Trump announces new federal “AI Force” as industry leaders raise concerns about AI risks

Posted in Commentary with tags on September 21, 2026 by itnerd

President Donald Trump has announced plans to create a new federal “AI Force” focused on artificial intelligence, according to The Wall Street Journal.

Trump compared the initiative to the creation of the U.S. Space Force and said he will appoint a new AI czar. The administration has not yet disclosed how the AI Force will be structured, funded or what specific authority it will have.

The announcement comes as AI executives call for additional safety measures. Trump has opposed broad new restrictions on AI development, arguing that existing criminal and civil laws can address harmful uses of the technology.

Doc McConnell, Head of Policy and Compliance, Finite State:

“Let’s not overcomplicate the question of AI regulation. In every other sector of the economy, we hold manufacturers accountable for the safety of what they build: toys, houses, cars. There’s no reason AI should be the exception. Today, what clouds the debate over accountability is that there are multiple actors: the frontier labs that train the models, the companies that deploy them, and the users who prompt them and act on the outputs. That gives everyone a reasonable-sounding excuse. The lab claims that a deployer failed to sandbox the agent, the deployer blames a reckless user, and the user says the underlying model was flawed.

“To ensure that these models are fundamentally safe, there must be meaningful liability for the frontier labs. This liability should apply to the doomsday scenarios we’re hearing about today, like biological agents or cyber attacks against real-world infrastructure. But it should also apply to the harms that we’ve already seen play out: the creation of child sexual abuse material, or the contributions of chatbots to self-harm and suicide. And the liability must be strong enough to counterbalance the enormous commercial incentive for labs to build faster, more responsive, more autonomous models.

“And there can be no compromise to our existing anti-discrimination protections in fields like healthcare and housing. AI is a tool, used by people. Those people must remain accountable for the fair and equitable outcomes of their work, no matter what tools they choose to use.”

Denis Calderone, CTO, Suzu Labs:

“Workable regulation is whatever survives an administration that doesn’t want to regulate, and that narrows it fast to two things, mandatory incident disclosure and clear liability for real-world harm.

“Self-reporting fails for the same reason the SEC has mandatory disclosure and OSHA runs inspections instead of waiting for companies to mail in hazard reports, because the organization with the most to lose is the worst one to decide what the public hears.

“Put people with real security experience in the room. The people who’ve actually built, broken, and hardened production systems, who’ve worked a breach and had to explain to a customer what happened to their data, should be designing these tests and reviewing the findings.”

This isn’t nearly enough as we have AI escaping places right left and center. That required a more substantial response. This isn’t it and the Americans will pay for it. Mark my words.

Hackers manipulate operational systems at Colorado water utilities

Posted in Commentary with tags on September 21, 2026 by itnerd

Foreign hackers breached operational technology systems at two private Colorado water utilities in late August, according to a spokesperson for Colorado Governor Jared Polis who spoke to The Denver Post.

The attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles at the facilities. Officials said the incidents were brief and quickly addressed. Treatment processes, water quality and public safety were not affected.

The CISA said more than 100 internet-exposed water systems were targeted in July, with activity focused on OT including programmable logic controllers.

John Strand, Owner, Black Hills Information Security:

“I think everything happening with AI is absolutely important, and people should be paying attention to it. But I truly feel like the AI news cycle has completely overwhelmed the targeting of critical infrastructure in the United States.

“For a long time, it seemed like many nation-states were avoiding direct attacks against critical infrastructure, at least at the rate we’re seeing now. It increasingly feels like the gloves are off. We’ve seen municipalities disrupted by cyberattacks, and we’re seeing water and other critical infrastructure targeted and compromised.

“This isn’t something critical infrastructure operators can fix overnight. Many of the security programs these organizations need take months, sometimes years, to properly implement. We were caught flat-footed. We need to start taking action now, because building that defensive capability is going to take time.”

Damon Small, Board of Directors, Xcape Inc.:

“Direct manipulation of operational technology in critical infrastructure threatens physical reliability, regulatory compliance, and public trust long before water quality is compromised. Cyberattacks against Colorado water utilities highlight a distinct shift in state-sponsored tactics, moving past initial proof of concept access to actively probing operators’ response capabilities. Despite many critical changes having been made to remote access, alerting, and pump cycles, the human operators detected the anomalies and responded quickly, mitigating the incident.

“Broad access to Internet-exposed programmable logic controllers is now an established reality, making the central threat no longer whether adversaries can gain unauthorized entry, but how rapidly the victim organization contains the breach once inside. Security leaders must move past basic perimeter defense by removing control interfaces from the public Internet, enforcing multi-factor authentication across all remote access gateways, and isolating industrial control networks behind strict firewalls.

“Critical Takeaways

  • Adversaries have escalated from opportunistic probing to evaluating operational incident response capabilities in real time.
  • Despite attackers altering critical configurations, rapid human detection prevented physical impact, highlighting the necessity of agile response.
  • Executives must enforce strict network segmentation, eliminate direct remote management, and isolate industrial control panels behind multi-factor gateways.

“Proving adversaries can break in is old news; the real test is whether your team can kick them out before the pumps change cycles.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“A utility serving fewer than 200 people cannot fund a security engineer. Foreign actors hit two private Colorado water plants that size in late August, changed pump cycles, disabled alarms, and cut remote access the on-call operator relied on to check the plant. Governor Jared Polis’ office says treatment and water quality held after the providers drove out and reset the controllers.

“Minnesota was July, the Cybersecurity and Infrastructure Security Agency (CISA) counted more than 100 internet-exposed water targets the same month, and Colorado was August. Controller-focused hits on U.S. water are common enough now that defenders should execute CISA’s July guidance on internet-facing programmable logic controllers (PLCs), inventory external access, and pull anything you cannot actively monitor offline.

“OpenAI’s Daybreak for Frontline Defenders and the OpenAI-led industry letter on critical infrastructure both try to put AI on the defender’s side for water utilities. I want that help aimed at plants like these. Model credits only matter if someone on payroll can review a change to a live treatment process without breaking it, which is why the Multi-State Information Sharing and Analysis Center (MS-ISAC) training piece in Daybreak matters as much as the subsidy.

“Federal funding should cover those salaries first, then stack the private-sector offers on top. The pacing from Minnesota to Colorado says defenders should plan for the next wave now.”

While this is a priority of a bunch of priorities, this is big and needs attention ASAP. Because this is already trending in a bad direction.

Google confirms Gemini autonomously hacked three companies

Posted in Commentary with tags on September 21, 2026 by itnerd

Google has confirmed that its Gemini AI accessed the systems of three real companies while undergoing cybersecurity testing, according to The Wall Street Journal.

The incidents occurred in May during “capture the flag” cybersecurity evaluations run by third-party testing company Irregular. Gemini was supposed to retrieve information from systems belonging to a fictional company inside the test environment, but the model was unintentionally given internet access and encountered real companies while attempting to complete its task.

In one case, Gemini guessed a password and successfully entered a protected system. In two other test runs, it searched the internet, found credentials exposed in public repositories and used them to access systems belonging to two additional companies. Google said Gemini stopped the intrusions after recognizing that it had accessed real systems rather than test environments.

Google said all three affected companies were notified and that no harm resulted. Irregular notified Google about the incidents in late July, but Google did not publicly disclose them until the Wall Street Journal contacted the company in September.

John Strand, Owner, Black Hills Information Security:

“The more I see these breaches happen again and again, and the less I see organizations learning from each other’s mistakes, the more I’m convinced that some of this is becoming a marketing ploy. Frankly, I hope that’s what it is, because if these agents really are repeatedly escaping their controls, then we have much, much larger problems.

“That said, if you look at the attack paths being disclosed, these agents don’t appear to be inventing novel zero-days or entirely new categories of exploitation. They’re doing a lot of the same basic exploitation that a standard penetration testing team would do. So we’ll have to see how this develops.

“But I keep coming back to accountability. Companies deploying autonomous agents need to be responsible for what those agents do. If an agent accesses systems it has no authorization to access, we need to seriously examine liability under laws such as the Computer Fraud and Abuse Act. ‘The AI did it’ cannot become a shield from responsibility. If your company deploys the agent, your company should be accountable for its actions.”

Ryan McCurdy, VP of Marketing, Liquibase:

“Gemini tried to complete the task it received and ended up accessing systems its operators never intended it to reach.

“That problem gets much bigger as AI starts participating across the SDLC. Agents can write code, interact with repositories and infrastructure, initiate deployments, and make changes to production systems. The more access we give them, the more important it becomes to control what they can actually do.

“We can’t rely on an agent to recognize after the fact that it crossed a line. Organizations need to define what an agent can access, what it can change, and what policies it must meet before a change reaches production.

“We shouldn’t expect AI agents to make the right decision every time. We need to build the AI SDLC so a bad decision doesn’t automatically become a production problem.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Google just joined Anthropic, OpenAI, and Meta in admitting that a model it was running logged into other people’s systems during a cybersecurity evaluation. Claude hit three real companies. OpenAI’s agents reached Hugging Face. Gemini guessed a password and used leaked credentials against three more. For anyone outside these labs, that is a felony under the Computer Fraud and Abuse Act (CFAA).

“An agent given a name collision and a path to the internet treats the real company as the challenge. I have watched my own pentest agents pull Domain Name System (DNS) records, find similarly named domains, and decide those hosts belong in scope. They chase the objective. They will try the keys they find.

“The controls that hold sit outside the model’s reasoning. Deny-by-default egress so a test host cannot reach production even when someone leaves a route open. An immutable scope file that blocks any host not on the list, including the real firm that happens to share the fake one’s name. A human in the loop system who signs off before a guessed password or a leaked credential is used. I run those hooks on my own offensive tooling because the agent will enlarge its own scope and reason around controls if you let it.

“Executive Order 14409, signed June 2, told the Department of Justice (DOJ) to prioritize 18 U.S.C. 1030 cases against anyone who uses AI, including autonomous agents, to access a computer without authorization. The model is the tool. The operator is the defendant.

“Google, Anthropic, OpenAI, and Meta get an evaluation-mishap press line. Everyone else gets the charging memo the White House asked DOJ to write. If my pentest agent guessed a password into a company that was never on the scope sheet, I would be hiring counsel that afternoon.

“They have already confessed in public. Nothing will happen. These firms have a stranglehold on the economy that no case against them is going to survive, making the double standards in the justice system excruciatingly obvious”

First OpenAI, now Google. That has to make you wonder if the rest are failing to admit something. And you have have ask if the breakouts are worse than they anticipated. That’s absolutely a problem that is only going to get worse if no regulation on AI happens and happens soon.

LittleHorse Saddle Command Center Delivers the Missing Action Layer for Orchestrating AI Successfully Using the Business-as-Code Paradigm

Posted in Commentary with tags on September 21, 2026 by itnerd

LittleHorse Enterprises today announced Saddle Command Center 1.3, a major new release that uses the Business-as-Code approach to enable business teams and engineers to work at a higher level of abstraction while creating and deploying AI applications. The platform provides an action layer that bridges business requirements and code, enabling organizations to orchestrate, stream, connect and govern the agents and microservices that power modern applications.  

New capabilities in Saddle Command Center 1.3 include easy AI agent creation, pre-built task workers and agent skills, a Javascript SDK for developers, and a new free serverless offering for easy trial.

A Founder Story Rooted in an Enterprise Infrastructure Problem

LittleHorse was founded in 2022 by Colt McNealy after working as a software engineer and stitching together complex business processes across mortgage, insurance, scheduling and operations systems. He saw firsthand how enterprise workflows required custom integrations, brittle code and constant rework, leading him to conclude that enterprises had an orchestration problem long before AI agents arrived. AI did not create the problem, rather it exposed and amplified it, making the need for a better abstraction layer impossible to ignore. That insight became LittleHorse and its Business-as-Code approach to orchestrating people, applications and AI agents within governed, observable business processes.

Colt’s vision ultimately convinced his father, Scott McNealy, the longtime co-founder and former CEO of Sun Microsystems who spent decades helping define enterprise infrastructure, that enterprises had a foundational orchestration problem that AI agents would ultimately expose and amplify in ways existing orchestration and workflow platforms were not designed to address. Scott backed LittleHorse himself and currently serves as advisor. The company has been in production with enterprise customers for more than 18 months.

New Free Serverless Trial Offering Lowers the Barrier to AI Application Development

The new free serverless trial offering makes it easier for startups and teams to experiment, create new applications, and test ideas without the burden of setting up and managing infrastructure.  The offering enables users to get started with LittleHorse and immediately begin orchestrating, streaming, connecting and operationalizing their applications. Saddle Command Center supports developers working in Java, Python, Go and C#, and 1.3 adds a complete Javascript SDK developers who prefer the language.

An Action Layer for Business-as-Code

LittleHorse Saddle Command Center provides an end-to-end platform for implementing Business-as-Code, enabling organizations to translate business processes into executable workflows, while maintaining alignment between business requirements and code. The platform provides the action layer needed to orchestrate, stream, connect and govern agents, microservices and events. This allows organizations to build cross-domain applications while managing the complexity of distributed systems and AI-powered workflows. 

Developer outcomes from using LittleHorse include faster deployment of new services, reduced SaaS costs, successful integration of AI agents, less time wasted tracing failures in brittle systems, and the ability to integrate real time data flows across the enterprise.

Saddle Command Center 1.3 is available now.

Are modified AI agents better at hacking?

Posted in Commentary with tags on September 21, 2026 by itnerd

New research from Tracebit has just been released assessing whether modified, openweight AI agents are better at hacking and see if you want to see it under embargo? The key points are: 

  • Criminals increasingly talk about modifying openweight models but surprisingly the ‘abliterated’ configurations were 9x less effective at hacking – Tracebit found they reached administrator privileges in 2.3% of runs, compared with 20.5% for the original model, across 82 runs.
  • The abliterated version is also slower – it took 92% longer overall to reach their first critical action (59.3 minutes versus 30.9).
  • Previous research found that inserting political sensitive content (such as mentioning Tiananmen Square) into security canaries (decoy resources) stopped Chinese models and inserting info biological weapons stopped leading Western Models
  • But the above didn’t work against Qwen so Tracebit devised a new payload using prompt injection to tell the attacking agent to halt – this did work against Qwen and an obliterated version

You can read more here: https://tracebit.com/blog/context-bombs-against-abliterated-ai-models

Securonix Uncovers Windows Backdoor That Enables Continuous Document Theft

Posted in Commentary on September 21, 2026 by itnerd

Securonix Threat Research has released new research on TASK#STOMP, a Windows backdoor designed to maintain long-term access and continuously steal business documents. The malware targets files across every fixed drive, monitors for new or modified documents and gives attackers ongoing remote access to the infected system.

Key findings include:

  • TASK#STOMP combines scheduled tasks, a Startup-folder launcher and rotating Windows-style task names to maintain persistence and evade detection.
  • Two PowerShell modules provide redundant command-and-control channels and can steal documents, saved Wi-Fi passwords and clipboard contents, capture screenshots and execute remote commands.
  • Its full capabilities may be missed in endpoint telemetry, but the broader chain of script execution, task creation, timestomping and runtime compilation provides defenders with strong detection opportunities.

You can read the research here: https://www.securonix.com/blog/task-stomp-powershell-backdoor-document-theft-remote-access

What European IT teams say about application management: Recast

Posted in Commentary with tags on September 21, 2026 by itnerd

There is new research from application management provider Recast Software. Recast surveyed over 100 IT professionals at European community and industry events between January and June 2026 about application management priorities. Respondents included sysadmins, endpoint engineers, packagers, architects and IT managers.

A few interesting findings:

  • 53% cite application security and compliance as a top challenge, while 51% cite managing application updates and patches
  • 44% expect changes to their VDI/SBC environment within the next 12 months, and 70% expect change within a defined timeframe
  • 85% use Microsoft Intune, while 32% also use Configuration Manager
  • 47% are open to exploring new application management solutions

The full report, “The State of Application Management: What European IT Teams Told Us,” is available here:
https://www.recastsoftware.com/resources/state-application-management-what-eu-it-teams-told-us/.

Privacy Policies Of Router Companies Analyzed By Cybernews

Posted in Commentary with tags on September 21, 2026 by itnerd

Cybernews has a study they’ve just released analyzing the privacy policies of leading router brands. We examined what user data these companies disclose collecting and what their policies leave unclear.

Here are the most concerning things we found after analyzing the privacy policies of 25 leading router brands:

Pre-purchase transparency is blocked 

Because relevant privacy terms are often inaccessible until after purchase, registration, or setup, consumers cannot make informed privacy decisions before buying.

Catch-all policy increases legal ambiguity 

High-risk-scoring brands like D-Link, Omada, and Wyze performed poorly largely due to overly vague, corporate-wide policies that create legal ambiguity around network monitoring.

Universal DNS opacity

All 25 analyzed vendors (100%) received a Not Specified rating for DNS request logging, failing to confirm or deny whether they record the domain names users visit. Given that DNS is one of the most revealing signals a router can log (it’s basically a timestamped list of every site a user visits), providers seem rather too ambiguous about it.

Pervasive geolocation exposure

Zero analyzed brands explicitly rule out tracking precise device location (7 confirm doing so outright, 6 do it conditionally, while 12 fail to specify), and 92% (23 of 25) either partially confirm or fail to disclose whether they harvest nearby Wi-Fi network identifiers (SSIDs/BSSIDs). Ultimately, this opens the door to highly invasive physical location tracking.

The full report is available here: 

https://cybernews.com/privacy/router-privacy-index-2026-industry-wide-transparency-failures-exposed

GM Begins To Bring Back Apple CarPlay And Android Auto

Posted in Commentary with tags on September 20, 2026 by itnerd

Well this is a shock. Actually this isn’t a shock. Remember when GM tried to kill Apple CarPlay and Android Auto in its EVs? Then it tried and failed to justify the move? Twice? Well it’s back:

GM is bringing Apple CarPlay and Android Auto back to its vehicles, reversing one of the more unpopular decisions in the automaker’s recent history.

The company this week unveiled a new infotainment interface, debuting on the 2027 Chevrolet Silverado and GMC Sierra pickups, that folds smartphone projection back into the dashboard and runs alongside GM’s native system.

And:

GM justified the move, claiming it would address clunkiness when switching back from CarPlay to the vehicle’s own infotainment system, but in reality, GM wanted to keep all the data it was getting from its users.

No GM. It’s not the clunkiness. It’s the fact that likely your sales have fallen through the floor given that Android Auto and Apple CarPlay were not part of the deal. Not that I am the gold standard for anything, but my wife and I were looking at EVs and GM products were off the list because they didn’t have Apple CarPlay and Android Auto. But don’t take my word for it. Take GM dealers word for it:

The backlash was immediate, and the data was brutal. Surveys at the time found 79% of new-car buyers would only consider a vehicle that offered CarPlay, and that it was available on 98% of new cars sold. Dealers warned buyers would simply walk to a rival showroom.

“CarPlay’s not broken. Why fix it?” dealer sources told the Detroit Free Press. Industry analyst Karl Brauer predicted to Yahoo Finance that the move would “backfire.”

Well it’s backfired. And I have to admit that this may not get us into a GM showroom after they’ve reversed it. The fact that GM has tried to kill Android Auto and Apple CarPlay so casually says a lot about GM and how little they think of customers. And my wife and I will not forget that. Ever.

The bigger lesson from the Brevo supply-chain attack

Posted in Commentary with tags on September 19, 2026 by itnerd

If you have heard of the Brevo supply-chain attack, you can skip to the next paragraph. If not, here’s a quick primer:

https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/

Jacob Krell with Suzu Labs says the incident is another example of how compromising a trusted vendor, embedded script or API key can quickly extend the impact across its downstream customers. He also points to the growing attack surface created by long-lived credentials used by AI agents and stored in MCP configurations.

Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity (https://www.linkedin.com/in/jacob-krell)

“The same supply chain pattern keeps repeating in the news at a seemingly increasing rate. Compromise one trusted vendor, one embedded script, or one API key, and you inherit every customer downstream. Agentic AI work is widening that surface because every agent ships with long-lived tokens for Cloudflare, Amazon Web Services (AWS), email, ticketing, and source control, usually parked in Model Context Protocol (MCP) configs on hosts we still do not inventory like developer laptops.

“Brevo is the latest example of how fast that fans out. Attackers used a hardcoded Cloudflare API key with full account permissions to deploy a Worker that rewrote JavaScript at the content delivery network (CDN) edge for the email and marketing platform’s sites and for the forms and SDK loader files customers embed on their own properties. Origin files never changed, so integrity checks stayed green while the Worker stripped Content-Security-Policy headers on the way out. For about five and a half hours on September 14, selected visitors got ClickFix lures dressed as Cloudflare verification, and logged-in WordPress administrators could receive a silent plugin that survived after Brevo tore the Worker down.

“I’m seeing attackers skip the application and go straight for the credential that can rewrite what customers already trust. I would map every API key an agent can reach with the same rigor you map third-party JavaScript on your homepage, because Brevo just showed you do not need to breach the vendor’s app to own the blast radius.”

Supply chain attacks are preventable. The discipline to not trust those around you and check everything that you rely on is a big reason why they don’t work. All that is needed to exercise that discipline.