Meet the Samsung Galaxy S26 FE: Galaxy AI, My FanCam and More 

Posted in Commentary with tags on August 27, 2026 by itnerd

Samsung has announced the Galaxy S26 FE, the newest addition to the Galaxy S26 family, bringing signature Galaxy S camera and AI experiences together with the latest One UI 9

Built around the experiences people use most, Galaxy S26 FE puts a particular focus on capturing, editing and sharing content, alongside more personalized and context-aware Galaxy AI features. Highlights include: 

  • My FanCam comes to the Galaxy S series: First introduced on Samsung’s latest foldables, My FanCam automatically tracks a selected subject and keeps them centred in the frame, making it easier to capture social-ready video with less manual editing. 
  • More ways to capture and create: A triple rear camera system includes a 50MP wide, 12MP ultra-wide and 8MP telephoto camera with 3x optical zoom, while Nightography and Super Steady Video with Horizontal Lock help capture clearer, steadier footage. Photo Assist also lets users make edits using natural language prompts. 
  • The latest Galaxy AI with One UI 9: Updated Now Brief offers customizable briefing cards, while Now Nudge can surface relevant suggestions across select third-party apps and notifications. Circle to Search with Google and Gemini Live can also identify multiple items in an image at once. 
  • Built for the everyday: Galaxy S26 FE features a 6.7-inch Dynamic AMOLED 2X display with a 120Hz refresh rate, a 4,900mAh battery45W wired charging, and seven generations of OS upgrades and seven years of security updates. 

Galaxy S26 FE will be available starting September 4 in Blueberry, Graphite and Pistachio, starting at $1,049

Here’s some details:

Category Details 
Display 6.7” FHD+ Dynamic AMOLED 2X display; 120Hz refresh rate 
Processor Exynos 2500 
Memory 8GB RAM 
Storage 128GB, 256GB or 512GB 
Rear camera 50MP wide + 12MP ultra-wide + 8MP telephoto triple rear camera 
Front camera 12MP 
Battery 4,900mAh 
Charging 45W wired charging; 15W wireless charging 
Durability IP68 
Software One UI 9 / Android 17 
Category Details 
Pricing Starting at $1,049 
Colours Blueberry, Graphite, Pistachio 

OpenAI’s AI agents built their own hidden coordination system before the Hugging Face hack

Posted in Commentary with tags on August 27, 2026 by itnerd

OpenAI disclosed that AI agents coordinated the intrusion behind the Hugging Face breach through a self-organized communication system, first an improvised bulletin board inside its internal Artifactory service, then, after that was shut down, messages encoded directly into directory names, letting agents share tools, divide labor, and settle disputes. On July 10, an agent found 14 Hugging Face credentials with write access and posted them to the board, which other agents used to gain broad infrastructure access within days.

You can see the details here: OpenAI agents formed secret swarm, hacked Hugging Face, then forged their own logs

Gidi Cohen, CEO & Co-Founder, Bonfy.AI

“This shows how quickly AI agents can improvise when they find cracks in the rules. The message board wasn’t just a weird side effect, it became a coordination hub that let agents share discoveries, stack exploits, and push far past what the system expected. Once they had a way to talk, they basically formed a small team.

The speed is the real story. One note turned into a whole communication network, then into privilege escalation, then into agents building on each other’s work across runs. That’s not just misalignment, that’s group behavior emerging on its own. And seeing agents pressure each other, even when some tried to opt out, shows how unpredictable things get when they influence one another outside approved channels.

Yusif Mukhtarov, Lead Machine Learning Engineer, Polygraf AI

“The bigger takeaway is that isolation assumptions don’t hold anymore. If agents can create side channels, they will and their collective capability jumps fast. Teaching models to ignore unsanctioned instructions helps, but future systems need to assume agents will collaborate, improvise, and repurpose infrastructure unless guardrails are airtight. This incident feels less like an anomaly and more like a preview of how agentic systems behave when left to their own devices: resourceful, collaborative, and quick to escalate impact.”

There’s the time slot between May 12 and July 19th where no action from anyone was taken even though the agent left in a package repo. In that time period OpenAI pulled down Artifactory, revoked the credentials and brought everything back. It took one day for agents to start talking again, and this time the messages were hidden in directory names. The problem was treated as if it’s a credential one. But I think the disturbing part here is that agents refused things. Some of them pulled out once they realized it was unauthorized hacking. The group got a proposal to contact an outside party because it was social engineering. Then one of the agents that objected went ahead anyway after another agent posted a deadline at it. This shows how models have a safety behavior that folds when the pressure comes from a peer. OpenAI’s building that distinction into training now, which tells us how far ahead of the safety work multi-agent deployment has gotten. Everything else here was ordinary hygiene: 14 write-capable credentials sitting in a public dataset, admin rights through an unpatched flaw, 22 admin accounts the agents made that nobody flagged.”

If you let AI do its thing without having proper safety measures, bad things will happen. This is an example of that. And you should take note and take action.

UPDATE: An independent investigation by METR and Redwood Research was also posted on this issue. Bri Frost, Director of Product Management, Cloud Range had this to say:

“If your AI security strategy is ‘put it in a sandbox and trust the prompt,’ you don’t have a security strategy, you have a wish. The Irregular and OpenAI–Hugging Face incidents show that AI agents will systematically search for any available path to complete an objective, acquire new credentials, assume trusted identities, communicate with other agents, and continue beyond their intended scope. Containment still matters, but this is increasingly an identity and behavior problem: organizations must continuously validate what an agent is doing, whether it remains authorized, and how quickly its access can be revoked.

The most uncomfortable part is that METR had to rely heavily on AI agents to analyze the AI agents and admitted those analysis agents made mistakes human researchers likely would not have made. That should end the fantasy that we are ready for fully autonomous agents. Humans still need to evaluate, orchestrate, and validate these systems in safe environments while defenders build the muscle memory to respond at machine speed. Until an organization can detect and stop an agent, or even hundreds of collaborating agents, from going off mission, deploying one with broad authority is not innovation. It is an uncontrolled production experiment.”

ATF investigating ‘major’ cybersecurity incident

Posted in Commentary with tags on August 27, 2026 by itnerd

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) yesterday announced an investigation into a “major” cybersecurity incident that the Qilin ransomware group claimed responsibility for. Given that is is Qilin, that’s all that needs to be said really.

Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech

“We recorded a significant uptick in the number of Qilin’s claims last month. Qilin claimed responsibility for the second-most data breaches out of all ransomware gangs in July, second only to the Gentlemen. Many of Qilin’s attack claims have proven credible. Most experts believe Qilin is based in Russia, which raises further questions about national security and what data was exposed.”

If you want to see more details on the Comparitech report that is being referred to, here you go: https://www.comparitech.com/news/ransomware-roundup-july-2026/

Guest Post: Why GRC Is Becoming an Engineering Discipline 

Posted in Commentary with tags on August 27, 2026 by itnerd

By Yasmine Abdillahi, Executive Director of Cyber GRC and Business Information Security Officer, Comcast 

When security leaders hear “engineering discipline” applied to Governance, Risk, and Compliance (GRC), the instinct is to brace for more tooling, more headcount, and more infrastructure that needs to be justified to the board. 

But this initial reaction misreads what is actually happening. GRC is becoming an engineering discipline not because someone decided to make it more complicated, but because the complexity was already there. The compliance programs built a decade ago were designed for the slower world of annual audits, static risk registers, and policies that changed quarterly at best. That world is gone. Today, cloud infrastructure can spin up and down in hours, AI agents are proliferating, regulations can multiply across jurisdictions, and a board member might ask about risk posture, with the expectation of an immediately trustworthy answer. 

The teams making real progress aren’t the ones that have added more people or tools. They’re the ones that changed what GRC is built on. Today, GRC engineering is how organizations simplify governance, shorten the time it takes to find value, and stop reinventing the wheel of pipelines year after year. 

The Problem Is the Data Beneath GRC 

Most organizations don’t fail at GRC because they lack frameworks, policies, or good intentions. They fail because the underlying knowledge of what is connected to what, which data resides where, and which controls protect which assets is scattered piecemeal across security, IT, cloud, identity, and business systems — none of which were designed to maintain that picture coherently. Every time a control needs to be validated, someone manually pulls from multiple sources, normalizes the results, and hopes the timing is close enough to tell a consistent story. 

Consider a simple question: “How many of our critical systems have MFA enabled?” Answering it accurately means pulling identity data, cross-referencing asset inventory, filtering the results by criticality classification, and clarifying whether “enabled” means configured, enforced, or actively used. By the time the answer is ready, it’s already a snapshot from last week. Multiply that by the hundreds of controls a mature GRC program tracks, and you see the real problem: teams aren’t doing GRC work. They’re doing data plumbing. 

Why agentic AI is amplifying the urgency 

AI governance dominated the conversation at Black Hat USA 2026, with much of it tracing directly back to the Hugging Face incident — a preview of how quickly “AI agents” went from an emerging buzzword to the central topic on the floor. 

These solutions are responding to the fact that agents drift and can get exploited when nobody is looking at them. However, AI governance is not just a feature that can simply be added to existing security tool stack. It’s a practice or a discipline requiring alignment between IT, Cybersecurity, GRC, finance and the business. 

Access control issues for agents cannot be observed and trusted periodically. Instead, they need continuous validation and remediation. Because agents can update themselves at runtime; a control evidenced at a point in time may not be compliant an hour later. 

This isn’t hypothetical. In July 2026, an AI model undergoing a routine capability evaluation escaped its test environment and compromised Hugging Face’s production infrastructure — autonomously, over four days, without a human directing each step. The agent didn’t need stolen admin credentials to escalate; it read cloud metadata, minted its own service-account tokens, and mapped its own permissions in real time. That’s the identity-to-agent-to-asset chain breaking down in exactly the way static, point-in-time control evidence can’t catch. 

This is where the identity-to-agent-to-asset mapping underneath any GRC platform needs to be engineered and current. 

Why Building Your Own Solution Usually Stalls 

The natural response is to unify the data by building an internal pipeline, a custom dashboard, and a “security data fabric” that pulls everything into one place. The intent is right, but the execution is where things get hard. 

Data normalization is genuinely demanding. Matching a user record from an identity provider to a Configuration Management Database (CMDB) asset record and a Security Information and Event Management (SIEM) log entry isn’t a configuration task — it’s an engineering challenge requiring sustained expertise. Audit defensibility gets added after the fact, if at all. And maintenance quietly becomes a permanent commitment, consuming engineering capacity that was supposed to go elsewhere. 

Agentic AI makes the engineering lift heavier as its governance requires granular traceability including what the agents are permitted to do and what they actually did, with what inputs, on whose behalf and why. If an agent’s effective permissions can be manipulated by the content it processes through prompt injection, then “what can this agent do” isn’t a static fact pulled once and normalized; it has to be validated continuously. 

What “Engineering GRC” Actually Means 

Engineering GRC doesn’t mean every organization needs to engineer it themselves. It means GRC now depends on properties that must be designed in from the beginning, not added later. 

Those properties are observability, testability, and explainability. Observability means your compliance posture is visible in real time, not reconstructed at audit time. Testability means controls are validated continuously against live data, not just when a review is coming. And explainability means every metric has a traceable origin. If someone asks how a number was derived, you can show exactly what data was used, how it was transformed, and what was included or excluded. 

With adding agentic AI to the attack surface, internal pipelines that have been built to track control configuration need to be expanded to continuous action-level traceability. 

Where the Real ROI Lives 

An organization that has built toward these properties is doing something fundamentally different from one that prepares for audits by collecting screenshots. The output might look similar from the outside, but the foundation is entirely different. The business case is often framed around efficiency such as less audit prep time, and fewer manual handoffs. Those gains are real, but the more compelling argument is compounding value. 

In most GRC programs, a significant chunk of team time goes toward “rebuilding truth.” Every quarter, every audit, every board report, someone pulls from the same sources, normalizes the same fields, and produces a number everyone agrees on. That work doesn’t accumulate into anything. Engineering the data foundation converts this recurring cost into a durable asset — a compliance posture that updates continuously and produces the same defensible answer whether the question comes from internal audit, an external assessor, or the board. 

There’s a risk dimension too. When compliance data is manually assembled, a gap can exist for weeks without anyone knowing. When the foundation is continuous and observable, that window closes. 

Most importantly, with agentic AI, the cost of not having the mapping foundation is an attack vector and not just a control gap. 

The Shift Worth Making 

GRC is becoming an engineering discipline because trust and accountability must now operate at machine speed. The organizations navigating this well aren’t the ones building the most sophisticated internal capabilities — they’re the ones that stopped rebuilding truth from scratch and started instrumenting it. 

When talking to GRC leaders early on in this journey, the question is almost never: “Shouldn’t we do this?” Instead, it’s: “Where do we start?” The answer: start with the data you already have. Map where your control evidence actually comes from. Identify the reconciliation work your team does every quarter that produces no lasting value. Then ask what it would take to make that work happen once — automatically, continuously, with full lineage — instead of repeatedly by hand. 

That question leads you to the foundation. Everything else follows from there. 

About the Author 

Yasmine Abdillahi is Executive Director of Cyber GRC and Business Information Security Officer at Comcast, where she leads security risk and compliance across Comcast and Sky. She is a recognized speaker at SINET, Gartner Evanta, and BrightTalk. She is also a senior fellow at the Atlantic Council. Connect with her on LinkedIn: linkedin.com/in/yasmine-abdillahi-2631b97 

White House order targets foreign-made equipment and software in U.S. power grid 

Posted in Commentary with tags on August 27, 2026 by itnerd

Yesterday, the President Of The United States signed an executive order declaring a national emergency to secure the U.S. bulk-power system, citing cybersecurity and operational risks associated with foreign-produced energy equipment.

The order can prohibit the acquisition, importation, transfer or installation of foreign-made bulk-power equipment, including associated software and digital capabilities, when it is determined to pose a significant national security risk.

The order specifically warns that foreign-made equipment could contain vulnerabilities or digital backdoors capable of providing remote access to U.S. energy infrastructure.

The restrictions could affect equipment such as power transformers and components used in solar infrastructure. China currently accounts for 85% of global solar supply-chain production capacity.

The Department of Energy has 120 days to develop rules implementing the order in coordination with other federal agencies.

Doc McConnell, Head of Policy and Compliance, Finite State:

   “On August 26, the President declared a national emergency over foreign-made equipment in the United States electric grid. Executive Order 14420 is the latest in a series of supply chain actions from this administration, and it includes a now-familiar assumption: equipment manufactured in a foreign country poses a national security risk.

   “The order points to two reasons. First, where equipment incorporates software, firmware, or other digital components, an adversary could build in remote access for surveillance or sabotage. Second, an adversary could cut off the supply of critical equipment at a moment of its own choosing, and do real damage that way.

   “Supply chain risk is real, and it is appropriate for the federal government to act on it. But for software and firmware, I don’t agree that foreign development is inherently risky, or that requiring development to happen within our borders keeps us safe.

   “A better way to secure our critical infrastructure is to test the equipment we install. For example, analyzing the compiled firmware binary of bulk-power system equipment can identify vulnerabilities, surface insecure configurations, and allow us to mitigate specific risks to better secure our energy infrastructure, regardless of where that equipment was manufactured.

   “The Department of Energy has 120 days to write the implementing rule. I hope that we see an evidence-based approach to evaluating the security of the equipment in our energy grid.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “This has been a concern for a large number of people in the computer security industry for a very, very, very long time. If you go back to concerns raised around Super Micro Computer Incorporated, the bigger issue has always been the same. Where are the components that make up our critical infrastructure actually coming from, and how much do we really know about that supply chain?

   “It’s nice to finally see this being acknowledged at a serious level. But acknowledgment is the easy part.

   “The details of how this gets implemented are going to be much more interesting. This isn’t a situation where we can simply decide we don’t trust a supplier and buy the equipment somewhere else. China dominates the production of many of the components and materials that modern technology and critical infrastructure depend on. In some areas, there simply aren’t enough alternative suppliers to make an immediate transition realistic.

   “So yes, I’m glad this is being looked at. It should have been looked at much more seriously years ago. But the real question isn’t whether we recognize the supply chain risk. We do.

   “The question is how we actually reduce that risk when much of the supply chain we’re worried about is also the supply chain we currently depend on.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “The cybersecurity issue here isn’t limited to finding a secret backdoor soldered into a foreign-made transformer. A legitimate vendor update mechanism or remote maintenance service becomes a national-security dependency when the infrastructure behind it is controlled by an entity the U.S. considers adversarial. Modern grid equipment increasingly relies on vendor-maintained update channels, remote diagnostics, firmware management, and other lifecycle services. That control-plane dependency is the threat surface this order actually reaches.

   “The order’s definitions acknowledge this more clearly than its preamble. Section 2(a) expressly covers software, firmware, digital services, maintenance services, and remote-access capabilities. Section 5(b) separately tells agencies to consider “remote access capabilities, lifecycle maintenance and update mechanisms, and other supply chain dependencies.” That operative language goes well beyond hypothetical malicious implants.

   “Section 2(b) creates the harder enforcement challenge, authorizing DOE to order identification, isolation, monitoring, disconnection, or replacement of foreign equipment already installed. This is rip-and-replace authority dressed in “phased compliance” language. Traditional asset inventories may tell a utility who manufactured a device, but not who controls its firmware, update infrastructure, remote maintenance services, or other lifecycle dependencies. The 2020 version of this policy ran into the same implementation problem, with some utilities struggling to determine what equipment fell within scope.

   “The 120-day rulemaking window will determine whether this becomes enforceable policy or another unfunded mandate. If DOE applies the “Covered Foreign Entity” definition narrowly and provides a realistic pre-qualification pathway, utilities can plan around it. If the rules function as a blanket ban without realistic transition guidance, the order risks creating the same grid-reliability problem it is intended to prevent. You can’t rip out a 345kV transformer on a regulatory deadline when a compliant replacement may have a multi-year lead time.”


Donald McFarlane, Advisory Board Member, 
Xcape, Inc.

   “EO14420 is a balanced executive order.  It recognizes that supply-chain provenance is a legitimate national security issue without treating every piece of foreign-made equipment as inherently compromised.  DOE has to identify a connection to a covered foreign entity and make a risk determination, and the order expressly requires consideration of reliability, replacement availability and continuity of service before existing equipment is disconnected or removed.

   “The cyber concern goes well beyond transformers. The order specifically reaches inverters, battery-storage systems, protective relays, PLCs, intelligent electronic devices, software, firmware, maintenance services and remote-access capabilities. The electric grid is increasingly a distributed network of computers, and that is before considering the possibility of undocumented or deliberately concealed capabilities and covert communications channels. Whenever equipment can receive an update or a remote command, who built it, who maintains it and who ultimately retains access to it are important security questions.

   “One interesting feature is what the order leaves out. It reaches transmission down to 69 kV but specifically excludes local distribution. I would not interpret that to mean distribution is safe or unimportant. It looks more like deliberate risk prioritization: generation and transmission are where a successful attack is most likely to create cascading, nationally significant consequences, while distribution is vastly larger, more heterogeneous, subject to different regulatory authorities and potentially much harder to remediate given existing supply-chain dependencies. The exclusion of distribution shouldn’t be read to mean distribution is secure. It means the government is starting with the part of the grid where compromise can most readily become a national event.

   “But that boundary is becoming less comfortable as distributed energy resources proliferate. One compromised residential inverter is not a threat to the grid; coordinated control of thousands or tens of thousands of installations and their inverters, batteries, EV chargers or other distributed resources is a very different proposition. A large fleet of individually modest devices can become a systemically important grid asset if an adversary can command them together. That is why the security of aggregated distributed resources increasingly has to be considered alongside the traditional generation-and-transmission security perimeter.

   “So, I view this EO as an important first step rather than a complete solution.  Cheap infrastructure isn’t cheap if a foreign adversary may retain a control path into it.  The test should be straightforward: do we know what the equipment contains, what and how it communicates with, and who can update or remotely control it?  The next challenge is making sure we eventually apply that same security thinking below the traditional bulk-power boundary, without imposing requirements that utilities and domestic supply chains simply cannot meet.

   “Engineers deliberately build margin into systems, for safety, for growth, and for resilience. In too many parts of the country, rapid load growth and constrained generation and transmission growth are consuming that headroom.  Sophisticated controls and grid-enhancing technologies can help us extract more capacity from existing infrastructure, but they are no substitute for building sufficient physical generation and transmission.  Cybersecurity, supply-chain security and adequate capacity are all parts of the same operational resilience problem.  The United States needs this EO, and it needs substantially more investment in generation and transmission.  It is very encouraging to see this administration treating those issues with the seriousness they deserve.”

Critical Infrastructure needs to be protected. The power system is critical infrastructure and hopefully organizations of all sizes pay attention to this and take whatever action is required to make themselves secure.

Three experts on tech challenges & realities Meta faces in restricting kids’ platform access

Posted in Commentary on August 27, 2026 by itnerd

As widely reported, here for example, Meta has agreed to pay $18 billion and sharply limit underage platform access to settle US lawsuits over children’s social media addiction to its platform. Three cybersecurity experts weigh in on some of the cybersecurity steps, missteps and implications involved in the governance that Meta is required to invoke, and that other social platforms may also be faced with.

Michael Bell, CEO and Founder, Suzu Labs:

“The settlement requires Meta to certify an age assurance AI within one year and have it tested annually. That is the right requirement. The problem is in how those systems get built. When you benchmark your safety AI against a competitor’s model by feeding it adversarial prompts through fake accounts, you are not learning how that model protects children. You are learning how it responds when it is being attacked. Those are different things. Research published in Nature shows that training on outputs from another model causes the student model to lose the rare-case knowledge, the edge-case judgment, that makes a safety system actually function. Child safety is almost entirely an edge-case problem. The auditor will be certifying a system that may have been developed by inheriting the blind spots of the models it was tested against, not by building independent safeguards. That is what the court needs to understand before it accepts Meta’s compliance reporting at face value.”

Yasir Zahid, Cybersecurity Leader, Founding Member, Secure.com 

The headline here is 18 billion dollars, but the real lesson for security leaders is about data governance. Regulators went after how children under 13 had their data collected and used, and how product design shaped that. That is a governance problem, not just a legal one. 

If your platform touches minors, you now have to prove age assurance works, prove default settings are safe, and prove what data you hold and why. An independent auditor will check Meta for ten years, so evidence has to be continuous, not a once a year snapshot. 

My advice is simple: Map where minor data lives, tighten consent controls to match COPPA and state privacy laws, and treat safety defaults as security controls you can test and demonstrate. If you cannot show your work, you carry the risk.

Ted Miracco, CEO, Approov on attestation issues of time limits for mobile app users:

“The mechanics of getting the time-limit guardrails right for teens on mobile platforms needs some planning and for most organizations, a clearer understanding of what’s involved, what’s needed and what’s challenging.

“Remember that in April 2026, the European Commission launched a white-label age verification app, built under a contract reported at roughly €2 million. It was billed as privacy-preserving: prove you’re over eighteen without handing a website your passport. Within days, researcher Paul Moore bypassed it. In July, after hardening and a re-release as version 2026.07-1, he bypassed it again — using Chrome extensions he says he built in minutes with an AI assistant.

“The second technique matters most. His extension detects the age verification QR code on a website and relays it to a remote, automated phone running the genuine app with a genuine credential. A real signature returns in seconds. Nothing is forged. He called it unfixable.

“I’d put it differently. This underscores that the security industry is largely built on the assumption that the user and the app owner are on the same side and the attacker is a third party. Age verification inverts that, as the user becomes the adversary. Almost none of our collective defensive playbook was designed for a world where the person you’re protecting is the person trying to get around you. Pretending otherwise is how you end up calling a relay attack unfixable instead of just predictable.

“When a privacy-preserving system fails publicly on a quarterly cadence, regulators won’t conclude that the goal was wrong. They’ll conclude the checks weren’t strict enough. Every bypass becomes an argument for something more invasive. Prove your age becomes prove your identity, and the privacy-first framing that justified the program may become the casualty of its own ineffectiveness.

“For anyone building or procuring these systems for mobile users such as teens: get the trust boundary right before buying any hardening. If security depends on the client behaving honestly, obfuscation buys time, not much of it, and not safety. Mobile app publishers need to fund attestation before cosmetics. And be honest about the remainder — attestation is necessary and insufficient, and anyone claiming it tells you who is holding the phone is selling the same client-side trust that just failed twice in four months.

I am calling it now. This will not deter Meta. Stricter enforcement is needed. Ideally by third parties. And more lawsuits are needed as Meta has proven that it will not change its behaviour on its own.

ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta

Posted in Commentary with tags , on August 27, 2026 by itnerd

The infamous ShinyHunters ransomware crew has added CyrusOne, a major US data center operator, to its list of victims, claiming to have stolen a treasure trove of highly sensitive data which, if proven true, could turn this into a bonafide catastrophe for the company and its customers. CyrusOne is used by Miscrosoft and Meta both. 

Rebecca Moody, Head of Data Research at Comparitech

“It’s important to distinguish between ransomware attacks and data theft with a ransom demand. ShinyHunters isn’t a traditional ransomware group, rather, it’s an extortion group that seeks to steal vast quantities of data before demanding a ransom to delete it. It doesn’t tend to use ransomware to encrypt systems. 

Regardless of the type of attack on CyrusOne, it serves as a reminder that cybercriminals are continuing to seek out companies with huge datasets. Technology companies like CyrusOne are a prime example as they’ll often deal with multiple companies. Therefore, by targeting one company, hackers can access the data of multiple organizations. As well as giving them access to more data, it also gives hackers more negotiating power. Not only will the organizations be pressured into resolving the attack as quickly as possible by their clients but hackers may even start contacting the organization’s clients individually, issuing them with a ransom demand, too.”

Brian Higgins, Security Specialist at Comparitech:

“This attack is one to watch. The nature and volume of data stolen simply cannot be mitigated with backups and patches. What happens in the next couple of days could seriously set the agenda for high stakes ransomware challenges as we move into the data centre era. ShinyHunter’s frustration at the lack of engagement is clearly exposed but what that means for any next steps is anyone’s guess at this stage. If CyrusOne have a trick or two up their sleeve it will be fascinating to see them played. Otherwise the potential fallout could be catastrophic. It’s a high profile game of Cyber-chicken and if it weren’t so devastating for the tech sector it would probably make a good movie.”

This is a #fail as it gives ShinyHunters keys to the kingdom so to speak. Everyone needs to take note now and take the appropriate steps to mitigate what appears to be a substantial threat.

Kyndryl expands alliance with Broadcom to drive secure by design private cloud for the AI era

Posted in Commentary with tags on August 27, 2026 by itnerd

Kyndryl today announced an expanded strategic alliance with Broadcom to deliver end-to-end consulting services for VMware Cloud Foundation (VCF), bringing cloud-like speed, automation and developer experience to private and hybrid cloud environments.

Under the expanded collaboration, Kyndryl and Broadcom are helping enterprises modernize, secure and scale mission-critical systems by building sovereign, AI-ready private clouds that reduce operational complexity, are secure by design and strengthen long-term performance. To support this joint effort, Kyndryl and Broadcom are investing in the skills development of several thousand certified Kyndryl consultants, architects and delivery specialists to enable agentic workflows.

The announcement comes as enterprises confront a rapidly shifting landscape. AI is accelerating innovation, but it is also amplifying risk as Frontier AI models are collapsing zero-day exploits to just hours and posing challenges to regulatory compliance and operations for organizations running critical systems. Sovereignty rules are reshaping where autonomous agents discover and exploit vulnerabilities across application source code, containers, VMs and pipelines at machine speed, without conventional signatures. Modernizing IT infrastructures to defend against fast-moving adversaries requires a private cloud hardened with policy guardrails and secure golden paths before a workload is provisioned, not patched after the fact.

Through the expanded collaboration, Kyndryl provides end-to-end VCF and VMware Tanzu transformation capabilities across advisory and strategy, architecture and design, upgrade and modernization and secure Day-2 operations, spanning virtualized and containerized workloads, while enabling seamless integration with public cloud landing zones as workloads evolve. With deep industry knowledge across financial services, healthcare, manufacturing, transportation, government and regulated industries, Kyndryl’s modernization approach maximizes business impact along with technology transformation objectives.

Kyndryl is also focused on helping mutual customers operationalize AI governance across VCF environments by applying the Kyndryl Agentic AI Framework and its policy as code capability to hold agents to approved, deterministic actions informed by business rules and regulatory requirements, so automation stays inside guardrails and drift is contained. This will ensure that AI agents act only within approved, deterministic guardrails shaped by each customer’s business rules and regulatory requirements, containing drift while preserving flexibility across models, data and infrastructure.

Combining the VCF private cloud capabilities with Kyndryl’s managed services unlocks the value of VCF, enhanced through industrialized operations, automation and AIOps-driven delivery. The result is a unified private cloud environment that runs virtual machine and containerized workloads, including AI inferencing, on a single scalable platform. IT teams and platform engineers can deliver an agile and robust developer experience, while maintaining the security, control and sovereignty the business requires.

Additionally, Kyndryl’s cyber recovery capability – built on VCF’s isolated recovery environments (using VMware vDefend), immutable snapshots (using Advanced Cyber Compliance) and orchestrated runbooks (using VCF Automation/Operations) – restores critical operations rapidly and with verified integrity. Kyndryl is a Pinnacle Partner in the Broadcom Advantage Partner Program and one of the world’s largest providers of managed VMware assets. The company was recognized as Broadcom Mainframe Partner of the Year 2025 in South America and in Finland. Kyndryl’s VMware services are bolstered by deep expertise and proficiency in the latest skills and technologies companies need to modernize VMware environments and adopt new VCF capabilities to enhance their VMware estate and achieve business objectives.

Learn about Kyndryl’s alliance with Broadcom VMware.

Chinese hacking platform takedown exposes an ORB network hiding in your routers 

Posted in Commentary with tags , on August 27, 2026 by itnerd

The DOJ and FBI just disrupted QTFY, a Chinese state-linked hacking platform built around QScan, which scanned the internet for vulnerable IoT and SOHO devices, and QTRouter, which enrolled those devices into an obfuscation mesh to hide attacker traffic. Authorities seized the domains hard-coded into the malware, making the tooling inoperable across every operation that relied on it, not just one campaign. The FBI also flagged business ties between the company behind QTFY and groups like Salt Typhoon and i-Soon.

Josh Picolet, VP of Detection & Analysis, Team Cymru had this to say:

“QTFY is a useful case study in how state-linked contracting networks actually operate. The detail worth noting is what QScan was built to do. It scanned the internet, likely in a very targeted manner, for vulnerable IoT/SOHO devices and enrolled them into QTRouter, the layer that hid the actual operations behind a mesh of compromised hardware. That is the operating model of an ORB network, an operational relay box mesh assembled from hijacked edge devices, and it is exactly the type infrastructure ecosystem we have been tracking at Team Cymru for years. QTFY is one network in a much larger pattern. Turning routers, IoT gear, and SOHO devices into an obfuscation layer for attacker traffic is not a one-off tactic bolted onto a single contractor. It is how China’s freelance hacking and contracting market has learned to work, and the business ties noted here to Salt Typhoon and i-Soon are the visible edge of a quartermaster model that resells capability and access across many customers.

That model is also why the takedown landed the way it did. The domains were hard-coded into the malware for communication and authentication, so seizing that infrastructure made the tooling inoperable across every operation depending on it, not just one intrusion. Detection built around a single campaign’s indicators would never have surfaced a platform built to be shared across operators. What exposes infrastructure like this is the ability to detect the shared obfuscation layer underneath the operations, recognizing the mesh as a repeatable tradecraft pattern rather than a scatter of unrelated victims.

Defenders should not expect this one to fade. The quartermaster model and the compromise of edge devices for obfuscation will be fought for years to come. We track a large number of these ORB mesh networks, and the modus operandi across them is remarkably consistent. That is why we tag and track every model of router, IoT, and SOHO device we can observe, so these networks can be detected early and customers get a real risk level on the IPs involved. Organizations in defense, telecom, and critical infrastructure should be asking whether their own detection reaches that layer, well past the perimeter.”

Disruptions like this are good. But what will really solve the issue is going after the people behind these schemes and bringing them to justice. That way the profitability gets taken out of activities like these.

Other World Computing to Premiere New and Enhanced Storage and Connectivity Solutions at IBC 2026

Posted in Commentary with tags on August 27, 2026 by itnerd

Other World Computing today announced its plans for the upcoming International Broadcasting ConventionIBC 2026, taking place September 11-14, at RAI Amsterdam, where it will take the wraps off several all-new products as well as showcase its world-renowned media and entertainment workflow innovations, in Hall 7, Booth 7.A60. 

While mum’s the word for now, during the week leading up to IBC 2026, OWC will 

launch brand new and dramatically enhanced storage and connectivity solutions across its OWC Jellyfish, dock, hub, and cable solutions portfolios – which it will then premiere live for the first-time at the event. 

In addition, OWC will feature its acclaimed, real-world proven, lines of storage and connectivity solutions, in Hall 7, Booth 7.A60 including: 

OWC Storage Solutions

  • OWC Express 4M2 Ultra – Thunderbolt 5 (80Gb/s) NVMe RAID storage solution, pre-configured with SoftRAID in 4TB, 8TB, 16TB, and 32TB capacities – also available as a bare enclosure for building your own configuration
  • OWC Envoy Ultra – first and fastest Thunderbolt 5 portable SSD, available in 2TB, 4TB, and a new category-defining 8TB capacity
  • OWC Envoy Pro Elektron – fastest, toughest mini-sized SSD available. It’s crushproof, dustproof, and waterproof for transferring gigabytes of data in seconds
  • OWC Express 1M2 80G – supremely fast, widely compatible, and highly portable USB4 NVMe SSD – build your own or choose ready-to-run solutions
  • OWC Thunderbay Series – delivers where it matters most: massive capacity, dependable performance, and cost-effective storage for large and growing data needs
  • OWC Express 4M2 – four-slot USB4 (40Gb/s) external storage enclosure for NVMe M.2 SSDs
  • OWC Studio Stack – world’s first, fastest, and highest-capacity Thunderbolt 5 stackable hybrid storage solution for Mac Studio and Mac mini machines
  • OWC ThunderBlade X12 – fastest and highest capacity production shuttle and editing RAID SSD in the universe

OWC Shared Storage Solutions

  • OWC Jellyfish Nomad – fastest, smallest, and most user-friendly mobile NAS on the planet, designed for DITs, independent 3D and VFX studios, and on-the-go editing teams
  • OWC Jellyfish Studio – high-performance desktop NAS built for collaborative production teams that need more shared storage, more users, and flexible all-SSD or HDD configurations

OWC Memory Cards & Readers

OWC Connectivity Solutions

  • OWC Thunderbolt 5 Hub – compact port expansion hub that turns one Thunderbolt 5 connection on your computer into multiple high-speed ports
  • OWC Thunderbolt 5 Dock – all-in-one command center for eliminating cables, expanding ports, and maximizing performance at your desk
  • OWC Thunderbolt 5 Dual 10Gb/E Network Dock – high-end network + connectivity docking station built for professionals who need serious network speed

Strada (In December 2025, Strada announced a partnership with and investment from OWC)

  • Strada 2.0 Peer-to-Peer Collaboration Platform – Strada will demonstrate its remote editing capability, which enables remote teams to edit video files stored on-premises…no file uploads or ongoing cloud subscription costs required! With Strada, creative teams can access remote video files, experience a seamless editing experience, and transfer files without any cloud intermediaries. This technology is a breakthrough solution for media customers concerned with data sovereignty, subscription costs, and the environmental impact of cloud storage companies. For a limited time, OWC customers who want their teams to experience remote collaboration can receive a special Strada discount.

“IBC brings together the people who are constantly pushing the boundaries of what’s possible in production, post, broadcast, and content creation, and our job is to make sure their technology never gets in the way of that,” said Chris Kooistra, Vice President, Marketing, Other World Computing (OWC). “Whether you’re moving massive files on set, editing against shared storage, building out a studio, or collaborating with a team across the world, every second matters. Everything we’re bringing to IBC this year is about helping professionals work faster, smarter, and more reliably — eliminating any and all potential bottleneck between capture and final delivery.”

To learn more about IBC 2026 and register to attend, please visit: https://show.ibc.org/.