SOCRadar Goes Inside the LiteLLM Supply Chain Attack That Exposed 2,500+ Companies 

Posted in Commentary with tags on August 13, 2026 by itnerd

Today, the SOCRadar research team published a new research report on the LiteLLM supply chain attack that exposed 2,500 companies. It includes full attack chain, TeamPCP profile, IOC table, five detection checks, rotation guidance andFAQ.  

What’s different from general coverage:

  • They worked from the ranked company list. SOCRadar analyzed the 2,188 organization records at row level and the timeline changes.
  • The 40-minute PyPI window was the end of a 5-day collection run, not the start. 95% of affected organizations were already exposed before March 24, and the earliest record lands 18 minutes after the poisoned Trivy build published on March 19.

SOCRadar Findings/Differentiators:

  • Six CI/CD platforms, GitHub Actions and GitLab CI near-equal, self-hosted GitLab included
  • Footprint skews European and Latin American, Germany then Brazil then France, 137 TLDs, eight .gov
  • Credentials reach npm and Docker publishing tokens, Stripe, Twilio, SendGrid, not just AI keys
  • Our Dark Web monitoring caught the loot brokered on Telegram at 150+ GB, tied to Vect ransomware

SOCRadar’s report is here: LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies 

BreachLock Named Sample Vendor for Red Teaming as a Service and Penetration Testing as a Service in the Gartner® Hype Cycle™ for Security Operations, 2026

Posted in Commentary on August 13, 2026 by itnerd

BreachLock announced that it has been identified as a Sample Vendor in the Gartner Hype Cycle for Security Operations, 2026 in both the Red Teaming as a Service and Penetration Testing as a Service categories.

Security teams are navigating an increasingly complex threat landscape shaped by AI-driven innovation, evolving attack surfaces, and the growing need for continuous validation. The industry is shifting from reactive approaches toward proactive, threat-led validation practices that help organizations understand which exposures present meaningful risk.

Several market trends are impacting security operations, including the growth of Continuous Threat Exposure Management (CTEM), the adoption of cloud-delivered validation services, and the increasing need to move beyond point-in-time assessments toward continuous evaluation of security controls and exposures.

As organizations adapt to accelerated vulnerability discovery, expanding cloud environments, and AI-enabled threats, continuous offensive security testing is becoming an increasingly important component of modern security programs. Through its PTaaS and RTaaS offerings, BreachLock helps organizations combine expert-led offensive security testing with scalable, SaaS-based delivery models that support ongoing validation efforts.

To learn more about BreachLock’s offensive security solutions, visit BreachLock.com.

The North Korea Hiring Problem

Posted in Commentary with tags on August 13, 2026 by itnerd

North Korean IT workers infiltrating US companies and government agencies points at a threat model most security teams still aren’t built for: the attacker doesn’t break in, they get hired. Once someone clears interviews and onboarding, they inherit the same trust as any other employee, and almost nobody re-verifies that trust after week one.

The State Department put out (yet another) warning about this here: Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers – United States Department of State

In the warning there’s this:

Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.).

Justin Beals, CEO & Founder, Strike Graph, an AI-native GRC and compliance automation platform had this to say:

“This isn’t a hacking story. It’s a hiring failure with a nation-state attached. North Korean IT workers are getting through interviews, background checks, and onboarding because most companies still treat identity verification as a one-time gate instead of continuous evidence. Once that person is on payroll, they inherit the same trust as every other employee, and almost nobody re-checks that trust after day one.

The real gap is systemic. Organizations verify a document once, verify a face on a video call once, and then assume the risk is closed. It isn’t. Identity is not static and access should not be either. A hire that looked clean in week one can still be sitting on infrastructure tied to a sanctioned state a year later, and nobody is watching for it because nobody built a control for it.

The fix isn’t a smarter background check vendor. It’s treating high-access hiring as a compliance surface with ongoing evidence, not a one-time HR checkbox. Location consistency, device behavior, and access patterns need to be monitored the same way you’d monitor a production system, because at this point, that new hire effectively is one.”

North Koreans are here today and it is time to kick them out today. Because if they are still present tomorrow, it is one day too many.

Cybernews comments on fake Wi-Fi network on Delta flight 

Posted in Commentary with tags on August 13, 2026 by itnerd

Following a report of a fake Wi-Fi network on a Delta flight to Atlanta, Cybernews’ Senior Information Security Researcher Aras Nazarovas has commented on the risks such networks may pose, as well as what the people affected should know. 

What risks do fake Wi-Fi networks pose? What is an evil twin attack?

“An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.

Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.

The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.”

Are the people who connected to the network at risk?

“Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. 

If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.

However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.”

$300M Senate bill to target cyber threats to U.S. water systems

Posted in Commentary with tags on August 12, 2026 by itnerd

Senators Adam Schiff and Amy Klobuchar introduced the Water Cyber Shield Act, which would give the EPA explicit authority to conduct cybersecurity assessments, require corrective actions and establish security standards for water systems alongside CISA and NIST.

The bill would also authorize $300 million annually for water infrastructure upgrades, require risk assessments for large systems and expand mandatory cyber incident reporting.

The legislation follows coordinated cyberattacks against dozens of community water systems across at least 12 states. Separately, DEF CON Franklin and the National Rural Water Association launched the Water Watch Center to provide cybersecurity services to utilities serving fewer than 10,000 people, a group representing 91% of the roughly 50,000 community water systems nationwide. Five cybersecurity firms will provide managed detection and response services, building on a two-year pilot involving nearly 450 volunteer cybersecurity experts across seven states.

Damon Small, Board of Directors, Xcape, Inc.:

   “The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector’s systemic fragility. Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.

   “The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments. Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.

   “Critical Takeaways

  • Funding dilution: Allocating $300 million across 50,000 utilities yields $6,000 per facility, failing to cover basic operational technology remediation.
  • Operational reality: Standards already exist, but infrequent maintenance windows choke security execution far more than funding deficits.
  • Immediate action: Operators must enforce network segmentation, eliminate Internet-facing control systems, and rotate default credentials immediately.

   “Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.”

Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs:

   “While it’s always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it’s likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found here https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys

   “I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past.  If we look at just the 118th and 119th Congress, we have had 9 bills introduced, as far as I’m aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still “pending’ but considering no movement has occurred on them, they will likely reach the same fate. 

   “Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn’t be dependent on the goodwill of private citizens to protect public infrastructure. Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn’t the first time we have had this situation happen before.  So, my fingers are crossed, but I’m not holding my breath.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade. Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.

   “My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised. It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.”

While addressing critical infrastructure is long overdue, the time to act is now as the threat is real and present. Will lawmakers act on that threat is the real question.

Rogue Wi-Fi network discovered aboard Delta flight

Posted in Commentary with tags on August 12, 2026 by itnerd

Delta is investigating an alleged passenger created, rogue Wi-Fi network aboard Flight 591 from Las Vegas to Atlanta on August 10, one day after the DEF CON cybersecurity conference concluded in Las Vegas.

The unauthorized network, named “Delta WiFi Fast,” impersonated the airline’s legitimate Wi-Fi and was reportedly intended to scam other passengers. The crew disabled the aircraft’s Wi-Fi for approximately 30 minutes after discovering the network.

Delta said no aircraft operating systems were affected and flight safety was never in question. 

   “Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,” Monika Hathaway, head of press for DEF CON said.

Seemant Sehgal, Founder & CEO, BreachLock:

   “Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.

   “Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved. The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.”

Denis Calderone, CTO, Suzu Labs:

   “Hackers will hack. I go to DEF CON most years, and it’s pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn’t have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that’s taking the expected hijinks way too far.

   “The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth. But there’s a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.

   “For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same. Beyond that, if a WiFi network on a plane doesn’t match what the crew announced or what’s printed on the seat card, don’t connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that’s not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you’re being asked for something that doesn’t make sense for the context, you’re probably not on the real network.”


Jacob Warner, Director of IT, 
Xcape, Inc.:

   “While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks. Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet. Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.

   “This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.

   “Critical Takeaways

  • “Reputational damage: Pulling wireless hijinks on commercial flights damages industry credibility with non-technical audiences and disrupts legitimate travel.
  • “Transit vulnerability: Unencrypted inflight Wi-Fi exposes business travelers to man-in-the-middle credential harvesting and session hijacking.
  • “Endpoint hardening: Security leaders must enforce always-on virtual private networks and disable automatic SSID connections on all corporate devices.

   “Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.

   “There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.

   “I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.”

This is basically dumb. I hope that the people are found and punished accordingly. But at the same time Delta and other airlines need to make sure that this sort of exploit isn’t possible. Use an VPN every time to protect yourself from this exploit as the next time it might be someone bad behind it.

Which CMS platforms provide the strongest out-of-the-box security? 

Posted in Commentary with tags on August 12, 2026 by itnerd

Content Management Systems (CMSs) power millions of websites worldwide, making them one of the most common ways to publish content online. Because many CMS users have limited cybersecurity expertise, the security protections enabled by default can play an important role in reducing risk.

In a study published today, Comparitech researchers took a look at four of the most popular open-source CMSs (WordPress, Drupal, Joomla, and Ghost), to determine which has the strongest out-of-the-box security. The CMS platforms were assessed immediately following installation to determine their secure-by-default posture, with the assessment considering browser security controls, information disclosure, authentication securiy, and API and enumeration exposure. 

Key findings include: 

  • WordPress had the weakest out-of-the-box security protections, with a score of 8 out of 100
  • Drupal achieved the highest overall score (27.1 out of 100) – note that none of the tested CMSs provided a particularly strong security posture immediately after installation
  • Joomla has had the greatest number of disclosed vulnerabilities in the past five years
  • Drupal recorded the highest number of high- and critical-severity core vulnerabilities between 2021 and 2025
  • WordPress has the largest extension ecosystem, which may increase exposure to security risks associated with third-party plugins

For full details, please see the research here: https://www.comparitech.com/news/which-cms-platforms-provide-the-strongest-out-of-the-box-security/

Wagepoint expands AI-powered vision with AI Payroll Summary

Posted in Commentary with tags on August 12, 2026 by itnerd

While a third of Canadian small businesses reported using AI in their operations by the end of 2025, many business owners and their accountants are still spending hours reviewing their payroll runs, trying to spot a mistake. Canadian business optimism may have grown in the last month, but the onset of new tariff threats puts time and money pressure back on the table.

The recent launch of Wagepoint’s latest feature, the AI Payroll Summary, built directly into its platform makes this workable for small business.

As making payroll errors can be costly, Canadian payroll software company Wagepoint has implemented AI’s capabilities to provide a summary of each payroll run, identifying any unusual patterns or changes. The final review is ultimately in the hands of the business owner or AB, but saves ample time and narrows the margin of error.

New SharePoint auth bypass already being exploited hours after PoC went public

Posted in Commentary with tags on August 12, 2026 by itnerd

Rapid7 published a proof-of-concept exploit today for CVE-2026-55040, an authentication bypass in SharePoint’s JWT token validation that lets an attacker impersonate any user or admin without credentials. Threat intel firm Defused reported the exploit code was already hitting its honeypots the same day; it’s the second distinct on-prem SharePoint flaw to make news this week, after Monday’s ransomware-exploited deserialization bug.

More info here: CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

Roman Sannikov, Global Research Coordinator, iCOUNTER said this:

“Microsoft patched CVE-2026-55040 in July. Rapid7 published a full technical write-up and working exploit code today, and Defused was already seeing that exact code hit its honeypots the same day. Hours passed between a researcher publishing proof-of-concept code and someone using it against real targets. No group has been identified yet, which tracks, at this stage it’s likely opportunistic scanning off the public PoC rather than a targeted campaign. This is exactly the kind of flaw that matters more as companies move away from plain passwords. CVE-2026-55040 breaks the token validation that’s supposed to replace passwords in the first place, and we’re seeing threat actors go after tokens and other forms of MFA directly instead of trying to phish or guess a credential. The bigger pattern is worth focusing reporting on: this is the second separate on-prem SharePoint flaw in the news this week. The story now is how many separate ways into the same platform are surfacing at once.”

This is fixed and people should update all the things. That would mitigate this issue completely. Otherwise pwnage will be guaranteed.

Half of UK tech leaders say outages threaten revenue

Posted in Commentary with tags on August 12, 2026 by itnerd

Research published by Zen Internet found that half of UK technology leaders believe network outages threaten revenue. The study surveyed 500 senior technology decision-makers across the UK.

The findings point to wider concern about the role of network resilience in business performance. More than half of respondents, 51%, said resilience was business-critical and that outages would significantly affect revenue, operations or customers. A further 94% said resilience was important to their organisation’s success.

Many technology leaders also said complexity within their IT estates was slowing change. Zen found that 78% said technology complexity was holding back transformation, with multiple vendors, platforms and contracts cited as major obstacles.

You can read the full story here: https://securitybrief.co.uk/story/half-of-uk-tech-leaders-say-outages-threaten-revenue

Commenting on this, Mayur Upadhyaya, CEO at APIContext, said: 

The fact that half of UK technology leaders now see outages as a threat to revenue shows how closely digital resilience and business performance have become linked.

Complexity doesn’t come from the number of systems you have. It comes from the number of dependencies between them. A payment, customer journey or identity transaction can cross multiple APIs, cloud services and third parties before it completes, and organisations don’t always have visibility across that entire chain.

AI and agentic adoption add another dimension. Increasingly, machines are executing those transactions, making decisions and retrying when something degrades. Machines can fail silently, and they fail at machine speed. That means a small degradation can propagate through dependent systems before an operational team even knows there is a problem.

The answer isn’t to slow innovation. It’s to recognise that resilience now means continuously verifying the critical transactions the business depends on, not simply monitoring the individual systems underneath them.”

Outages cripple or kill companies. So stopping outages should be the priority or bad things will happen.