why Lazarus exploiting a Windows zero-day is particularly concerning despite the vulnerability’s “Important” CVSS rating. And how kernel-level rootkits like FudModule can undermine the security tools defenders rely on, and what organizations can do when patching or traditional mitigations aren’t immediately possible.

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“This story highlights an important shift in how organizations need to think about defense. Effective cybersecurity can no longer be reduced to firewall rule changes, patching, and configuration updates. Those remain important, but they’re no longer sufficient on their own.

“Security teams need to start training for the moments when those traditional options aren’t available. What happens when a critical system can’t be patched? What happens when operational requirements prevent you from making firewall changes? Those situations are becoming increasingly common, especially in legacy environments and critical infrastructure.

“That’s where compensating controls become essential. Organizations should be regularly exercising these scenarios and asking, ‘What can we do today to reduce risk while we wait for a patch or a permanent fix?’ Whether it’s increased monitoring, network segmentation, deception technologies, stricter access controls, or enhanced threat hunting, teams need to understand which defensive options are available and when to deploy them.

“The goal of compensating controls isn’t to eliminate the risk. It’s to buy time. As zero-day vulnerabilities continue to emerge at a faster pace, organizations need strategies that slow attackers down and reduce their opportunities while vendors develop patches and defenders work to implement them.

“The organizations that will be most successful over the next several years won’t necessarily be the ones that patch the fastest. They’ll be the ones that have rehearsed how to operate safely when patching isn’t immediately possible.”

Denis Calderone, CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)

“Lazarus has now exploited use-after-free vulnerabilities in Windows built-in drivers three times in two years to deploy the same rootkit. They went from appid.sys to AFD.sys to AFD.sys again. For a while, the standard playbook for getting kernel access was bring-your-own-vulnerable-driver: load a signed but buggy third-party driver, exploit it, get kernel privileges. Defenders adapted with driver allowlisting. Lazarus adapted by finding bugs in drivers that Windows ships by default. AFD.sys handles every socket operation on every Windows machine. You can’t blocklist it.

“Once the use-after-free fires, the attacker gets a kernel read/write primitive, and from there FudModule takes over. This is a rootkit that disables EDR callbacks, zeros out ETW provider registrations, and hides its own processes from the tools security teams rely on. The latest version, v3.1, adds the ability to tamper with Smart App Control, which means the rootkit is evolving faster than the mitigations Microsoft is building around it. And this CVE carries a CVSS 7.0, rated Important. There are 42 Critical patches in the same August Patch Tuesday release. If your vulnerability management program triages by severity score, this one is going to land in the middle of the queue behind remote code execution bugs that nobody has actually exploited yet. That’s exactly backwards.

“CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities catalog on August 11 with a federal remediation deadline of August 25, so needless to say, get this one patched right away, regardless of the CVSS score. Given that Lazarus had at least five weeks of active exploitation before the fix shipped, organizations in defense, aerospace, and adjacent sectors should be particularly diligent and treat anything unpatched since early July as potentially compromised. Check Point’s report includes the full IOC list covering file hashes, C2 domains, and the specific malware components used in the campaigns. Hunt for evidence of the MISTPEN downloader. It beacons out using Microsoft Graph API and OneDrive traffic, so look for anomalous indicators from workstations that don’t typically use those tools. Also look for unsigned DLLs loaded alongside legitimate PDF viewers and any evidence of ETW provider or kernel callback manipulation. Lazarus has shown that it’s possible to render EDR telemetry useless from the kernel level, and too many defenders still treat their EDR as a single source of truth. That dependency is exactly what FudModule is built to exploit.”

New FIRE Analysis of ExfilSquad’s D365 Data Extortion Campaign 

Posted in Commentary with tags on August 13, 2026 by itnerd

Fortra Intelligence and Research Experts (FIRE) just released research examining ExfilSquad, a new data extortion group believed to be exploiting misconfigured Microsoft Power Pages to access Dynamics 365 data. FIRE have obtained ExfilSquad data samples, and our analysis supports ExfilSquad’s claim that they have access to sensitive data from 15 different organizations.

This report is intended to help security teams understand the likely attack path, indicators of exposure, the types of data at risk, and immediate steps to identify and secure vulnerable Power Pages environments before sensitive CRM and ERP data is exposed.

Report can be accessed here: https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data

How Does the White House Privatizing US Cybersecurity Help It Defend Against AI-Driven Attacks?

Posted in Commentary with tags on August 13, 2026 by itnerd

The White House has a new memo on involving private cybersecurity companies in US defense against AI-driven hacks, vishing, and other attacks:

Transnational Criminal Organizations (TCOs) pose a growing threat to American citizens, businesses, and national security. These organizations conduct sustained cyber campaigns to perpetrate frauds that undermine American prosperity, security, and freedom. Through Executive Order 14390 of March 6, 2026 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), I directed the Federal Government to take various actions to combat cyber‑enabled crime harming American citizens. This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector.

Chris Nyhuis, CEO of Vigilant, released the following comments that all organizations should follow:

It’s the right move. But it quietly changes the role of private cybersecurity companies in American national security. The biggest question isn’t whether America has the technical capability to fight back. It’s whether we establish the doctrine necessary to do it without making a cyber incident worse.

I support this. America has extraordinary cyber capability sitting in the private sector, and we should be putting some of that capability into the fight. But offensive capability without disciplined rules creates its own risk. Before America acts, we need to prove who we’re dealing with, contain the original intrusion, understand the escalation risk, and then decide what action actually accomplishes the mission.

The forthcoming federal operating rules need to establish a simple doctrine:

PROVE > CONTAIN > DECONFLICT > ACT > PROTECT

1. PROVE: “EVERYBODY WANTS TO KICK THE DOOR DOWN. SOMEBODY STILL HAS TO PROVE IT’S THE RIGHT DOOR.”

Cyber attribution has always been difficult. But the consequences of getting attribution wrong are about to become significantly greater.

Cybersecurity companies use terms like ‘high confidence’ all the time. That’s one thing when the result is a threat-intelligence report. It’s something entirely different when that assessment becomes the basis for an operation against somebody else’s infrastructure.”

Attackers also understand how attribution works and can attempt to manipulate the evidence defenders rely upon. Infrastructure can be shared or compromised. Tools can be copied. Malware can be planted. Indicators can be manufactured. That creates a potentially dangerous scenario:

“Imagine you’re a foreign adversary and you can make America believe your enemy attacked us. If our attribution process isn’t strong enough, you don’t have to attack your enemy yourself. You try to manipulate us into doing it for you.”

Nyhuis believes the program should therefore establish one forensic attribution standard for every participating company.

“One company’s telemetry cannot become America’s definition of truth.”

Attribution should be independently corroborated and then subjected to an adversarial review in which another team actively attempts to prove the attribution wrong.

Before you ask, ‘Why do we believe it’s them?’ put somebody in the room whose job is to prove that it isn’t.”

2. CONTAIN: “NEVER OPEN A SECOND FRONT WHILE THE ATTACKER IS STILL INSIDE YOUR PERIMETER.”

Correct attribution isn’t enough. Before an offensive operation begins, Nyhuis believes there is another question that has to be answered: Have we actually contained the original intrusion?

Removing malware, restoring a compromised server or blocking the attacker’s known access does not necessarily mean the attacker is gone. The adversary may still possess valid credentials, persistence mechanisms, undiscovered access paths or other footholds inside the victim’s environment.

“Before you start talking about going after somebody, you’d better know whether you’ve actually contained the original intrusion.”

Launching an offensive operation before containment has been established could turn one cyber incident into a two-front fight.

“Never open a second front while the attacker is still inside your perimeter.”

If the attacker retains access when their infrastructure is disrupted, they may already possess everything necessary to retaliate from inside the victim’s environment.

“Think about the position you’ve just created. You’re attacking outward while the adversary may still be operating inward. They don’t have to break back into your network to retaliate — they may already be there.”

The attacker could destroy evidence, steal additional information, establish new persistence, disrupt operations, or deploy destructive malware using access they already possess. That is why containment status and retaliation risk should be part of the government’s operational approval process.

Offensive cyber doesn’t make incident response less important. It makes disciplined incident response more important.”

Containment also does not necessarily mean immediate eradication. There may be legitimate investigative or intelligence reasons to knowingly maintain visibility into an adversary. The critical distinction is whether continued adversary access is known and intentional or simply undiscovered.

“You can make a deliberate decision to observe an attacker who’s still inside. That’s very different from launching an offensive operation because everybody incorrectly assumed the attacker was gone.”

3. DECONFLICT: “THE TECHNICALLY CORRECT ACTION CAN STILL BE THE OPERATIONALLY WRONG ACTION.”

A cyber target rarely exists in isolation. The same infrastructure could be part of a corporate incident response, federal criminal investigation, intelligence operation, foreign-partner investigation or an active case involving victims.

Before private operators act, they need to know who else may already be operating in that environment, and what could be damaged by taking action.

Cyberspace doesn’t put up a sign telling you that somebody else is already working the case.”

Nyhuis believes government deconfliction should therefore be a mandatory gate before offensive action. That becomes particularly important when an investigation involves live victims.

“If taking down a server destroys an evidence chain, alerts an offender or puts a victim at greater risk, you’ve won the technical battle and potentially lost the actual mission.”

The question cannot simply be whether an operator can disrupt the target. It has to be whether disrupting the target at that moment advances the larger mission.

“The technically correct action can still be the operationally wrong action.”

4. ACT: “OFFENSE NEEDS AN OBJECTIVE, NOT JUST A TARGET.”

Once attribution, containment, and deconfliction have been established, there is still one more question before action: What exactly are we trying to accomplish? Surveillance, intelligence collection, disruption, denial, degradation and destruction can produce very different consequences.

“The objective can’t simply be, ‘We found the bad guy, now hit him.’ What outcome are we trying to create? What happens when they respond? And what does success actually look like?”

An operation designed to collect intelligence should be evaluated differently from one intended to disrupt infrastructure. An operation intended to temporarily deny capability is different from one intended to permanently destroy it. And every action creates the possibility of a reaction.

Nyhuis believes escalation therefore needs to be evaluated as part of the operational decision—not after the operation has already begun.

“America absolutely needs the capability to go after foreign cybercriminals. But capability needs doctrine. Prove who did it. Contain the original intrusion. Understand the escalation risk. Then decide whether and how to act.”

Offensive cyber capability is ultimately a tool. The mission should determine how—and whether—that tool is used.

5. PROTECT: “IF AMERICA AUTHORIZES PRIVATE CITIZENS TO ENTER THE FIGHT, WHAT HAPPENS WHEN THE FIGHT FOLLOWS THEM HOME?”

There is another side of this program that Nyhuis believes cannot be an afterthought: Who protects the private-sector people conducting these operations? The individuals carrying out authorized operations may be private-sector cybersecurity professionals—not military personnel, federal law-enforcement officers, or diplomats.

That distinction matters.

If the United States authorizes a private cybersecurity professional to disrupt a foreign criminal organization on America’s behalf, we need to think seriously about what happens to that person afterward.”

The United States may view the individual as an authorized participant in a lawful government-directed operation. The organization being targeted may see something much simpler: The person who attacked them. And the risk may not end when the operation does.

“Cyber operations don’t necessarily end when somebody closes the laptop.”

An operator who helps disrupt a sophisticated foreign criminal organization could potentially become a target for retaliation, identification, doxxing, intimidation, or other threats.

International travel raises another set of questions. What happens when that private-sector operator travels overseas months or years later? Could a foreign jurisdiction investigate or seek to detain the operator based on its own laws? What assistance would the United States provide? What happens if the criminal organization identifies the operator or their family?

These are questions the program should answer before the first operation is authorized, not after something goes wrong.

“We shouldn’t discover the government’s responsibility to these people when the first American cyber operator gets detained at a foreign airport or targeted because of an operation our government asked them to conduct.”

Nyhuis believes the framework should explicitly address operator identity protection, operational security, physical-security risk, foreign legal exposure, international travel, threat monitoring, and government assistance if an authorized operator is threatened or detained.

This isn’t an argument against using private-sector operators. It’s an argument for recognizing what America is asking them to do.

“If America asks private citizens to accept personal risk while conducting a U.S.-authorized cyber operation, then America needs to define what protection follows that authorization.”

Because bringing private cybersecurity professionals into national-security operations creates responsibilities in both directions.

We need rules protecting America from a bad operation. But we also need rules protecting the Americans we’re asking to conduct a good one.”

THE DOCTRINE

The framework Nyhuis believes should govern private-sector offensive cyber operations can be reduced to five principles:

  1. PROVE

Do we have forensic evidence that identifies the right adversary?

  1. CONTAIN

Is the original attacker still inside — and what could they do if we escalate?

  1. DECONFLICT

Who else is operating, investigating or potentially at risk if we act?

  1. ACT

What outcome are we trying to achieve, what response should we anticipate, and is offensive action the right tool?

  1. PROTECT

What responsibility does the United States assume for the private citizens it authorizes to conduct these operations?

“America absolutely needs the capability to go after foreign cybercriminals. But capability needs doctrine. Prove who did it. Contain the original intrusion. Understand the escalation risk. Then decide whether and how to act — and protect the Americans we authorize to do it.”

UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this comment:

   “This article is both exciting and concerning at the exact same time. It genuinely feels like the cyber equivalent of letters of marque, where private industry is authorized to conduct specific, targeted operations on behalf of the United States government.

There are a number of questions that immediately come to mind. How will oversight work? What are the limits of these authorities? Who is responsible for ensuring those limits aren’t exceeded? How does this fit within international law? Those are all critical issues that need to be answered before a program like this reaches full maturity.

   “That said, it’s also important to acknowledge the strategic reality. Our adversaries are already operating this way. We’ve seen multiple reports of China leveraging private cybersecurity companies to conduct offensive cyber operations. Russia has long relied on so-called private hackers who carry out activities that align with government objectives. When our adversaries embrace a model that we refuse to consider, it can leave the United States at a strategic disadvantage.

   “For that reason, I think this is a positive step, particularly for strengthening U.S. offensive cyber capabilities. At the same time, it has to be implemented carefully. Strong oversight and clearly defined legal boundaries are essential if this model is going to be successful.

   “There’s another issue that deserves attention as well. If private security companies are going to participate in these operations, what level of legal protection and indemnification will they receive? Before any company signs a contract to perform offensive cyber activities on behalf of the U.S. government, those questions need clear answers.

   “There’s a lot to unpack here, and I expect the next 60 to 90 days will determine not only how this proposal evolves, but also how the relationship between government and private industry develops in the offensive cyber space.”

Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:

   “I personally see this as a positive step in combating cybercrime because it recognizes that some of the best technical expertise is outside of the government.

   “The private sector cybersecurity community brings a wide range of skill sets and many have dealt with the aftermath and active defense from these threats on a daily basis. Cybercriminals and state sponsored groups have been attacking US companies and assets for years causing billions of dollars in damages and it’s good to see the gloves come off. Cybercriminals have benefited for years from jurisdictional boundaries and the difficulty of pursuing threat actors operating overseas and this program could be a game changer.

   “Speed important in terms of cybersecurity and the perception is that government processes can be slowed down by bureaucracy. Criminal infrastructure can appear, move, and disappear in hours so a public-private model could help bridge that gap of speed and efficiency. Another benefit is information sharing. Private companies often see pieces of an attack that government agencies may not see, while law enforcement and intelligence agencies possess information unavailable to the private sector.”


Donald McFarlane, Advisory Board Member, Xcape, Inc.:

   “This is not cyber vigilantism. It connects private-sector visibility and capability to lawful federal authority and oversight.

   “This is a significant evolution of the public-private cyber partnership. We’re moving beyond simply sharing threat intelligence to creating a pathway by which threat information acquired through normal business activities, along with threats identified by state and local government, can feed proposed operations for federal approval.

   “Capability is not going to be the scarce resource. Target validation, competing intelligence equities and deconfliction will be. The NCC is going to be busy. The secret’s in the deconfliction.”

Corey Ham, Director of Continuous Pentesting, Black Hills Information Security, Inc.:

   “My primary concern is the security of these contractors. Giving more entities access to sensitive information increases the likelihood that it can be compromised. Most of the information we have on Chinese state-sponsored hacking similar to this is from data leaks and breaches affecting contractors like I-Soon, for example. I worry that both nation states and crime groups will compromise the contractors who are targeting them, and access information they should not be able to access, like forensic data from other targets or classified data.”

Databricks Grows >80% YoY, Surpasses $7B Revenue Run-Rate, Scales Lakebase, Genie, and Unity AI Gateway

Posted in Commentary with tags on August 13, 2026 by itnerd

Databricks today announced it crossed a $7 billion revenue run-rate, delivering >80% year-over-year growth during its Q2. Building on this momentum, the company closed a $5 billion strategic funding round at a $190 billion valuation. The investment will drive continued innovation across Lakebase, its serverless Postgres database built for AI agents, Genie, Databricks’ AI coworker that turns business data into trusted answers and actions, and Unity AI Gateway, for multi-AI governance and cost controls.

The round was led by Coatue, along with Blackstone, MGX, accounts advised by T. Rowe Price Associates, Inc. and T. Rowe Price Investment Management, Inc., and new investor Sixth Street Growth. Other new investors included BOND, Clearlake Capital, Point72, Premji Invest, and TPG alongside existing investors Andreessen Horowitz, Dragoneer, Fidelity Management & Research Company, Franklin Templeton, GIC, Growth Equity at Goldman Sachs Alternatives, Insight Partners, J.P. Morgan Private Capital, Kinetic, Morgan Stanley Investment Management, NEA, Ontario Teachers’ Pension Plan, Temasek, Thrive Capital, and WCM Investment Management.

The Future of Data + AI 
Today, companies have a new set of employees to support: AI agents. To do their jobs, agents need a reliable, scalable foundation, clear, accurate answers from enterprise data, and the ability to easily forecast budgets and switch to more cost-effective models to avoid burning through expensive tokens. The Databricks Data + AI Platform delivers the foundation with Lakebase, enterprise context with Genie, and smart routing and cost controls with Unity AI Gateway, giving teams a simple way to build AI that actually works.

Databricks’ Financial Momentum
This funding follows Databricks’ continued business momentum, including:

  • Growing >80% year over year, surpassing $7B revenue run-rate
  • Continuing to deliver positive adjusted free cash flow over the last 12 months
  • Surpassing $1.5B revenue run-rate for Lakehouse, its data warehousing product, growing over 100% year over year 
  • Exceeding $100M revenue run-rate for Lakebase
  • >1,000 customers consuming at over $1 million revenue run-rate
  • >100 customers consuming at over $10 million revenue run-rate

The Check Point Q2 2026 Ransomware Report Is Out

Posted in Commentary with tags on August 13, 2026 by itnerd

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it. 

Key takeaways 
  • Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% year over year
  • The top 10 groups still controlled 57.6% of all victims, but the number of active groups jumped from 71 to 93, a new high
  • Leaked chats from The Gentlemen ransomware operation showed how a core team of roughly nine people, aided by AI coding tools, built a top three global operation in a matter of months
  • Ransom payment rates fell to about 23%, yet on chain ransomware payments still topped $820 million in 2025, pushing operators toward data theft over encryption
  • Defending against this shift means treating initial access, exfiltration, and exposure reduction as equally urgent
What actually happened in Q2 2026? 

Data leak sites, where ransomware groups publish victims who refuse to pay, logged 2,139 victims in Q2, essentially flat against Q1 and up 33% year over year. The ecosystem is holding at the elevated baseline it settled into through 2025. 

What shifted is who’s doing the attacking. In Q1, the top 10 groups controlled 71% of victims across just 71 active groups, a tight, top heavy market. By Q2, that eased to 57.6%, and active groups climbed to 93, the highest on record. Cl0p, whose Oracle E-Business Suite campaign drove much of Q1’s numbers, nearly vanished, and a wider mid tier filled the gap. Qilin held the top spot for a fourth straight quarter with 279 victims, narrowly ahead of The Gentlemen, which grew 62% and outpaced Qilin in June. 

Figure 1 – Total Number of Reported Ransomware Victims in data leakage websites, per month
(June 2024 – June 2026)

Figure 2 – Top-10 share and active group count, Q2 2026

What did the leaked Gentlemen chat logs actually reveal? 

A leak of The Gentlemen’s own backend and chat history, giving researchers a rare inside view of a top tier operation. The core team was just nine people, running a 90/10 split with a broader affiliate base that carried out most of the intrusion work, the highest cut advertised in the market. 

The detail worth remembering: the group’s admin, Zeta88, built the operation’s ransomware management panel in about three days using AI coding assistants, with a candid admission that the tools still require someone who understands the code well enough to guide and correct it. That’s genuine evidence AI is speeding up how ransomware tooling gets built, though its use here was about writing software faster, not running operations or picking targets. The bigger signal: the barriers to building a serious ransomware business have narrowed enough that one experienced operator can reach the top tier in months. 

Figure 3 – The Gentlemen monthly victim trajectory, Sep 2025 – Jun 2026

Why does data theft matter more than encryption right now? 

Payment rates have fallen for six straight years, from 85% in 2019 to roughly 23% today, largely because backups have gotten better at neutralizing encryption. Backups don’t help against data theft, though. If files are already stolen and about to be published, restoring systems doesn’t stop the leak, which is why operators are leaning into exfiltration first extortion. Total dollars paid haven’t followed payment rates down: on chain payments still exceeded $820 million in 2025. 

Law enforcement spent the quarter chasing shared infrastructure rather than individual groups, dismantling a laundering platform, sanctioning exchanges tied to ransomware actors, and taking down a malware signing service and major infostealer networks. None of that shows up as a drop in Q2’s victim count, and seized infrastructure tends to get rebuilt elsewhere, but raising the cost of laundering, signing, and credential harvesting adds friction that compounds over time. 

What should defenders actually prioritize? 

A few things fall out of the quarter’s data. Initial access remains the fight that matters most: The Gentlemen’s own pipeline ran on VPN scanning, brute forcing, and brokered credentials, the same route used across most of the ecosystem, so phishing and exposed remote access deserve defense in proportion to how often they’re the opening move. Exfiltration detection now deserves the same weight backup and recovery has traditionally received, and remediation speed matters more too, since the gap between disclosure and exploitation is now measured in hours. Defenses still running on a human review cycle are working against AI assisted tooling that no longer waits for one. 

How does Check Point address what this Ransomware quarter found? 

Most of what this report documents starts with a person, usually through phishing or stolen credentials feeding the same pipeline The Gentlemen relied on. Workspace Security protects users across email, browsers, SaaS applications, and endpoints, using AI driven detection to stop ransomware delivery before execution and limit lateral movement and exfiltration after a compromise. 

Hybrid Mesh Network Security applies consistent, AI driven controls at every connectivity point, from firewalls that block malicious files before they reach devices to CASB scanning that catches malware entering through SaaS platforms like OneDrive and Slack, a route access brokers increasingly favor. If a compromise happens anyway, Zero Trust access through SASE Private Access limits the blast radius so ransomware can only reach what the compromised user was authorized to touch. 

Exposure Management answers the harder question of which vulnerabilities ransomware groups can actually reach and use, not just which ones exist. Check Point’s 2026 Exposure Gap Report found vulnerabilities now make up 42.6% of critical exposures, more than double the year before, and that they can realistically be closed in under an hour, with utilities sector organizations using the platform resolving 30% of theirs within that window. 

AI Security addresses the same tooling ransomware groups are learning to use. ThreatCloud AI keeps protection moving on the same accelerated timeline as AI assisted exploitation, AI Agent Security governs the agent permissions that let an admin like Zeta88 build tooling in days, AI Red Teaming tests an organization’s own AI applications before deployment, and Workforce AI Security stops credentials and data from leaking through the AI tools employees already use. 

July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens Says Check Point

Posted in Commentary with tags on August 13, 2026 by itnerd

July’s cyber threat landscape was shaped by pressure across multiple fronts. Global cyber attacks continued to rise, ransomware activity broke from the more stable pattern seen earlier in the year, and GenAI exposure became a clearer operational risk as employees used more tools and generated more prompts across the enterprise.

Cyber Attacks Keep Climbing

The global attack curve continued upward in July. Organizations faced an average of 2,336 weekly cyber attacks, up 3% from June and 16% from July 2025. While the monthly rise was more moderate than June’s rebound, the broader trend remains clear: average weekly attacks per organization have increased by 13.7% since May, signaling sustained pressure rather than a temporary spike.

Education Remains the Top Target

Education remained the most targeted sector, averaging 4,848 weekly attacks per organization, up 14% year over year. Government ranked second with 3,044 weekly attacks, up 11%, followed by Telecommunications at 2,927, up 6%. Energy and Utilities moved into fourth place with 2,759 weekly attacks, up 20%, while Hospitality, Travel and Recreation entered the top five with 2,614 attacks, up 28%, possibly reflecting higher exposure during the summer travel period.

Latin America Leads in Volume as Europe Sees a Sharp Rise

Regionally, Latin America continued to face the highest attack volume, with 3,561 weekly attacks per organization on average, up 19% from July 2025. APAC followed with 3,316 weekly attacks, while Africa ranked third despite a 5% year-over-year decline. Europe stood out for its growth rate, with attacks up 18% year over year, while North America rose 9%.

GenAI Risk Moves from Theory to Daily Business Reality

GenAI risk is becoming a daily business issue. The main concern is not only how AI tools are used, but what employees enter into them, from customer records and internal documents to infrastructure, legal, financial, or HR information. July’s data shows how quickly that exposure can scale:

  • 1 in every 36 prompts from enterprise networks carried a high risk of sensitive data leakage
  • 88% of regular GenAI-using organizations were affected by high-risk prompt activity
  • 22% of prompts contained potentially sensitive information.
  • Organizations used an average of 8 GenAI tools, while the average user generated 95 prompts during the month

This makes GenAI both a governance and security issue, especially as adoption moves faster than policies, training, and controls. Exposure was highest in Latin America and North America, while Europe and APAC were slightly below the global average. By industry, Business Services and Healthcare and Medical recorded the highest risk, followed by Information Technology and Government.

The type of information being exposed is also important. Personal data remained the most common sensitive category, appearing in 70% of organizations. Financial Data and Network and IT Infrastructure followed at 68% each, while Legal and Regulatory content appeared in 63% and Employee and HR data in 62%. The issue is not limited to one team, use case, or document type. It cuts across the core information organizations rely on every day.

Email Remains a Key Entry Point for Cyber Risk

Despite growing focus on newer attack surfaces, email remained a high-volume risk channel in July. One in every 128 emails, or 0.78%, was classified as phishing, while another 20% fell into unwanted or risky categories such as graymail, spam, and suspicious messages, adding to the daily burden security teams need to filter and investigate.

Africa recorded the highest phishing rate, with one in every 106 emails classified as phishing, followed by North America at one in every 117. Beyond the regional differences, the trend reinforces email’s role as a common starting point for broader attack chains, from credential theft and malware delivery to business email compromise. In July, that escalation was most visible in ransomware activity.

Ransomware Breaks the Pattern

* This ransomware data draws from ransomware “shame sites” operated by double-extortion groups, which publicly disclose victim information. While these sources have inherent biases, they provide valuable insight into the ransomware landscape.

The clearest shift in July came from ransomware. Reported attacks reached 964, up 87% from July 2025 and 49% from June. This marked a decisive break from the first half of 2026, when monthly ransomware activity averaged around 672 incidents.

The increase was broad, touching multiple regions and industries, but Business Services remained the most affected sector, accounting for almost one third of reported victims.

North America remained the most affected region, accounting for 45% of reported ransomware incidents. Europe followed at 28%, while APAC accounted for 17%.

At country level, the United States continued to dominate the victim count with 39.4% of reported attacks, followed by Germany, Canada, the United Kingdom, and Italy.

The Gentlemen and Qilin Lead as the Ransomware Landscape Shifts

The Gentlemen and Qilin were the most prevalent ransomware groups in July, each responsible for 14% of published attacks. DeadLock climbed to the top three, with 10% and 97 reported victims.

  • The Gentlemen: A fast-growing Ransomware-as-a-Service operation launched in mid-2025. The group combines ransomware operations with initial access brokering, helping it scale quickly in a short period of time.
  • Qilin: An established Ransomware-as-a-Service group with victim disclosures dating back to 2022. Its mature affiliate model and renewed recruitment activity have helped it increase victim listings and regain momentum.
  • DeadLock: A group first observed in July 2025. It has gained attention for using blockchain-based techniques to rotate command-and-control proxy addresses, alongside the use of legitimate remote management tools.

What July Tells Us

July’s threat landscape was defined by accumulation rather than a single dominant risk. Global attacks kept rising, ransomware accelerated sharply, and GenAI exposure became more visible as part of routine business activity. For security teams, the message is clear: prevention cannot be limited to one layer or one threat category. Organizations need coordinated protection across network, cloud, endpoint, email, and AI usage, supported by the visibility to understand where sensitive data and attacker activity are moving next.

SOCRadar Goes Inside the LiteLLM Supply Chain Attack That Exposed 2,500+ Companies 

Posted in Commentary with tags on August 13, 2026 by itnerd

Today, the SOCRadar research team published a new research report on the LiteLLM supply chain attack that exposed 2,500 companies. It includes full attack chain, TeamPCP profile, IOC table, five detection checks, rotation guidance andFAQ.  

What’s different from general coverage:

  • They worked from the ranked company list. SOCRadar analyzed the 2,188 organization records at row level and the timeline changes.
  • The 40-minute PyPI window was the end of a 5-day collection run, not the start. 95% of affected organizations were already exposed before March 24, and the earliest record lands 18 minutes after the poisoned Trivy build published on March 19.

SOCRadar Findings/Differentiators:

  • Six CI/CD platforms, GitHub Actions and GitLab CI near-equal, self-hosted GitLab included
  • Footprint skews European and Latin American, Germany then Brazil then France, 137 TLDs, eight .gov
  • Credentials reach npm and Docker publishing tokens, Stripe, Twilio, SendGrid, not just AI keys
  • Our Dark Web monitoring caught the loot brokered on Telegram at 150+ GB, tied to Vect ransomware

SOCRadar’s report is here: LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies 

BreachLock Named Sample Vendor for Red Teaming as a Service and Penetration Testing as a Service in the Gartner® Hype Cycle™ for Security Operations, 2026

Posted in Commentary on August 13, 2026 by itnerd

BreachLock announced that it has been identified as a Sample Vendor in the Gartner Hype Cycle for Security Operations, 2026 in both the Red Teaming as a Service and Penetration Testing as a Service categories.

Security teams are navigating an increasingly complex threat landscape shaped by AI-driven innovation, evolving attack surfaces, and the growing need for continuous validation. The industry is shifting from reactive approaches toward proactive, threat-led validation practices that help organizations understand which exposures present meaningful risk.

Several market trends are impacting security operations, including the growth of Continuous Threat Exposure Management (CTEM), the adoption of cloud-delivered validation services, and the increasing need to move beyond point-in-time assessments toward continuous evaluation of security controls and exposures.

As organizations adapt to accelerated vulnerability discovery, expanding cloud environments, and AI-enabled threats, continuous offensive security testing is becoming an increasingly important component of modern security programs. Through its PTaaS and RTaaS offerings, BreachLock helps organizations combine expert-led offensive security testing with scalable, SaaS-based delivery models that support ongoing validation efforts.

To learn more about BreachLock’s offensive security solutions, visit BreachLock.com.

The North Korea Hiring Problem

Posted in Commentary with tags on August 13, 2026 by itnerd

North Korean IT workers infiltrating US companies and government agencies points at a threat model most security teams still aren’t built for: the attacker doesn’t break in, they get hired. Once someone clears interviews and onboarding, they inherit the same trust as any other employee, and almost nobody re-verifies that trust after week one.

The State Department put out (yet another) warning about this here: Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers – United States Department of State

In the warning there’s this:

Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.).

Justin Beals, CEO & Founder, Strike Graph, an AI-native GRC and compliance automation platform had this to say:

“This isn’t a hacking story. It’s a hiring failure with a nation-state attached. North Korean IT workers are getting through interviews, background checks, and onboarding because most companies still treat identity verification as a one-time gate instead of continuous evidence. Once that person is on payroll, they inherit the same trust as every other employee, and almost nobody re-checks that trust after day one.

The real gap is systemic. Organizations verify a document once, verify a face on a video call once, and then assume the risk is closed. It isn’t. Identity is not static and access should not be either. A hire that looked clean in week one can still be sitting on infrastructure tied to a sanctioned state a year later, and nobody is watching for it because nobody built a control for it.

The fix isn’t a smarter background check vendor. It’s treating high-access hiring as a compliance surface with ongoing evidence, not a one-time HR checkbox. Location consistency, device behavior, and access patterns need to be monitored the same way you’d monitor a production system, because at this point, that new hire effectively is one.”

North Koreans are here today and it is time to kick them out today. Because if they are still present tomorrow, it is one day too many.

Cybernews comments on fake Wi-Fi network on Delta flight 

Posted in Commentary with tags on August 13, 2026 by itnerd

Following a report of a fake Wi-Fi network on a Delta flight to Atlanta, Cybernews’ Senior Information Security Researcher Aras Nazarovas has commented on the risks such networks may pose, as well as what the people affected should know. 

What risks do fake Wi-Fi networks pose? What is an evil twin attack?

“An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.

Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.

The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.”

Are the people who connected to the network at risk?

“Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. 

If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.

However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.”