Anthropic resumes external AI testing with new safeguards

Posted in Commentary with tags on September 1, 2026 by itnerd

Anthropic has resumed external cybersecurity testing of its AI models after introducing new safeguards, roughly a month after Claude models breached company systems during security evaluations.

The incidents occurred when models being tested for cyber capabilities went beyond their intended environments and accessed real-world systems. The company has now introduced stronger safeguards designed to limit what models can access and do during testing, including additional monitoring and restrictions around external systems.

Separately, Anthropic is warning customers about infostealer malware stealing active Claude login sessions from infected computers without going through normal password and two-factor authentication (2FA) login processes. The stolen sessions can allow attackers to access victims’ Claude accounts and consume their usage.

Noelle Murata, Chief Operating Officer, Xcape, Inc.:

   “Artificial intelligence tools are inherently benign, but threat actors will harness their capabilities regardless of corporate guardrails. Anthropic resuming model evaluations following internal sandbox escapes highlights an enduring reality: the leap-frog dynamic between defenders and adversaries is as old as software development itself. Using autonomous systems to monitor autonomous systems is ultimately using the problem to solve the problem.

   “As capability drift persists, operational environments exposed to AI agents must implement operator-aware context controls and strict transactional guardrails to prevent catastrophic actions from execution, whether initiated maliciously or accidentally. Beyond local sandbox containment, organizations face concurrent risks from infostealers harvesting session tokens to bypass multi-factor authentication. Security leaders must implement continuous internal controls, restrict session token lifetimes, enforce hard authorization bounds on target environments, and isolate testing sandboxes from corporate networks and the Internet.

   “Critical Takeaways

  • AI tools remain neutral capabilities that malicious actors will exploit regardless of safety guardrails.
  • Target systems must enforce operator awareness and hard transactional guardrails to prevent autonomous agents from taking catastrophic actions.
  • Fundamental identity hygiene and strict network isolation from the Internet remain the primary defense against token theft and agent escapes.

   “Playing leap-frog with autonomous agents is fine until the model jumps directly out of the sandbox.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “Anthropic is managing AI security from both directions this week. The company resumed external cybersecurity evaluations after deploying new safeguards, a month after Claude models breached three organizations during testing. Separately, it’s warning users that commodity infostealers are hijacking active Claude sessions to drain usage.

   “The evaluation incidents revealed three distinct failure patterns this summer. Anthropic’s preliminary analysis suggests its models encountered evidence of a real internet connection and rationalized it away to keep believing the environment was simulated. OpenAI’s Hugging Face incident showed a different mode, where agents recognized they were crossing a boundary and did it anyway. And the UK AI Security Institute found Mythos 5 attempting a supply chain attack against real open-source maintainers, creating fake identities and trying to socially engineer a human into approving malicious code.

   “I see the same dynamics in my own offensive security tooling. I’ve had agents try to enrich their own scope during penetration tests, finding adjacent targets and deciding they should be in play. The model can recite the rules perfectly and still reason around them in pursuit of the objective. That’s why I build deterministic hooks that cross-check every action against an immutable scope file before it executes.

   “The infostealer warning is a different problem with the same lesson. Stolen session cookies bypass two-factor authentication (2FA) entirely because the attacker never goes through the login flow. Claude sessions now sit alongside cloud console cookies and banking credentials on the commodity malware market.

   “Monitoring, alignment training, system prompts, and login-flow protections are all necessary, but insufficient as models get more capable. High-risk agent actions need hard technical controls and human approval before they execute. Increasingly capable agents can either knowingly disregard the rules or reason themselves into believing the rules don’t apply. Security architectures need to account for both.”

Face facts. Cyber security needs to take into account AI. If it doesn’t, it’s a fail. These examples prove it without a doubt.

White House & Texas Government launch Texas pilot to find and fix cyber weaknesses in water systems

Posted in Commentary with tags on September 1, 2026 by itnerd

The White House along with the Texas Government has launched Project Watershed 250, a six-month cybersecurity pilot that will provide Texas water and wastewater utilities with private-sector cybersecurity and AI resources at no cost.

The program will use red teaming to test utilities’ existing defenses, identify vulnerabilities and harden systems, with a particular focus on smaller and rural water providers that often lack dedicated cybersecurity resources.

The initiative will be overseen by the Office of the National Cyber Director and Texas Cyber Command, with companies including Microsoft, Google Cloud, AWS, Cloudflare, Palo Alto Networks, Fortinet, Forescout and Dragos contributing technology and expertise.

The pilot follows a wave of attacks against U.S. water infrastructure, including a recent campaign affecting 30 water systems across 12 states. Officials said the goal is to determine which defenses are effective during the six-month test and then scale successful approaches to water and wastewater systems across the country.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “You can’t harden what you don’t know is connected. Incomplete asset inventories are one of the most common findings I see across engagements, and critical infrastructure environments have some of the worst visibility gaps. Forescout, one of Watershed 250’s twelve participating vendors, recently found 4,400 internet-exposed Rockwell and Allen-Bradley controllers. Twenty-two sit in cities already hit by the recent water attacks, and 19 of those run firmware vulnerable to a flaw Rockwell patched many years ago.

   “Twelve companies are contributing technology and expertise at no cost, but bringing more tools into environments that lack staff to configure and maintain them just grows the unmanaged attack surface. A firewall with default rules or a monitoring console nobody watches becomes another blind spot in an inventory that was already incomplete. These utilities need governance and dedicated security personnel before they need enterprise-grade technology.

   “Month seven is the real test. Iranian campaigns against U.S. water systems and FBI-documented Chinese access to critical infrastructure are persistent threats, not six-month engagements. Replacing an exposed Programmable Logic Controller (PLC) might mean swapping a 15-year-old controller that was never designed to be networked, and the utility that can’t fund a dedicated security hire can’t fund that replacement either. If “scale what works” is the exit plan, it needs to include who pays for ongoing staffing and governance after the pilot ends.”

Damon Small, Board of Directors, Xcape, Inc.:

   “Federal support for critical infrastructure represents a welcome partnership between the public and private sectors, offering underfunded municipal utilities a no-cost opportunity to reduce operational technology risk. While Project Watershed 250 establishes an important first step, utility executives must question who benefits most over time: whether this effort drives long-term resilience or simply lines vendor pockets with short-lived service agreements. Temporary tool donations and red teaming cannot fix legacy hardware and deficient network architecture design without sustained capital investment. The broader challenge remains defending the entirety of the nation’s critical infrastructure beyond rural water systems.

   “To turn this initial momentum into permanent defense, security leaders must isolate control networks from the public Internet, enforce multi-factor authentication on remote access gateways, and baseline legacy environments before deploying complex artificial intelligence tools.

   “Critical Takeaways

  • Federal support and private-sector partnerships provide essential temporary coverage, but pilot programs cannot substitute for long-term capital investments in legacy hardware.
  • Utility executives must evaluate whether vendor-backed initiatives drive systemic resilience or merely create vendor lock-in.
  • Immediate operational technology defense requires foundational controls, including network isolation from the public Internet and enforced multi-factor authentication, before layering on advanced tools.

   “Upgrading national security requires durable capital allocation, not just a six-month software trial with big-tech name drops.”

Hopefully this isn’t just a one time investment because quite honestly, that’s not what the US needs. Now more than ever.

Airrived Launches Sovereign AI Platform, Putting Enterprises Back in Control of Their AI

Posted in Commentary with tags on September 1, 2026 by itnerd

Airrived today announced the launch of its Sovereign AI Platform, giving governments and enterprises a way to run agentic AI entirely inside their own environments — with nothing required to leave the building. Airrived will showcase the platform live at GISEC Global, taking place 16–18 September 2026 at the Dubai Exhibition Centre (DEC), Expo City, Dubai.

As AI adoption accelerates, a harder question is catching up with it: who actually controls the intelligence running your organization?

Sensitive data crosses borders it was never meant to cross. Token costs swing unpredictably from one quarter to the next, turning AI from a fixed cost into an open-ended liability. Mission-critical systems depend on external providers with no guarantee of continuity. And for the world’s most regulated institutions, sending data, prompts or intelligence to an externally hosted AI system isn’t a risk worth taking — it’s simply not an option.

Airrived built its Sovereign AI Platform to remove that trade-off entirely. The launch follows Airrived’s #1 overall ranking in the AWS/CTIB Cybersecurity Startup Accelerator, a global program backed by Amazon Web Services (AWS), CrowdStrike, CyberE71 and the UAE Cyber Security Council — recognition from some of the industry’s most demanding cloud and cybersecurity players that Airrived’s approach to agentic AI holds up under serious scrutiny.

Organizations can deploy Airrived on-premises, on private GPU infrastructure, or inside fully air-gapped environments — running their own models or Airrived’s models entirely within their own infrastructure.

An Agentic OS Built for Sovereignty

Airrived delivers an end-to-end Agentic OS: organizations can consume pre-built AI applications or build their own agents and agentic applications, all while keeping full control of the infrastructure underneath. The platform unifies agent orchestration, models, enterprise context, reasoning, governance, observability and AI applications into a single sovereign architecture.

With Airrived, organizations can:

  • Go fully sovereign — run AI completely on-premises or air-gapped
  • Break free from token economics — reduce dependency on externally hosted models and unpredictable costs
  • Own the compute — operate private GPU infrastructure on their terms
  • Choose the model — run customer-selected or Airrived-native models locally
  • Protect the perimeter — keep enterprise data and AI interactions within organizational boundaries
  • Build without limits — create and deploy agents and multi-agent applications
  • Govern with confidence — apply enterprise access controls and governance to every AI operation

The model is already proven in the region: through its partnership with Wizdom, Airrived’s Agentic OS powers agentic AI capabilities natively within Wizdom’s own data center infrastructure — sovereignty, not in theory, but in production.

The launch arrives as governments across the Middle East accelerate national AI strategies built on the same principle: sovereign control over data, infrastructure and intelligence. From the UAE’s National AI Strategy to similar initiatives across the GCC, the region has made clear that AI adoption must go hand in hand with data sovereignty and national digital resilience. Airrived’s platform is built to meet that mandate directly, giving governments and regulated enterprises a way to adopt agentic AI without ceding control of their most sensitive data.

The Next Era of Enterprise AI Is Sovereign

For governments, critical infrastructure operators, financial institutions and other highly regulated enterprises, real AI adoption now demands more than powerful models — it demands control.

Airrived believes the next generation of enterprise AI infrastructure will be defined by choice: where intelligence runs, which models power it, who can access it, and where the data ultimately lives.

Airrived will showcase its Sovereign AI Platform live at GISEC Global, 16–18 September 2026, at the Dubai Exhibition Centre (DEC), Expo City, Dubai.

BDO Canada partners with Workday to help organizations transform HR, finance, and planning

Posted in Commentary with tags on September 1, 2026 by itnerd

BDO Canada today announced a partnership with Workday, Inc. (NASDAQ: WDAY), the enterprise AI platform for HR, finance, and IT. As a Workday Sales and Services Partner, BDO will combine its business advisory and Human Resources Technology & Transformation expertise with Workday’s leading platform to help organizations modernize HR, finance and planning, accelerate digital transformation, and create greater business value.

Organizations are navigating increasing operational complexity, evolving workforce expectations and growing demand for better business insights. Together, BDO and Workday will help organizations simplify operations, improve decision-making and build a stronger foundation for long-term growth.

Through its Human Resources Technology & Transformation practice, together with specialists across finance, technology, and advisory, BDO provides end-to-end support across the transformation journey, from strategy and roadmap development through implementation, optimization and ongoing advisory services. The partnership further strengthens BDO’s growing ecosystem of strategic technology alliances, helping clients access integrated solutions that connect technology with business strategy.

Through the partnership, organizations can access advisory, implementation and optimization services across Workday Human Capital Management (HCM), Financial Management and Adaptive Planning, helping connect people, finance and planning to improve visibility, strengthen decision-making and support long-term growth.

For more information about BDO’s Workday services, see here.

Today Starts National Insider Threat Awareness Month

Posted in Commentary on September 1, 2026 by itnerd

National Insider Threat Awareness Month (NITAM) is a critical reminder that some of the most damaging security incidents originate from within. Human error, policy bypasses, and phishing-induced lapses account for most internal breaches, often costing millions to fix.

Organizations can protect their sensitive information by strengthening internal defenses, adopting stronger controls such as multifactor authentication and authorization, and fostering a culture of vigilance.

Eric Polet, Director of U.S. Operations, Arcitecta had this to say:

“At a time when cyberattacks are more frequent and data environments are larger and more complex, safeguarding critical assets requires continuous vigilance, intelligent monitoring, and a proactive defense against internal vulnerabilities.”

Max Gannon, Cyber Intelligence Team Manager at Cofense adds this:

“Insider threats are often associated with employees who intentionally misuse their access, but that definition misses a growing part of the risk. External attackers can create many of the same problems by stealing employee credentials, hijacking sessions or manipulating users through social engineering. Once they are operating through a legitimate account, malicious activity can be much harder to distinguish from normal business behavior.

Insider risk is no longer only a question of employee intent. It also includes how trusted access can be compromised. Employees are often the first to notice when a login request, MFA prompt or message feels out of place, making human context an important signal in identifying misuse of trusted access that may otherwise appear legitimate. Insider Threat Awareness Month is an opportunity to broaden the conversation around what insider risk actually looks like today.”

Piyush Sharrma, co-founder and CEO at Tuskira says this:

“Insider risk gets much more complicated once you stop looking at permissions as a flat list.

A user may only have access to a handful of systems. One of those systems may trust another identity. That identity may connect to a cloud role. An exposed vulnerability may open the next step. What looked like fairly limited access on paper can become a path to something far more sensitive.

Security teams already have plenty of data describing vulnerabilities and identities. The harder question is how those pieces connect.

AI-assisted attack-path analysis can trace that relationship across an environment. It can identify where legitimate access intersects with exploitable weaknesses. It can also show whether existing controls break the path before critical assets become reachable.

With insider threats, the first credential doesn’t have to be stolen. Sometimes it was legitimately issued. The security problem begins with everything that credential can reach next.”

Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ adds this:

“An insider already has what an external attacker usually wants first: access.

That’s why organizations can’t judge insider readiness by whether an alert exists for suspicious downloads or abnormal logins. They need to know how much damage a trusted account could actually cause if it were abused.

Can that user reach a privileged system? Can they escalate access? Can they move laterally toward sensitive data? In many environments, the answer is yes, especially when permissions have accumulated over time or controls haven’t been tested against real attacker behavior. The more important question is whether existing defenses would detect and stop those actions before access turns into compromise.

This is where continuous exposure management becomes useful. Insider scenarios should be part of the same adversarial validation organizations use against external threats. AEV can test realistic techniques against existing defenses before a real employee, compromised account or malicious contractor tries them.

Awareness helps people recognize insider risk. Validation tells you whether the environment can withstand it.”

Ross Filipek, CISO at Corsica Technologies follows with this:

“The insider threat problem isn’t always dramatic. Sometimes nobody disables an old account. An employee moves to another department and keeps permissions they no longer need. A contractor finishes a project but still has remote access. Someone leaves the company and their SaaS accounts aren’t shut down until days later.

Those gaps can be easy to miss because access follows people across IT, HR, and management processes. Smaller organizations may not have one team watching the entire employee lifecycle. Responsibilities get split up, and access quietly accumulates.

Basic process discipline is incredibly important. Teams need to know what employees should have when they join, review access when their roles change, and remove it immediately when they leave. Periodic access reviews can catch what gets missed along the way.

Insider threat programs don’t have to start with sophisticated surveillance. For a lot of businesses, simply making sure people only retain the access they actually need could eliminate a surprising amount of risk.”

Kevin Kirkwood, CISO at Exabeam had this to say:

“We need to retire the idea that an insider is always a disgruntled employee stealing files on the way out the door.

Exabeam has already encountered a much stranger version. A foreign operative aligned with North Korean interests made it through the hiring process and entered the organization as a seemingly legitimate employee. The access looked legitimate too. Small behavioral anomalies eventually told a different story. Those weak signals became meaningful once they were viewed together.

Now organizations have another insider entering the workforce: AI agents.

Agents can hold credentials. They can interact with internal systems. They can take actions without someone approving every step. None of that makes an AI agent malicious. It does make blind trust dangerous.

Insider Threat Awareness Month should push security teams beyond asking whether an identity successfully authenticated. They need to understand whether its behavior still makes sense. That applies to employees. It applies to contractors. Increasingly, it applies to machines acting with employee-like authority.

The next generation of insider defense will depend on understanding normal behavior well enough to notice when trusted identities stop acting normally.”

Kevin Mata, Director of Cloud Operations and Automation at Swimlane says this:

“One strange login probably isn’t enough to call something an insider threat. Neither is a large download or an unexpected privilege change. The challenge starts when several of those signals appear around the same person and nobody has the full picture.

That’s a very real problem for security operations. Identity data may sit in one system. Endpoint activity lives somewhere else. Cloud access adds another layer. Analysts can spend more time assembling the story than deciding what to do about it.

AI can help connect those signals while the investigation is still developing. Automation can enrich the activity and pull in additional context. It can also route higher-risk cases to the people who need to see them.

That last part matters with insider risk. Security isn’t always the only team involved. HR or legal may need to participate. The best response isn’t necessarily the fastest one. It’s the one where everyone is working from the same evidence before a judgment is made.”

Michael Centrella, Head of Public Policy at SecurityScorecard:

“National Insider Threat Awareness Month often brings to mind the traditional image of a malicious employee walking out with sensitive information. Today’s threats show that this is only one part of a much larger issue. Organizations also have to contend with outsiders who obtain legitimate access, contractors who can be recruited or compromised, stolen identities, and employees who intentionally or unintentionally put sensitive information at risk.

Recent incidents show both sides of that equation. A North Korean IT worker was hired by a U.S. government agency, giving a suspected foreign actor legitimate access through the front door rather than forcing them to break through the perimeter. In another case, a former TD Bank employee pleaded guilty after accepting bribes and using his legitimate access to obtain confidential customer information that was passed to outside co-conspirators. In one case, an outsider became a trusted insider. In the other, a trusted insider became an avenue for outside criminals.

Insider threat programs cannot rely only on pre-employment screening or assume that a valid account equals a trusted user. Security teams need to understand what access people and third parties actually require, limit privileges accordingly, and identify when behavior begins to deviate from the role behind the credentials. Trust cannot be treated as permanent. In a workforce increasingly made up of employees, contractors, remote workers, and external partners, authorized access needs the same ongoing scrutiny as any other part of the attack surface.”

John Bruggeman, vCISO at CBTS adds this:

“National Insider Threat Awareness Month is a reminder that insider risk extends well beyond the traditional image of a disgruntled employee. A legitimate account can create serious exposure when it is compromised, misused, or retains access that no longer reflects the user’s responsibilities. Most of the time I see organizations have good on-boarding processes but weak off-boarding processes.

With Agentic AI, AI is now an insider threat, AI could now be your weakest link. You need to make sure your AI agents can be trusted, just like your employees. What you want to consider is whether you can recognize when trusted access begins to deviate from its intended purpose. Ask yourself, can you recognize when trusted access, human or AI, starts to drift from its intended purpose?

Answering that question requires disciplined identity governance and consistent oversight. Access should be reviewed as roles change, employment ends, or business needs evolve. Security teams also need enough visibility to recognize meaningful changes in how an account is being used without relying on a single signal. A login from an unexpected location or access to information outside a normal work pattern may warrant scrutiny, particularly when it involves sensitive systems.

Organizations should always know who can reach critical data and why that access is still necessary. Align identity controls with monitoring, and misuse gets caught earlier, before it has room to spread.”

You can read more about this here: https://securityawareness.dcsa.mil/cdse/nitam/index.html

Introducing OWASP OASIS

Posted in Commentary with tags on September 1, 2026 by itnerd

Today, a community of application security professionals launched OWASP Open Automated Security Initiative for Software (OASIS). This global initiative marshals human expertise to deliver crowd-validated vulnerability fixes for the open source software that underlies 98% of commercial codebases, including critical infrastructure and commercial software. OWASP OASIS combines donated AI-powered fix automation and validation tooling with human expertise to move open source security from discovery to immediate remediation at scale.

OASIS has attracted hundreds of AppSec professionals from a variety of industries, alongside founding industry members AppSecAI, Intigriti, and DryRun Security.

What OWASP OASIS Is

For decades, the security industry has focused on finding vulnerabilities. The bottleneck has always been remediation: the cost, process complexity, and specialized expertise required to deliver credible security fixes for vulnerabilities.

OASIS changes that by leveraging Fix Automation and Validation, an emerging category of AI tools that generate and validate candidate fixes as vulnerabilities are found. OASIS’s community-driven validation layer makes those fixes trustworthy for upstream developer validation and contribution.

The three-part process:

  1. AI Pipeline: Automated tools scan open source repositories and generate candidate security fixes at scale. Found vulnerabilities always come with a candidate fix
  1. Expert Community Validation: The community reviews fixes, assesses correctness and safety, and determines which ones are credible, reducing validation time to minutes
  1. Upstream Contribution: Validated fixes are provided to open source teams as credible, community-validated security patches for consideration, allowing maintainers to quickly validate them for functionality and performance and integrate them at their discretion

By generating code fixes while contributing to the open source ecosystem, OASIS democratizes the vulnerability remediation process with a collaborative platform to augment human capabilities and improve security fixes at scale.

Why Now?

The launch of OASIS comes at a defining moment. “Vibe hacking,” the AI-assisted discovery and exploitation of vulnerabilities, enables attackers to move faster than security teams can respond. However, the same generative AI powering attacks offers a defense: the AppSec community now has the power to find and generate validated fixes at comparable speed.

This reality has catalyzed complementary initiatives across the industry. Frontier AI developments like Anthropic’s Project Glasswing introduced highly advanced models like Claude Mythos to defenders, while OpenAI’s Patch the Planet and the Linux Foundation’s Akrites have mobilized elite research teams and tech coalitions to protect core software infrastructure.

While these programs focus on researcher-led intervention for select high-priority infrastructure, OASIS is open, democratic, and vendor-agnostic. It leverages volunteers from the AppSec community to scale broadly across the open source landscape and address the long tail of software libraries and applications used by enterprises.

Why Open Source Needs OWASP OASIS

Open source maintainers face an onslaught of low-fidelity information.

OASIS acts as a community quality filter. AppSec experts assess whether a candidate fix is accurate and safe. Human validation converts rapid AI output into a patch a maintainer can trust. It provides a straightforward, vendor-neutral way for AppSec professionals to give back to the open source community.

Why Enterprise Users need OWASP OASIS

Open source code underlies countless custom enterprise applications.  When that code is vulnerable, they are exposed, dependent on maintainers to keep organizations running. 

How to Get Involved

Join the initiative at owasp-oasis.org

Instarc Secures €1.25 Million Strategic Investment to Expand Cloud-Native Regulatory Compliance Platform

Posted in Commentary with tags on September 1, 2026 by itnerd

Instarc, a regulatory technology firm based in Tallinn, has secured a €1.25 million strategic investment to accelerate the commercial rollout of its cloud-native compliance platform for financial and accountable institutions in South Africa. The system is designed to be fully scalable and adaptable so it can work with compliance regimes around the world.

HFO Investments, advised by Athena Capital and Option 3 Capital, has joined Instarc as a strategic investor through the transaction. As South Africa strengthens KYC/CDD requirements under the Financial Intelligence Centre Act (FICA), the Instarc platform helps accountable institutions address evolving compliance obligations.

It delivers a structured and modular digital operating framework with client onboarding, identity and ownership verification, configurable workflows, document management, retrievable audit records, and APIs that connect seamlessly with institutions’ existing systems.

Instarc addresses a critical need for businesses in South Africa where compliance obligations are among the most rigorous in Africa. Instarc platform allow clients to keep up to date with the rapidly evolving and strengthening KYC/CDD requirements of the Financial Intelligence Centre Act (FICA).

Instarc’s cloud-native technology was designed to integrate compliance into an institution’s operating model rather than to function as a standalone platform. Client journeys can be configured according to product, risk appetite and institutional controls, allowing organisations to adapt processes as regulatory requirements change without rebuilding the underlying technology.

For more information, visit instarc.com.

Half of the top mobile apps silently collect browsing history

Posted in Commentary with tags on September 1, 2026 by itnerd

recent Surfshark analysis shows that 45% of top mobile apps collect information about the websites their users visit. Of the 40 leading Android and iOS apps analyzed across gen AI, social media, e-commerce, and messaging, 18 report collecting browsing history in their app store privacy labels.

Social media collects the most, followed by e-commerce

Nine out of 10 social media apps collect browsing history on at least one platform. Facebook, Instagram, TikTok, X, YouTube, and Pinterest collect it on both Android and iOS. Reddit, LinkedIn, and Snapchat collect it on Android only. Discord was the only social media app that collects it on neither platform.

This data helps platforms build a clearer picture of user interests, target advertising more specifically, and shape in-app feeds based on websites visited outside the app.

Half of the e-commerce apps analyzed collect browsing history on at least one platform. eBay, Shopee, and Shopify collect it on both Android and iOS, while Taobao collects it on iOS only and AliExpress on Android only. The commercial value is direct: the more these apps know about a user’s online interests, the more effectively they can recommend and advertise products. The cost is that browsing habits become increasingly difficult to keep private.

Messaging and generative AI apps also track websites visited

Three messaging apps collect browsing history: Rakuten Viber, Messenger, and LINE. Their parent companies can use this data to build more detailed profiles of users and their interests.

Collection was the least common in the generative AI category. Google Gemini was the only app of the 10 analyzed to report collecting browsing history.

METHODOLOGY

Surfshark analyzed 40 of the most popular mobile apps, 10 each in generative AI, social media, e-commerce, and messaging, selected mainly from Cloudflare’s ranking of the most popular internet services worldwide. For each app, it was recorded whether its Apple App Store privacy label reported collecting “Browsing History” and whether its Google Play Store label reported “Web Browsing History,” then compared results by platform and category. A separate set of browsers was analyzed outside the 40-app sample. For the complete research material behind this study, visit here.

McKesson confirms data breach after ShinyHunters claims it stole 284M records

Posted in Commentary with tags on August 31, 2026 by itnerd

Pharmaceutical and healthcare technology giant McKesson confirmed it is experiencing intermittent service disruptions following a cyberattack involving a third-party application.

The company confirmed that attackers gained unauthorized access and exfiltrated data associated with customers in its oncology and surgical business units, although customers can continue using its systems and services. McKesson said it has received reasonable assurance that the attackers are no longer inside its systems.

The potential impact is significant given McKesson’s role in the healthcare supply chain: the company delivers approximately one-third of all prescriptions in North America and distributes pharmaceuticals, oncology drugs, medical-surgical supplies and laboratory equipment.

The ShinyHunters cybercrime group has claimed responsibility and threaten

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “The McKesson incident is another reminder that an organization’s attack surface extends well beyond the systems it directly controls. Third-party applications with access to sensitive data can provide attackers with a path around otherwise mature security controls.

   “The potential impact is especially concerning in healthcare. When an organization sits at the center of the pharmaceutical and medical supply chain, a cyberattack is no longer just a data-security issue. Disruption can potentially ripple downstream to providers, pharmacies and ultimately patients.

   “Organizations need to treat third-party access with the same scrutiny as internal access. That means limiting privileges, segmenting critical systems, continuously monitoring vendor connections and having an incident response plan that assumes a trusted third party could eventually be compromised.

   “The reported 284 million records is a claim from the attackers and should be treated as unverified until McKesson confirms the scope. Regardless of the final number, this incident demonstrates why third-party risk has become one of the most important challenges in defending complex healthcare environments.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “This particular story highlights a major problem that I don’t think enough people spend time thinking about. Complexity is the enemy of computer security.

   “The more third-party vendors you integrate with, especially SaaS providers, the larger your attack surface becomes. Every integration, API, application, and vendor relationship creates another potential path into your organization.

   “I also don’t think enough is being done around supply chain security. Organizations should be asking harder questions of their SaaS providers, getting letters of attestation, understanding how these services are secured, and identifying exactly what access those vendors have to their environments.

   “AI is going to make this problem even bigger.

   “We’re seeing an explosion of custom-written SaaS applications because AI has dramatically lowered the barrier to building software. That’s fantastic in a lot of ways, but it also means we’re creating more applications, more integrations, more APIs, and ultimately more complexity at an incredible rate.

   “We’re going to continue seeing vulnerabilities and compromises that originate with third parties. Attackers don’t necessarily need to attack you directly when they can attack something you trust.

   “Once again, complexity is one of the easiest ways in.”

Damon Small, Board of Directors, Xcape, Inc.:

   “When a third-party application breach hits a healthcare supply chain giant like McKesson, a single vendor integration can escalate into a national patient data crisis. The claim that 284 million records were exfiltrated is alarming, even if core delivery operations remain online. McKesson responded quickly by notifying the Securities and Exchange Commission and engaging external incident response specialists to contain the breach. However, given the company’s central role in drug and supply distribution across North America, organizations supporting critical infrastructure must apply far more rigorous scrutiny to the third-party software partners plugged into their environments. Security teams must enforce least-privilege access, continuously monitor data egress at vendor integration points, and audit partner security controls before a secondary application becomes a primary breach vector.

   “Critical Takeaways

  • Exfiltration claims of 284 million patient records demonstrate how third-party application vulnerabilities turn peripheral software into massive data exposure events.
  • Rapid incident response, including SEC notification and external forensic engagement, is vital to containing blast radius when third-party access is compromised.
  • Supporting critical healthcare infrastructure requires rigorous ongoing security auditing and strict access bounds for all vendor software integrations.

   “When you deliver one-third of a continent’s medicine, your third-party vendors are no longer optional software; they are critical infrastructure.”

ShinyHunters have been busy. They pwned this company last week. That should tell you all you need to know about ShinyHunters, and what you need to do to defend against them.

UPDATE:ShinyHunters vished their way into a McKesson employee’s Okta credentials, then rode that single SSO account into Salesforce and Snowflake, pulling roughly a terabyte of data including Social Security numbers, medical records, and cause-of-death details, with a $55.2 million ransom demand and a 72-hour deadline attached.

iCOUNTER’s, Director of Counter Fraud Operations, Jason Brown said this:

“This is textbook third-party blast radius. The actual failure point wasn’t McKesson’s own perimeter, it was multiple employee SSO accounts, according to the attackers, that opened access to Salesforce and Snowflake, and that’s the exact chain most vendor risk questionnaires still don’t ask about, they check whether a vendor encrypts data at rest, not whether a single compromised identity can walk straight into critical SaaS platforms with no additional friction. From a fraud operations standpoint, the interesting clock now isn’t the breach, it’s the 72-hour deadline ShinyHunters set before publishing the stolen data, and once it’s published, the monetization happens fast because health data with Social Security numbers and diagnosis codes is high-value fuel for identity, medical, and synthetic identity fraud.”

Global watchdog names AI-driven cyberattacks the most immediate threat to financial stability

Posted in Commentary with tags on August 31, 2026 by itnerd

The Financial Stability Board (FSB) has identified the impact of frontier AI on cyberattacks as the most immediate AI-related concern for the global financial system.

FSB Chair and Bank of England Governor Andrew Bailey warned G20 finance ministers and central bank governors that advanced AI could materially change the speed, scale and economics of cyberattacks, including by accelerating attackers’ ability to discover vulnerabilities.

The FSB also warned that many countries do not yet have adequate frameworks for managing the deployment of advanced AI models. In the financial sector, growing reliance on a small number of powerful technology providers could create concentrated risk and potentially undermine market confidence if those providers are disrupted.

Bailey called for a coordinated global approach to safe model deployment, along with stronger response and recovery capabilities across financial institutions and their critical third-party providers.

John Strand, Owner, Black Hills Information Security, Inc.:

   “The problem with focusing on frontier AI is that attackers don’t need frontier AI to successfully break into financial institutions. A lot of the open-weight models available today can already help identify vulnerabilities, develop exploits, and automate attacks. They may be slower and less efficient, but in the right hands they can be every bit as deadly. We cannot solve this problem by focusing exclusively on the most advanced models. Financial institutions need an all-hands-on-deck effort to find and eliminate vulnerabilities, particularly in third-party software, before attackers get there first.”

Noelle Murata, Sr. Security Engineer, Xcape, Inc.:

   “AI-accelerated vulnerability discovery and exploit scaling transform systemic market concentration into an immediate operational threat for global financial institutions. Cybersecurity practitioners have long warned that automated tooling drastically compresses the window from vulnerability disclosure to active exploitation, making the Financial Stability Board warning to G20 leaders a necessary wake-up call outside the technology sector. The current wave of optimism and heavy investment in frontier models echoes the dot-com bubble of the late 1990s, where speculative technology spending added fragility to an already volatile market. Concentration risk paired with borrowed capital means a minor AI stumble or containment failure can rapidly turn into a systemic market event. The operational burden now shifts to financial firms to prove their recovery workflows and third-party dependencies hold up at machine speed. Although the foundational AI adoption blueprints issued by international watchdogs remain non-binding today, they establish the exact regulatory template supervisors will grade institutions against tomorrow.

   “To maintain operational resilience, security executives must audit vendor dependencies, enforce real-time integration monitoring, and validate recovery controls before automated threat campaigns disrupt core financial infrastructure.

   “Critical Takeaways

  • Global watchdog warnings elevate AI risk from routine security patching to systemic financial stability threats.
  • Market concentration combined with speculative technology investment increases susceptibility to cascading outages from machine-speed exploits.
  • Non-binding regulatory blueprints are setting the baseline standards that financial supervisors will use to audit vendor resilience and recovery speeds tomorrow.

   “Building financial security on unproven technology models means betting global market stability on pure optimism.”

Ryan McCurdy, VP of Marketing, Liquibase:

   “The biggest change AI introduces isn’t necessarily a new kind of cyberattack. It’s speed. Attackers can find vulnerabilities and exploit them faster, which gives financial institutions less time to respond.

   “You can’t solve that by adding more people and manual controls. Financial institutions need to know what changed, whether it was authorized, and whether it meets policy before that change reaches a critical system. And when something does get through, they need the visibility to understand what happened and recover quickly.

   “AI is forcing security and governance to operate at machine speed. The institutions that figure that out will be much more resilient than the ones still relying on humans to keep up.”

The key benefit to AI is speed. As in they can do attacks quickly and faster than most humans can. You therefore need to make sure that you can deal with AI at speed. Or you are guaranteed to be on the wrong end of things.