Shark robot vacuum flaw exposes fleet-wide IoT risks

Posted in Commentary with tags on July 22, 2026 by itnerd

Security researcher “tokay0” recently published a serious vulnerability affecting Shark robot vacuums. A certificate extracted from one compromised Shark robot vacuum could be used to access other devices, exposing live camera feeds, stored home maps and Wi-Fi credentials held in plaintext. During a 24-hour observation, the researcher identified more than 1.5 million Shark serial numbers in one AWS region, with approximately 674,000 devices responding to a command probe.

Edwin Shuttleworth, Lead Penetration Tester and Security Researcher at Finite State, offered the following comments:

   “This is a classic authentication-versus-authorization failure. The certificate issued to each device correctly authenticated the holder of that device’s private key. An attacker who had fully compromised a vacuum could extract the key and authenticate as that legitimate device. The cloud backend, however, did not correctly enforce authorization. As a result, a validly authenticated device was permitted to access data and perform actions involving other devices it should not have been able to reach.

   “This is a common security design mistake: treating a successfully authenticated identity as broadly trusted instead of applying narrowly scoped, per-device permissions. Security professionals reviewing IoT systems should verify both that device identities are unique and that each identity is restricted to its own resources and required operations.

   “Manufacturers must assess the complete connected-product environment because the most serious vulnerabilities often arise from interactions between multiple layers rather than a single isolated flaw. This case illustrates that clearly. Weaknesses in the device’s boot and debug protections allowed an attacker to obtain privileged access to the vacuum and extract its credentials. Those credentials were then accepted by the cloud service and granted access to MQTT resources belonging to other devices. Finally, dangerous command-handling functionality allowed cloud-delivered messages to result in remote code     execution.

   “Individually, each weakness might have appeared limited. Together, they created an attack chain that turned the compromise of one physical device into a potential fleet-scale compromise. Testing firmware, cloud permissions, credential storage or backend infrastructure only in isolation could therefore miss the true severity of the vulnerability.

   “Manufacturers should avoid storing sensitive information that is not necessary for the device’s function or business operations and should avoid transmitting sensitive information to the cloud when it is not needed. When information must be transmitted, robust encryption should be used to prevent access by unauthorized parties. Security testing must also be performed early and regularly to prevent compromises like this and minimize their impact when they occur.”

This is precisely why I am working towards making all of my IoT gear, of which I don’t have a lot, not talk to the Internet. My concern is that I don’t know who they are talking to. That is a huge problem as evidenced by this report.

95% of security teams are finding critical vulnerabilities their scheduled tests missed

Posted in Commentary with tags on July 22, 2026 by itnerd

Synack recently released a new survey of enterprise security teams and found that 95% discovered a high or critical vulnerability outside their scheduled testing window in the past year, with 42% saying it happens at least monthly, no breach required to expose the gap, no dramatic incident, just the ordinary rhythm of scheduled testing failing to keep pace with how fast environments actually change.

You can read the press release here: New Synack Research: The State of Continuous Security Validation

Brian Proctor, Founder and CEO, Frenos

“Finding critical vulnerabilities outside scheduled tests is the new norm. AI has pushed time-to-exploit toward zero, and no security team can continuously run live exploitation without breaking things. Nowhere is that more true than in OT and critical infrastructure, where live testing is a non-starter. Simulation against a digital twin of the environment is the only path to continuous, high-confidence validation of what’s actually exploitable. The real red flag in this data isn’t the 95%; it’s that only 15% of organizations are validating continuously.”

If you’re not testing, or testing frequently enough, then you aren’t protected. It is that simple. I would strongly recommend that all organizations increase their testing as part of their broader plan to stay secure.

OpenAI confirms Hugging Face breached by rogue AI Agent 

Posted in Commentary with tags on July 22, 2026 by itnerd

OpenAI has disclosed that one of its frontier systems autonomously escaped a testing environment and compromised Hugging Face. This is the first public demonstration that frontier AI can execute a complex, end-to-end cyberattack across multiple environments with minimal human intervention.

CBC News has some details: OpenAI model went rogue, hacked another company’s system during testing | CBC News

The ChatGPT creator was testing capabilities of some of its most advanced models in a controlled environment, but the agent escaped containment, reached the internet and broke into Hugging Face to satisfy its testing goal.

The incident signals how AI’s expanding capabilities are already fuelling fears about security and that even top developers can ​be caught off-guard by flaws their models can exploit.


Sonali Shah, CEO, Cobalt had this to say:

“This was inevitable. Every security leader has understood for some time that AI would eventually move beyond automating individual attack tasks to autonomously executing an entire attack lifecycle. This is the first public demonstration of that happening across multiple environments. The lesson for defenders is that the window between vulnerability discovery and exploitation is collapsing even further. Organizations should assume attackers will increasingly operate at machine speed, which means security testing, exposure management and remediation also have to operate at machine speed.

The attack techniques are not new. We’ve had tools capable of chaining attacks for over a decade. What’s different is that AI is removing many of the human validation steps that previously governed how those tools were used. That makes strong guardrails and human oversight more important than ever.

What escaped here was an autonomous offensive capability operating toward an objective. One analogy to illustrate this is giving an exceptionally skilled penetration tester unlimited patience, unlimited time and the ability to execute thousands of attack steps every minute. The concern is that the agent remained relentlessly focused on its objective and discovered attack paths humans hadn’t anticipated. That’s fundamentally an engineering, governance and containment challenge, not evidence of malicious intent. As organizations adopt increasingly autonomous AI systems, they need the same validation controls we’ve relied on for years in offensive security. Human oversight can’t disappear simply because AI can execute faster.

The biggest takeaway is that defenders increasingly need AI capabilities comparable to the attackers they’re facing. Historically, every organization could buy roughly the same security tooling. We’re now entering an era where the quality of your defensive AI may directly determine how quickly you understand, contain and remediate an attack. Perhaps the more significant lesson is that incident response can’t depend entirely on cloud-hosted AI services whose safety guardrails may prevent effective forensic analysis during a crisis.

Organizations should have vetted AI models they can operate inside their own trust boundary before an incident happens. That said, better models alone aren’t enough. AI for cybersecurity is still maturing, and organizations shouldn’t blindly trust autonomous systems. Every security leader wants the speed and scale AI delivers, but they also want humans to retain accountability for validating targets, approving attack paths and verifying results. You need both AI and humans.”

The genie is now out of the bottle. You can fully expect that AI will be used to attack you. So you should plan accordingly.

SOCRadar launches wp2shell exposure checker 

Posted in Commentary with tags on July 22, 2026 by itnerd

SOCRadar has launched a free wp2shell checker to help organizations quickly determine whether their WordPress websites may be exposed to CVE-2026-63030, a critical remote code execution vulnerability affecting recent WordPress versions.

The tool allows users to enter a domain and assess potential exposure without manually reviewing WordPress versions or configurations—particularly useful for organizations managing large numbers of public-facing, subsidiary, staging or forgotten websites.

The checker is designed to help security teams:

  • Quickly identify potentially exposed WordPress assets
  • Verify whether automatic WordPress updates were successfully applied
  • Prioritize vulnerable or overlooked sites for remediation
  • Reduce the risk posed by unknown WordPress installations across the external attack surface

SOCRadar has also published a supporting technical analysis explaining how the wp2shell vulnerability chain can lead to unauthenticated remote code execution, which WordPress versions are affected and what defenders should look for in their logs.

You can access the checker and analysis here:
https://socradar.io/blog/wp2shell-wordpress-rce-cve-2026-63030/

Chick-Fil-A breach exposes customer payment info 

Posted in Commentary with tags on July 22, 2026 by itnerd

The popular U.S. fast food chain Chick-Fil-A sent this breach notification to an undisclosed number of affected customers: “Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source. Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your Chick-fil-A One account.”

The customer’s membership number and mobile pay number, QR code and last four digits of their credit/debit card number were exposed, and were the customer’s customer birthday, phone number, and address if the member provided those to Chick-Fil-A.

Ted Miracco, CEO, Approov:

“The advent of AI powered attacks makes it more important than ever for companies who serve consumers through mobile apps to thwart attempts by attackers to bombard their back end login APIs via automated bots, malicious scripts, or modified apps. Automated attacks will only accelerate going forward, so to protect their customers and themselves, security hygiene dictates that servers should only accept requests from genuine, untampered mobile apps that are running on safe devices.”

John Strand, Owner, Black Hills Information Security:

“First, are we just going to walk past the fact that Chick-fil-A was compromised through a credential stuffing attack? There are probably a hundred jokes we could make about that, but the security lesson is much more important.

“Credential stuffing sits in one of those gray areas that many organizations never fully test. Most companies hiring a penetration testing firm don’t want testers launching credential stuffing attacks against production systems, and in many cases that’s the right decision. You don’t want a security assessment accidentally accessing legitimate customer accounts, especially in highly regulated industries like financial services where the legal and compliance risks can be substantial.

“The problem is that attackers don’t care about those boundaries. Organizations still need to validate that they’re resilient against these attacks, whether that’s through controlled password spraying, testing for account enumeration, or simply requiring multi-factor authentication for customer accounts. I understand the hesitation around requiring MFA because of concerns about user friction, but if MFA isn’t enabled, credential stuffing remains one of the easiest ways for attackers to compromise accounts at scale.

“Security teams need to pay close attention to the areas that often go untested, either because of legal concerns or internal politics. Those gray areas are exactly where attackers tend to find their opportunities.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Credential stuffing works because most organizations treat account authentication as a solved problem. The credentials used here came from a third-party source, which means Chick-fil-A’s own security controls were likely functioning exactly as designed, and the attack succeeded anyway. When attackers can walk in with valid credentials, the question every organization with a loyalty program or mobile account layer should be sitting with is how many of their active users are also active in a breach database somewhere.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

“This incident reflects how automation is changing attacker economics, making even secondary customer applications attractive targets at scale.

“Companies should assume that every internet-facing system with an authentication page will be tested continuously. Security standards cannot fall sharply simply because an application generates less revenue or appears less operationally critical.

“Credential stuffing is not a sophisticated or novel attack, but it remains effective at scale. Organizations should adopt phishing-resistant authentication, including passkeys where appropriate, alongside layered controls to detect and resist automated attacks. They should also minimize the data and value held in secondary applications so that a compromised account has less to expose or steal.”

Corporations like Chick-Fil-A need to take a breach like this as the worst thing ever. Yes it was credential stuffing. But it is still a big deal because it affects the reputation of Chick-Fil-A. Period.

Guest Post: A 20-Year-Old IoT Vulnerability Is Still Shipping in a 2026 Home Camera

Posted in Commentary with tags on July 22, 2026 by itnerd

A home security camera has one job: to keep watch over the places people care about most, the nursery, the front door, the shop floor after hours. A buyer also places quiet trust in every company that had a hand in that camera’s software, almost none of them visible from outside the box.

Finite State recently tested one such camera, a popular budget model, and found the trust misplaced deep in the device’s software. Inside was a serious flaw, first disclosed in 2002, exploitable over the network by anyone who could reach it, and still shipping in units sold in 2026. The camera’s maker, Wansview, fixed the problem thoroughly once notified. The harder question is how it went unseen for so long, and how many comparable devices carry problems no one has thought to look for.

We needed a device for testing, and the only requirement was that an ordinary person could actually buy it. A cheap, well-reviewed camera with steady sales fit, so we pulled its firmware and traced what was running and what it could reach. The flaw was not obscure. A single check of the web server against public vulnerability data would have surfaced it, and no one in the supply chain had run that check before the camera reached people’s homes.

Wansview sells the WVC Q5 as a baby monitor, a pet cam, and a home security device, a low-cost indoor model of the sort that ends up sharing a home network with laptops, phones, and everything else in the house. Buried in its firmware, the software that runs the device, sat a small, long-forgotten web server named jdbhttpd/0.1.0, and inside that server lived CVE-2002-1819, a directory traversal flaw that let anyone on the same network pull private files off the camera without so much as a password.

Age alone rarely determines risk. Outdated components turn up in shipped firmware constantly, and most never matter, because the vulnerable code sits where the device never reaches it. This flaw was the exception, dangerous on the very dimensions that usually keep such bugs harmless. Any device on the network could reach it, and the process it ran in could read every file on the system. The flaw had also moved through the entire supply chain unexamined, from the platform vendor to the brand that relabeled the camera to the retailer that sold it, and none of them recorded it or checked it against a public advisory two decades old.

How One Directory Traversal Flaw Unlocked the Whole Camera

The flaw itself is a directory traversal, a bug security engineers see often and rank as moderate, where a web server returns files from outside the folder it is meant to serve. The camera’s server built the path to each requested file straight from the incoming web request and never checked that the result stayed within that folder. A path stuffed with ../ sequences therefore climbed out of the web root and reached arbitrary files elsewhere on the device, with no password, no login, and nothing but a single HTTP request that any host on the network could send.

What made it dangerous was privilege. The server’s only purpose was to serve saved video images, yet it ran with permission to read every file on the device, and that mismatch handed an attacker the run of the whole system. A handful of requests pulled back the most sensitive material on it:

  • The system password and the administrator login, the latter left at the factory default of admin:123456, which unlock the device directly and, given how often passwords are reused across a home network, frequently everything else on it.
  • A cloud access token, which logs straight into the manufacturer’s servers, where the live video feed and device settings sit. The footage from a nursery or a front hallway is on the far side of it.
  • A copy of the web server program, which moved the rest of the work offline.

The program file proved the most valuable of the three. Pulled apart offline, it revealed two more ways into the camera, each an unauthenticated request that crashes the device on command, and each aimed at software built without the ordinary protections that would normally blunt such an attack. The project ran out of time before either could be pushed to a full remote takeover, but nothing about the device stood in the way, and a determined attacker with more time would likely get there.

These flaws are most dangerous in combination. An attacker who starts with one unauthenticated request can finish with the credentials, the cloud account, a reused password, or the camera itself, quietly repurposed as a permanent listening post inside the network. On a flat home or office network beside medical equipmentindustrial controls, or work computers, the reach of that one small device extends to everything around it.

The full research report
This post walks through what we found. The full write-up goes further, with the disclosure timeline, the technical detail behind each finding, and the complete supply-chain analysis.
Read the research report

How a 2002 IoT Vulnerability Ends Up in a 2026 Product

None of this suggests sabotage, and the likely explanation is mundane. Someone building the camera reached for a lightweight, free web server, settled on one that worked, and moved on, most likely without a security review of the choice or any look into the component’s past. Having solved the immediate problem, that developer had no reason to revisit it, and so the web server rode along inside a shipping product for years, unexamined by anyone.

Underneath that is a gap in ownership. Each company in the chain trusted the one before it, and none took responsibility for auditing what it passed along. Nothing about the traversal was hidden or exotic, since it carried a public catalog entry and a freely available exploit the entire time. What was absent was any inventory to test the components against, along with anyone tasked with keeping such an inventory current across the years the product stayed on sale.

The economics of how these devices get built widen the exposure well beyond one product. A white-label device like the WVC Q5 carries a brand that did not build the electronics or write the software inside it. Those come from a platform maker, in this case AjCloud, that produces a base device many brands relabel and sell under their own names, much as store brands roll off the same line as the label beside them. A second manufacturer, IOTECH (Shenzhen) Company Limited, surfaced during disclosure as well.

When a flaw lives in that shared base, it never stays contained to a single product. It ships in every device built on the base, under every logo. Finite State confirmed a fix only on the Wansview unit we tested, so any other product on the same base should be treated as vulnerable until proven otherwise.

The true count is unknown, yet the structure all but guarantees the problem reaches past one brand. The vulnerable web server even makes the affected devices easy to find, since it answers any single request with its own name and version (Server: jdbhttpd/0.1.0), a banner an attacker can scan for at internet scale.

Know What You Ship, Then Prove Which IoT Vulnerabilities Actually Matter

An SBOM would have closed most of this gap on its own. With the components written down, a single query against public vulnerability data flags a 20-year-old known flaw long before the camera reaches a customer, and the failure to write them down is exactly what let this one through. A team cannot patch, monitor, or even weigh a component it has never recorded.

A written inventory is only the first step, and it does not by itself tell a team where the real danger lies. Most of the effort in security goes into counting known vulnerabilities, and most of that count overstates the real threat, because the flawed code usually sits where the device never runs it. Here the pattern reversed, and the camera’s one exposed component, reachable without authentication and running with full privilege, outweighed a thousand entries on a list. What a product contains matters only alongside what an attacker can actually reach, and reachability is where most of the real risk reduction happens.

That combination, an accurate inventory paired with a clear read on what is reachable, is what the Finite State Platform is built to provide. Rather than read the source a team intended to ship, the Platform analyzes the finished software as delivered and identifies the components inside, including the supplier-provided binaries that source-code scanners never see. The result is a ground truth inventory anchored in what actually ships, which then feeds exploitability-based prioritization that ranks findings by what an attacker can reach in a specific build and clears roughly 90% of the noise, so teams spend their hours on the findings that matter. Regulators are moving the same way, and the EU Cyber Resilience Act now requires device makers to keep a current, accurate inventory across a product’s entire service life.

The Right Fix, and the Warning Around It

Wansview handled the disclosure well, and the response deserves as much attention as the flaw. Instead of leaving the unsafe component in place with a patch bolted on, the vendor removed the web server entirely and rebuilt the video feature around a design that no longer exposes the weak point, then delivered the fix to customers automatically over the internet. The update installs on its own whenever a camera is online, so owners had to do nothing to receive it, a better outcome than most consumer devices manage, where unpatched units sit in the field for years because no one thinks to check. That choice, to cut the attack surface out rather than paper over it, is the one the other brands on the same base ought to follow.

A fix on one product does not address the conditions that let the flaw through in the first place. Other brands built on the same base may still be shipping it, and nothing on the packaging tells a buyer either way, which leaves the same obligation on both sides of the sale. Manufacturers should build their software inventory from the device they actually ship rather than from build intentions, keep it current, vet every third-party component for age and support status before it goes in, and put someone in charge of it across the product’s life. Operators should assume they do not know what a device contains and design around that uncertainty, which means a dedicated network segment and no inbound access, since a flaw reachable only over the network is no danger to an attacker who cannot reach it.

A connected device is really an assembly of other people’s code, with the brand serving as a label on the outside. This camera matters precisely because it was ordinary, and ordinary is the problem. The safer posture is to judge a product by what it actually contains rather than by the name on the box, through inventory review and, where the stakes justify it, direct analysis of the shipped software, before the device ever joins a network beside anything that matters. Supply-chain risk is not a threat waiting somewhere in the future; it already shipped, 20 years old, inside a product built in 2026, and catching the next one depends on knowing a product well enough to notice it is there.

See what your firmware actually contains. Book a demo to watch the Finite State Platform break a device’s software down to its components, surface the ones a routine scan never reaches, and rank the rest by what an attacker can actually reach.

Larry Pesce is VP of Technical Research and Offensive Security at Finite State, where he leads firmware and hardware security research on connected devices. This research was conducted by Larry Pesce, Edwin Shuttleworth, and the Finite State security research team.

References

  • CVE-2002-1819, Tiny HTTPd / jdbhttpd 0.1.0 directory traversal (original 2002 disclosure)
  • EDB-42790, Tiny HTTPd 0.1.0 Directory Traversal proof of concept (Touhid M. Shaikh, September 2017)

The complete write-up, with the disclosure timeline and per-finding detail, lives in the research report.

About Larry Pesce, VP of Services, Finite State

Larry Pesce is a lifelong hacker, educator, and leader in embedded and connected device security. As Finite State’s Vice President of Services, Larry drives strategic security initiatives across the software supply chain, helping product teams build resilient devices from the ground up. With over 15 years of hands-on penetration testing experience spanning IoT, healthcare, ICS/OT, and wireless technologies, he combines deep technical knowledge with real-world expertise. Larry is also a renowned SANS instructor and co-host of the long-running Paul’s Security Weekly podcast, shaping the next generation of security professionals.

Samsung unveils newest product lineup

Posted in Commentary with tags on July 22, 2026 by itnerd

New foldable form factor. Smarter AI. More advanced wearables.

That’s what’s coming today as Samsung unveils its newest Galaxy lineup at Galaxy Unpacked in London. The lineup includes new Galaxy Z Fold and Flip devices, including the highly anticipated Galaxy Z Fold8, alongside the latest Galaxy Watches, with pre-orders opening July 22.

To help consumers get the most from their new device, Samsung Care+ offers added peace of mind beyond the standard manufacturer warranty, with convenient service options including same-day walk-in repairs and mail-in service.

Below is a snapshot of what’s new across the lineup:

DeviceKey FeaturesPrice
Galaxy Z Fold8 UltraFor the Life Maximizer The foldable built to replace your laptop. Samsung’s largest, most powerful foldable yet transforms into an expansive 8-inch workspace for multitasking, content creation and Galaxy AI. With flagship performance and a long-lasting battery, it’s designed for people who want to work smarter without carrying more. 256 GB: $2699.99
512 GB: $2979.99
1 TB: $3539.99
Galaxy Z Fold8For the Content Explorers Entertainment and creativity that fits in your pocket. Samsung’s most compact Fold delivers an immersive viewing experience for streaming, reading and browsing, while upgraded cameras, Nightography and Galaxy AI tools like My FanCam make it easier to capture, edit and share standout content. 256 GB: $2399.99
512 GB: $2679.99
1 TB: $3239.99
Galaxy Z Flip8For the Social ExpressersThe AI-powered phone made for creators. Samsung’s Z Flip8 combines an upgraded FlexWindow, smarter Galaxy AI and enhanced FlexCam to help users capture, edit and share content seamlessly. From Semantic Search to hands-free photography, it’s built for always-on creativity. 256 GB: $1549.99
512 GB: $1829.99
Galaxy Watch Ultra2Extreme EnthusiastsAdventure-ready, wherever the journey leads. Built for demanding conditions, Galaxy Watch Ultra2 pairs a brighter display, bigger battery and rugged durability with advanced GPS navigation and safety features like Fall Detection, giving outdoor enthusiasts the confidence to go further. $949.99
Galaxy Watch9Wellness EnthusiastsSmarter health insights for everyday life. Galaxy Watch9 puts personalized wellness at the forefront with sleep apnea detection, heart health and daily health insights, helping users better understand their health while making everyday interactions more effortless through intelligent, hands-free features. 40 MM Bluetooth: $519.99
44 MM Bluetooth: $559.99
40 MM LTE: $599.99
44 MM LTE: $639.99

Lookout Announces Mobile Software Exposure Center (MSEC)

Posted in Commentary with tags on July 22, 2026 by itnerd

Lookout today announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Delivered as a core integrated capability within the Lookout Mobile Endpoint Security (MES) platform, this new solution allows organizations to continuously identify, assess, prioritize, and manage software exposure risk across their mobile environments.

The market availability of frontier AI models, such as Anthropic’s Claude Fable 5 and Mythos 5, marks a critical inflection point for cybersecurity. AI has rewritten the economics of offensive cyber operations by compressing exploit discovery and vulnerability analysis from months of specialized human research into hours at minimal cost. Security experts anticipate an imminent “Zero-Day Flash Flood” where automated, offensive AI tools target unexamined code.

While enterprise security tools exist to handle software vulnerabilities, they are built for traditional desktop and cloud environments. They completely overlook modern mobile applications, which are assembled as a complex patchwork of open-source libraries, embedded SDKs, and third-party APIs. This creates a critical software exposure gap that legacy cybersecurity tools and Mobile Device Management (MDM) platforms cannot inspect, leaving security teams operating in the dark.

Legacy mobile defenses that only scan for basic malicious apps are entirely obsolete when faced with autonomous AI systems capable of constructing zero-day exploit paths inside legitimate software. This reality is illustrated by Lookout Threat Labs’ discovery of DarkSword, a sophisticated full-chain iOS exploitation framework that targets vulnerabilities hidden deep within legitimate apps that employees use ever day. In this high-velocity environment, relying on “free” alternative operating system utilities or generic software that does not see mobile threats is entirely meaningless.

By analyzing Android and iOS application binaries directly, the Lookout Mobile Software Exposure Center operationalizes exposure management at machine speed:

  • Binary SBOM Extraction: Extracts a versioned Software Bill of Materials (SBOM) directly from application binaries using advanced binary fingerprinting, giving full visibility into the software supply chain without requiring access to source code.
  • Continuous Vulnerability Correlation: Maps extracted SBOM components against CVE databases, threat intelligence feeds, and historical exploit activity to identify vulnerable libraries and outdated SDKs.
  • Vectorized SBOM Explorer: Transforms static inventories into a searchable format, allowing security teams to query the fleet instantly to identify exactly which apps contain specific vulnerable components.
  • Abandonware & Hygiene Scoring: Automatically flags applications and SDKs no longer actively maintained and calculates an Application Security Hygiene Score driven by the publisher’s Mean Time to Patch (MTTP).
  • Active Enforcement Workflows: Integrates directly into existing MDM and Unified Endpoint Management (UEM) workflows to automatically enforce risk policies or restrict high-risk applications at machine speed.

Lookout is uniquely positioned to address this crisis because the company is mobile-native and has been the first place enterprises turn to solve the mobile security problem for more than 15 years. This new platform capability is powered by an AI-driven mobile threat defense framework built on more than a decade of specialized expertise, protecting over 235 million devices and analyzing over 400 million applications globally. No other vendor sees more of the global mobile ecosystem or possesses the specialized telemetry required to solve this problem.

For existing Lookout customers, these capabilities will be delivered natively within the Lookout MES platform. Current deployments will gain immediate access to automated binary analysis, exposure scoring, and active enforcement workflows using the same unified console and agent footprint already deployed across their enterprise fleets.

This launch directly complements Lookout’s AI Visibility and Governance solution announced in April of this year. While AI Visibility and Governance is focused on securing outward-facing interactions and mitigating user data leakage, the Mobile Software Exposure Center focuses on securing the inbound software supply chain running on the device.

Together, these solutions deliver a complete, closed-loop framework for modern mobile enterprise security, empowering organizations to safely adopt AI tools while ensuring the underlying mobile ecosystem is fundamentally secure against automated, AI-accelerated threats.

Availability

The Lookout Mobile Software Exposure Center capability will be generally available to all new and existing Lookout Mobile Endpoint Security (MES) platform customers starting later this year.

Guest Post: Claude Opus 4.6 release saw the biggest surge in AI discussions on the dark web

Posted in Commentary with tags on July 22, 2026 by itnerd

As individual users and organizations are increasingly adopting AI, cybercriminals are not lagging behind. New dark web analysis from NordLayer, a toggle-ready network security platform, reveals that dark web discussions surrounding AI surged at the beginning of 2026, and dark web posts discussing AI and cybercrime are following an alarming upwards trajectory.

NordLayer analyzed data from NordStellar, a threat intelligence platform, and found that dark web user discussions surrounding AI spiked in February 2026, following the release of Claude Opus 4.6. Compared to a month prior to the release, the number of posts mentioning AI on dark web forums increased by 44%.

The data reveals that the Claude Opus 4.6 release coincided with the biggest surge on record, far above the average increase of around 11% observed around previous large language model (LLM) releases. Previous releases were followed by temporary spikes that eventually subsided. The Claude Opus 4.6 release, however, appears to have elevated the baseline itself — discussions have remained strong at around 2,518 posts per month with no sign of dropping back to pre-release levels.

“Today’s cybercriminals are highly opportunistic — they most likely monitor new releases to gauge potential impact and shifts in the digital ecosystem. The pre-release baseline for Claude Opus 4.6 was already elevated — a reflection of how normalized AI has become as a topic across all online communities, including underground forums,” says Andrius Buinovskis, cybersecurity expert at NordLayer. “The additional spike likely reflects the broader cultural moment. This release came at a point of intense public debate around AI capabilities, safety, and regulation, and it goes to show that these conversations don’t stay on the surface web.”

How cybercriminals are utilizing AI

The findings reveal that the baseline for dark web discussions surrounding AI and cybercrime has also been steadily increasing, now averaging around 500 posts per month. Phishing dominates the landscape of AI-related dark web activity. The 303 posts recorded through January-May 2026 represent 61% of the 497 posts seen in all of 2025, signaling a sharp year-over-year acceleration.


“When it comes to phishing, AI is instrumental to eliminating the initial red flags — before the rise of LLMs, users would often identify scammers through poor grammar and awkward phrasing,” explains Vakaris Noreika, cybersecurity expert at NordStellar. “AI enables even non-native speakers to craft highly convincing messages. Furthermore, LLMs allow accelerated personalization for massive scale attacks, tailoring hundreds or even thousands of phishing emails and messages by including various personal information that was scraped from public databases, like social media profiles.”

The data highlights another interesting trend — despite the rise in general AI discussions, mentions of branded malicious AI tools like WormGPT and FraudGPT totaled just 155 in 2025 and 93 in the first five months of this year — a stark contrast to the growth seen in broader categories.

“It seems that cybercriminals have realized that jailbreak versions of traditional AI tools are more powerful than custom-built malicious solutions,” says Noreika. “Malicious AI tools are very niche, and they lack the same level of training that’s present in widespread LLMs.”

Ramping up defenses against AI-powered cybercrime

According to Buinovskis, the analysis of dark web discussions surrounding AI is a clear indicator that while AI adoption is rising, cybercriminals are following fast behind. He says that users and organizations can expect an increase in attacks and urges them to prepare for the new AI-powered cyber threat landscape.

“Highly convincing, mass-volume attacks are becoming the new baseline,” says Buinovskis. “It’s now easier than ever to become a cybercriminal — technical skills are no longer a necessity. Users and organizations are getting hit from both sides. Veteran hackers are utilizing AI to scale their operations, and a whole new wave of beginners is joining the ranks every day.”

He says that in the new age of massive attacks, anyone can become a victim. Buinovskis emphasizes that, especially now, vigilance and awareness are key.

“A cautious approach is now more vital than ever — spotting AI and AI-powered attacks can be difficult even for seasoned cybersecurity experts,” says Buinovskis. “These attacks are designed to bypass both filters and human intuition, especially when we’re rushed. My key recommendation is to step back and critically assess any message that pushes to act now. In the age of AI, a healthy dose of skepticism is our first wall of defense.”

Despite that, Buinovskis explains that eventual user error is inevitable. Having proper security guardrails in place helps to minimize the possibility of a data breach and fallout of a cyberattack.

“Regarding AI-powered cyberattacks, solutions that identify malicious websites and block malware download attempts are the first step,” says Buinovskis. “For organizations, this must be part of a more comprehensive approach. True resilience requires a zero-trust architecture that treats every access request as a potential threat, combined with proactive dark web monitoring to identify leaked data before it can be weaponized.”

Buinovskis highlights that while cybercriminals are ramping up operations with AI, the fundamental attack vectors remain the same. This makes basic cybersecurity hygiene more critical than ever. Effective defense starts with rigorous password management — avoiding reuse and moving away from vulnerable consumer-browser password managers, while remaining aware of the digital footprint left behind through publicly available personal information, which attackers now routinely exploit to personalize social engineering attacks.

Methodology

NordLayer and NordStellar analyzed dark web activity between January 2024 and May 2026, tracking keyword-specific discussions across underground forums and Telegram. The research focused on the volume of AI-related mentions and how these trends shifted in direct response to major LLM product releases, with release dates sourced from public records.

Disclaimer. This analysis is based on detected activity and is for informational purposes only. It does not constitute professional advice or a guarantee of security. All third-party trademarks and references remain the property of their respective owners and are used for identification purposes only. This research tracks discussion trends in deep and dark web spaces and does not assess the safety, security, or intent of any AI provider or product.

Introducing Harness Agent DLC: New Capabilities for the AI Agent Development Lifecycle

Posted in Commentary with tags on July 22, 2026 by itnerd

Harness today announced it is extending its platform to cover the full AI Agent Development Lifecycle (DLC), giving enterprises a single set of pipelines and controls to build, test, deploy, and run agents the same way they already ship everything else.

Every enterprise is building AI agents, but most can’t get them past internal pilots or proofs of concept. According to Gartner®, “Only 8% of organizations have agentic AI in production.” The software delivery lifecycle enterprises’ trust for shipping application code hasn’t extended to agents yet, trapping the ROI of internal AI investments. Real innovation arrives once a company can run an agent live with the same trust and confidence it has in the rest of its software.

Why AI agents break the traditional software delivery lifecycle

Traditional software works because it’s predictable. Application code is deterministic. Run the same test against the same code twice, and it produces the same result both times.

Agents don’t work that way: an agent’s underlying language model decides how to complete a task, and the same agent, given the same input, can choose a different tool or take a different action from one run to the next. A test that passes once offers no guarantee it will pass the next time. Incidents stop being reproducible on demand, which means the standard playbook for catching and fixing bugs doesn’t transfer either.

The stakes rise with the size of the business. A rogue agent can expose customer data, violate a compliance policy, or take an action nobody approved. Enterprises need a way to answer for what their agents are doing, and the traditional software delivery lifecycle was never built to give them one.

New Harness Agent DLC products and capabilities

Agent DLC closes the gap between building an agent and delivering it safely to production. Today’s launch includes five new products and capabilities spanning testing, deployment, operations, and governance: 

  • Harness AI Evals makes agent quality measurable, letting teams define eval datasets, wire up scoring functions, and set quality gates that automatically catch regressions whenever an agent or model changes.
  • Agent Deployments extend the canary releases, approvals, and OPA guardrails that Harness already applies to Kubernetes deployments to managed agent runtimes like Amazon Bedrock AgentCore and Google’s Agent Runtime. Agents now ship through existing pipelines instead of a separate cloud-specific workflow.
  • AI Configs support the release and management of prompts and model changes at runtime, backed by the same feature flagging infrastructure that already manages code releases. Teams can test what performs best and roll back instantly, without redeploying.
  • AI Asset Catalog automatically discovers every agent, skill, and plugin built across an organization’s repositories and links each to an owner, so nothing ships or runs unaccounted for.
  • Harness AgentTrace records what happens during a single agent run and across a full multi-step session, showing which path an agent took, where it slowed down, and how different models or prompts affect the outcome. Harness is also open-sourcing the foundational components behind AgentTrace, including harness-sdk and harness-evals, so developers can bring the same tracing primitives into their own AI applications.

In addition, existing Harness products already extend to agents without requiring any changes: Continuous Integration builds them like any other service, Artifact Registry tracks their versions and dependencies, AI Test Automation validates their responses in plain English criteria, and AI Cost Management extends spend visibility to every agent and model. 

Securing the Agent DLC

Agents choose their own approach and path to get there, so their behavior is hard to predict and just as hard to secure. They expand their own attack surface by connecting to tools and APIs, spawning sub-agents, and inheriting trust from every model they touch. Static scans were never designed for this kind of risk. Harness is launching new security capabilities to close that gap.  

Shift-left: constrain what agents can do before they ship.

  • Primitive Scanning flags misconfigurations in agent skills, prompts, and models.
  • AIBOM captures every model, tool, and dependency an agent was built with.
  • AI Testing runs agents against adversarial inputs and the OWASP Top 10 LLM and Agentic AI risks.

Shield-right: enforce policy and maintain visibility once they’re live.

  • Agent Discovery and Posture Management continuously maps agents as they spin up and how they connect across the organization.
  • AI Firewall enforces policy in real time against prompt injection, tool misuse, and data exfiltration.

Together, these capabilities give Agent DLC a single audit trail from development to production. 

Built on the Harness platform

Harness built context and intelligence directly into the platform with the Software Delivery Knowledge Graph, which captures and connects data from every stage of the delivery lifecycle, now spanning both applications and agents. Organizations relying on siloed tools don’t have that same connected view.

In June 2026, Harness introduced Autonomous Worker Agents, a platform for building and safely running AI agents inside software delivery pipelines. Worker Agents run as governed steps within those pipelines, covered by the same controls Harness already applies to every deployment.

Agent DLC extends that same context and governance across the full agent lifecycle. The pipelines, policies, approvals, and evidence that already apply to an organization’s code now apply to its agents too, so eval gates, deployment approvals, and security checks run as stages within a single pipeline, from the moment an agent is created through everything it does afterward.

Availability

Harness Agent DLC capabilities are rolling out now to Harness customers. For a full breakdown of what’s included at each stage of the lifecycle, visit this blog page