The Dutch Institute for Vulnerability Disclosure Pwned By AI

Posted in Commentary with tags on October 1, 2026 by itnerd

The the Dutch Institute for Vulnerability Disclosure has apparently been pwned. That in itself is not news. What is news that is was pwned by AI:

Late last week, the organization said it had been hacked after seven years of uneventful operations, with the intrusion carried out autonomously by an AI agent.

The organization described the attack as “loud and very very messy,” leaving plenty of evidence to help them reconstruct what happened, but the incident was serious nonetheless.

“This is an attack we have not seen before. Not because it’s our first, but because the modus operandi indicates that this is an agentic AI-powered attack,” DIVD explained.

The organization launched an investigation and informed the police, the Autoriteit Persoonsgegevens (data protection), and the National Cyber Security Center (NCSC).

In an update on Monday, DIVD provided additional information about the incident but withheld full details to avoid influencing the investigation or putting more victims at risk.

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“This story highlights what AI is really, really good at. Exploit development isn’t like Hollywood. It takes a lot of fuzzing, scripting, and grinding through different possibilities. It’s tedious work, and that’s exactly the kind of research AI is suited for. Running that research in parallel to find zero-days is a natural fit. I think that’s the biggest lesson we should take from this story.”

Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security (https://www.linkedin.com/in/darinfredde)

(https://www.linkedin.com/in/darinfredde)

“When a vulnerability disclosure organization gets breached, the response matters as much as the breach. DIVD detected the intrusion within a day, stopped the attackers from moving deeper, and, with Merlon Security, identified two Zammad zero-days (CVE-2026-102489 and CVE-2026-102490). They reported them to the vendor three days after the breach and began notifying exposed owners two days after that. That is coordinated disclosure doing its job: one organization’s incident becomes everyone’s early warning.

“AI-enabled offense is helping us find subtle weaknesses faster, and like every tool ethical hackers and threat actors have always shared, it cuts both ways. What’s new isn’t the dual-use nature, it’s the tempo and economics. Google’s threat intelligence team reports that likely AI-discovered vulnerabilities lead to remote code execution at nearly twice the rate of others, and Mandiant finds exploitation now arrives, on average, before the patch. DIVD itself described the attack chain reaching root ‘in seconds.’ In my view, ‘cat and mouse’ no longer describes where we are. We’re moving toward machine-speed, multi-stage attacks, and no organization is immune.

“The answer is continuous offensive rigor: test, find, fix, prove the control works, and keep testing as the environment changes. Public counts likely understate AI’s role in discovery, which makes continuous testing and coordinated disclosure more urgent, not less. We cannot do this alone.”

Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)

“DIVD described the agent used in this attack as being sloppy, and leaving artifacts where the agent left comments where it over-explained the activity it was performing. And that generally the agent was loud, messy, and disorganized.

“Despite that, it still successfully exploited a public host by chaining two zero days to escalate privileges to root, and then gain RCE, allowing the attacker full permissions to execute whatever follow up they wanted.

“Despite flashy headlines, there wasn’t much novel about this attack. Two zero days were burned to gain access. Its not particularly common to utilize zero days to gain access, it’s much much more common to simply exploit unpatched systems, because so many systems don’t patch promptly. So the specific CVEs were new, but the techniques were old.

“Once access into DIVD systems was gained, the attack moves to what is called the post exploitation phase. This is where the attacker has access inside the environment, and can choose what they want to do with that access. In this case, it appears they set an agent loose rather than using any of the pre-existing post exploitation toolkits. We’ve had years of sophisticated tools that skilled attackers can use in this phase of the attack. But we didn’t see that here. Instead, and agent poked around the network, made a lot of noise, connected to various systems, stole some data, and generally left a lot of logs and evidence for DIVD to alert on and respond to.

“The good news for DIVD is that the attack left a lot of evidence behind. This made detection easier, and provides adequate artifacts to review during the investigation to put together a timeline of activity.”

This attack might have been sloppy. But OpenAI for example has agents who are not sloppy. This an example of that. And make no mistake that one of those agents are coming for you real soon.

Liquibase Secure 6.0 Brings Database Change Governance to Enterprise Scale

Posted in Commentary with tags on October 1, 2026 by itnerd

Liquibase today announced the general availability of Liquibase Secure 6.0, a major release that makes it easier for enterprises to automate and govern database change across mission-critical applications, data products, and AI initiatives.

The way enterprises build and deliver technology is changing quickly. Application and data teams are releasing more often, developers have more autonomy, and AI is dramatically increasing the volume of code and database change enterprises produce. But the controls around database change have not kept pace. Policies are still often scattered across pipelines, configuration files, repositories, and teams, making them difficult to manage consistently as organizations scale.

Liquibase Secure 6.0 changes that model by moving database change governance from pipeline-by-pipeline configuration to enterprise scale. Organizations can see database change across the enterprise, understand and remediate issues when they occur, define and manage policies from one place, set governed exceptions when they are needed, and control who has the authority to manage those policies. It gives enterprises a simpler way to answer three questions that become harder as the volume of change grows: What changed? Was it allowed? Who controls the rules?

Change Intelligence Turns Database Change Visibility Into Action

At the center of Liquibase Secure 6.0 is Change Intelligence, a completely new capability that gives enterprises a clearer picture of database change across applications, pipelines, teams, and environments.

Database teams have historically had to reconstruct what happened from pipeline logs, tickets, screenshots, and other disconnected sources. That becomes especially painful when something goes wrong. Teams need to understand what changed, where it failed, whether environments have drifted, what risk was introduced, and what they should do next.

Change Intelligence brings deployment activity, environment status, drift, policy outcomes, failures, and change history together in one place. Teams can understand how changes are moving across environments, identify where risk is building, and see what needs attention without manually piecing together the story across individual pipelines and tools.

More importantly, Change Intelligence helps teams move from visibility to action. When a deployment fails, AI-driven analysis helps teams understand what happened and provides remediation guidance to resolve the issue faster. Change Intelligence also centralizes audit evidence, giving engineering, security, and compliance teams a structured record of database change throughout the delivery lifecycle.

For executives and operators alike, Change Intelligence helps enterprises understand what is happening across the database estate, identify problems faster, and determine what to do next.

Making Enterprise Database Change Governance Easier

Governance has traditionally come with a tradeoff. Enterprises want consistent standards and stronger controls but they don’t want to create another layer of process that slows down delivery.

Liquibase Secure 6.0 also introduces a new graphical interface for policy management that makes governing database change much easier. Teams can create, organize, apply, and manage policies from one place instead of relying on pipeline-by-pipeline configuration or specialized command-line knowledge.

The new experience includes 50+ prebuilt policy rules based on years of working with some of the world’s largest and most complex enterprises. Teams can start with proven controls, organize them into reusable policy packages, and apply them across the applications and environments where they are needed.

The new experience also makes exceptions part of the governance model rather than something teams have to work around. When a legitimate exception is needed, teams can scope where it applies, document why it exists, control who can make it, and retain the decision in the audit history. Organizations can maintain consistent standards without pretending every application, data product, team, or database operates exactly the same way.

Controlling Who Can Change the Rules

As database change governance moves from individual pipelines to the enterprise, organizations also need control over who owns and manages those standards.

Liquibase Secure 6.0 introduces role-based access control that determines who can manage policies, assignments, exceptions, and governed assets. Organizations can separate ownership of governance from application and data delivery, creating clear responsibilities around who defines the rules and who works within them.

This allows enterprises to maintain separation of duties without taking autonomy away from development teams. Developers can continue moving quickly inside established boundaries, while database, platform, security, and compliance teams maintain control over the standards that protect the organization.

Together, Change Intelligence, centralized policy management, and role-based access control create a new operating model for database change. Enterprises can see what changed, govern what is allowed, and control who owns the rules from one platform rather than stitching together controls across individual pipelines.

Governance as a Force Multiplier for AI

AI is increasing how quickly enterprises can build and deliver applications and data products. But that advantage erodes if every increase in development speed creates a corresponding increase in manual review, operational risk, and governance overhead.

That is why governance becomes a force multiplier for AI. When database standards are defined up front and enforced automatically, enterprises can move faster with AI without requiring a human to review every database change it helps create. Whether a change is written by a developer or generated with AI assistance, the same policies and controls can be applied before it reaches production.

The goal is not to slow AI down so existing governance processes can keep up. Liquibase Secure 6.0 makes it possible for governance to operate at the speed of development, giving teams the freedom to increase the speed and volume of change while maintaining the controls the enterprise requires.

That model extends beyond AI. Liquibase Secure supports more than 65 database platforms, giving organizations a consistent governance layer across heterogeneous database environments. Platform and DevOps teams can scale database self-service without scaling governance overhead, database teams can spend less time rebuilding controls and reviewing routine changes, and security and compliance teams can put controls and evidence closer to the point of change.

As mission-critical applications, data products, and AI initiatives increase the speed, volume, and sources of database change, Liquibase Secure 6.0 gives enterprises one place to see that change, govern how it happens, and control who can change the rules, whether the change comes from a human or AI.

Availability

Liquibase Secure 6.0 is generally available September 30, 2026. The release includes Change Intelligence, the new graphical interface for centralized policy management, role-based access control, governed exception management, and 50 prebuilt policy rules.

For more information about Liquibase Secure 6.0, visit www.liquibase.com/liquibase-secure.

From the Pitch to Patients: Hisense Canada Shares FIFA World Cup Spirit with Toronto SickKids

Posted in Commentary with tags on October 1, 2026 by itnerd

Hisense Canada is helping keep the spirit of the beautiful game alive by donating FIFA World Cup 2026™-branded merchandise to The Hospital for Sick Children (SickKids) in Toronto.

As an Official Partner of FIFA World Cup 2026™, Hisense is proud to share the excitement, optimism and sense of community that sport can inspire. While the tournament may have concluded, the company believes the power of sport to bring people together extends far beyond the final whistle. The donation made by Hisense, including soccer balls, plush keychains, mugs and water bottles adorned with FIFA World Cup 2026 branding, will be distributed to children and families receiving care at the hospital.

SickKids is one of Canada’s leading pediatric health-care institutions, providing world-class care, research and education to improve the health of children in Canada and around the world.

The donation reflects Hisense Canada’s ongoing commitment to supporting communities and creating meaningful experiences beyond its products and partnerships.

For more information, please visit hisense-canada.com. 

Pink Samsung x TELUS phone for Breast Cancer Awareness Month 

Posted in Commentary with tags on October 1, 2026 by itnerd

As part of their 25th Anniversary Rethink Breast Cancer has announced they’ve partnered with 25 top Canadian brands on a curated collection of limited-edition products for their 25 for 25 Brand Collection, with a portion of proceeds directly funding breast cancer education, research, and advocacy for younger women. As a part of this, TELUS and Samsung are offering a promotion:

  • From Oct. 1–31, TELUS will donate $50 to Rethink (via the TELUS Friendly Future Foundation, up to $50,000) for every purchase, activation, or renewal of a Galaxy Z Flip8, Galaxy Z Fold8, or Galaxy Z Fold8 Ultra online or in participating TELUS stores.

Rethink is also opening its first-ever physical Toronto Pop-Up (Oct. 2–31), offering visitors an immersive look at their mission, exclusive brand collaborations, and interactive learning experiences.

SafeBreach is now cleared by both Anthropic and OpenAI to use their frontier models for offensive security research

Posted in Commentary with tags on October 1, 2026 by itnerd

SafeBreach today announced it has been approved for both leading frontier AI security programs: Anthropic’s Cyber Verification Program (CVP) and OpenAI’s Daybreak Blue (Trusted Access for Cyber). These identity-verified frameworks unlock the use of frontier models, including GPT-5.6-Cyber and Claude Opus and Sonnet, for the legitimate offensive-security research the SafeBreach attack content team and AI-assisted tooling utilize to provide faster, more realistic attack content for customers. 

Anthropic and OpenAI each review an organization’s legitimacy and the nature of its security work before approving specific accounts for advanced security research. Anthropic’s CVP covers what it calls “High-Risk Dual Use” research, such as vulnerability research and security testing. OpenAI’s Daybreak Blue covers defensive security work such as malware analysis, detection engineering, and incident response.

SafeBreach Labs can apply frontier models from both labs to threat analysis and attack-behavior research, shortening the path from new adversary research to production-safe validation content in the SafeBreach CTEM Platform. Every attack scenario is still written, tested, and validated by SafeBreach Labs before it ships.

The SafeBreach CTEM Platform is utilized by some of the largest financial services, healthcare, manufacturing, and transportation organizations in the world to enable a true closed-loop exposure management program that provides measurable risk reduction and enhanced cyber resilience. The SafeBreach CTEM Platform is grounded in the company’s award-winning adversarial exposure validation (AEV) capabilities and is powered by SafeBreach Helm, the AI infrastructure layer that orchestrates three purpose-built AI agents designed to operationalize the full CTEM lifecycle. Users engage with the platform via SafeBreach Helm’s intuitive, natural-language interface to continuously identify, validate, and resolve exposures. Together, the SafeBreach CTEM Platform and SafeBreach Helm help organizations evolve from fragmented, reactive practices to a unified, intelligence-driven exposure management program grounded in proven AEV and elevated by AI.

To learn more about the SafeBreach CTEM Platform, SafeBreach Helm and SafeBreach Labs, visit:

Bank of England governor says test AI first, regulate later

Posted in Commentary with tags on October 1, 2026 by itnerd

Bank of England Governor Andrew Bailey says regulating AI “is not the right place to start.” In his first Substack article, he called for rigorous testing to find vulnerabilities and build safeguards before any formal rules, pointing to work at the UK’s AI Security Institute. He expects models to “behave unexpectedly” during testing, and warned that frontier AI without a way to intervene could become a system that governs itself. His comments come days after OpenAI held back its latest model over safety concerns, and after President Trump announced a voluntary safety agreement with OpenAI, Anthropic, Nvidia, Meta, Google and SpaceX that leaves each company responsible for the safety of its own technology.

Adrian Culley, offensive security engineer at SafeBreach said this:

“Most of the risk sits in deployment, not in the model at release: agents with tool access, connectors, non-human identities and data flowing through integrations. That is where attackers operate. Prompt injection (MITRE ATLAS AML.T0051, OWASP LLM01) turns a trusted agent into an insider with legitimate credentials, and a voluntary, self-attested safety commitment will not catch it.

Regulators are moving towards evidence, not policy statements. Supervisors will increasingly ask financial firms to show how they validate AI-enabled systems, particularly where many institutions depend on the same underlying models and one failure could be correlated across the sector.

The answer is the discipline security teams already apply elsewhere: assume controls fail, then prove otherwise. Run realistic attack scenarios against deployed AI systems, measure whether intervention controls actually trigger, and repeat as models, prompts and permissions change.

Bailey calls for a system to intervene. That system must be validated under attack, not assumed to work.”

I personally want evidence based legislation in place before any rollout of AI is done. Companies who provide AI and companies who use AI can’t be trusted to do the right thing. Thus they have to have the right imposed upon them 100% of the time.

Canada’s “job huggers” are turning to AI to move forward

Posted in Commentary with tags on October 1, 2026 by itnerd

As uncertainty keeps many Canadians in their current jobs, new research suggests workers aren’t simply waiting for conditions to improve. They are using technology and AI to adapt, build confidence and make progress within the roles they choose to keep.

HP’s 2026 Work Relationship Index finds 69% of Canadian Knowledge Workers say it feels too risky to leave their job right now, contributing to a growing trend of “job hugging.” But technology is emerging as a bright spot for workers navigating continued change.

The Canadian findings show:

  • Technology is becoming a source of progress: 53% of Canadian Knowledge Workers say technology is better today than it was two years ago, rising to 63% among workers in the Healthy WRI Zone.
  • Workplace AI adoption is accelerating: 47% use work-provided AI daily or weekly, up from 35% in 2025.
  • The technology experience still matters: 52% say faster, more reliable devices would enable them to do their best work, while 43% want shared knowledge systems and 39% want seamless integration across tools.

The findings paint a more nuanced picture of “job hugging”. Canadians may be staying put, but they’re not standing still. For businesses, the opportunity is to equip employees with the AI, skills and reliable technology they need to adapt and do their best work.

You can learn more about HP’s latest Work Relationship Index Report findings here.

88% of Canadian TV Viewers Are Streaming. Now Comes the Hard Part…

Posted in Commentary with tags on October 1, 2026 by itnerd

Streaming has become the norm in Canada, but as audiences gain more choice, finding what to watch and where to watch it is becoming increasingly complicated.

New Canadian research from Roku finds 88% of TV viewers now stream, while 74% watch ad-supported streaming. At the same time, 66% of Canadian streamers say there are too many streaming services to keep track of, and 61% don’t always remember which platform has the show or movie they want to watch. 

For advertisers, the findings point to an interesting shift heading into 2027: the opportunity isn’t simply reaching Canadians on streaming, but finding useful ways to connect with them throughout an increasingly fragmented viewing journey.

A few findings:

  • Canadian streamers spend an average of 11.9 hours a week with ad-supported streaming, up from 10.2 hours in 2025.
  • Streamers spend an average of 13 minutes looking for something to watch, and one in five routinely spends more than 20 minutes searching.
  • 78% say ads that help them find or remind them about movies and shows to watch would be useful.
  • 67% have taken some form of measurable action after seeing a TV ad, from searching for more information to visiting a brand website or making a purchase.

Read more here: Overwhelmed by Choice, Canadians Spend About 80 Hours a Year Deciding What to Watch on TV, New Study Finds

Kyndryl Report: As AI broadens modernization agenda, leaders prioritize business outcomes over replacing legacy systems

Posted in Commentary with tags on October 1, 2026 by itnerd

Kyndryl today released its first global Modernization Report, which found that as organizations expand investments across legacy and modern platforms, modernization increasingly requires business orchestration, not technology consolidation.

Based on insights from 2,000 business and technology leaders across five continents and 12 industries, the research shows how AI is reshaping investment priorities across infrastructure and applications, while also challenging organizations’ operating models.

According to the report’s findings, the need to adopt AI now outranks priorities to reduce spending, replace legacy systems, or address a shrinking pool of legacy systems expertise. AI is the top driver of increased mainframe and edge computing use, the second-biggest driver for SaaS and private cloud expansion, and the leading reason organizations are upgrading their networks and application portfolios. Every organization with a mainframe now reports plans to deploy AI to the platform.

Together, these trends are creating more complex technology environments and new operational challenges for technology leaders.

Nearly half of respondents said they are behind schedule on their modernization goals. Agentic AI, which can autonomously plan and execute tasks, is emerging as a way to modernize faster. Ten percent of organizations have deployed agentic AI in production for modernization, applying it to typically time- and skills-intensive tasks of dependency mapping, code conversion, and generating documentation. Early adopters reported stronger outcomes, with 67% saying they are ahead of or on track with modernization goals, compared with 51% of other organizations.

The research also highlights what is slowing organizations down. Just 9% said they fully understand their applications’ dependencies, and one-quarter say they have large numbers of undocumented applications.

Among other findings, Kyndryl’s study shows that:

Modernization has become a business-wide priority, not just a technical one

The findings underscore the growing demands on CIOs, who must advance several priorities at once: AI adoption, cyber resilience, regulatory compliance, operational efficiency, and business growth. Respondents named nine distinct stakeholder groups with control over modernization, from CIOs and CTOs to boards of directors and finance and compliance teams. Modernization has outgrown the IT department and become a board-level business decision. Its growing importance also requires organizations to coordinate decision-making across more stakeholders without sacrificing speed.

Global events shape technology decisions alongside cost and performance

Sovereignty considerations are a growing factor in modernization strategies. While 65% of organizations address sovereignty selectively or primarily through a compliance lens, 63% expect sovereign cloud usage to increase and 55% expect sovereignty and regulatory requirements to place greater demands on their network architectures. The findings suggest that the geographic location of where technology runs is increasingly being shaped by governance and geopolitical considerations alongside performance, cost and innovation.

Complexity keeps compounding

The findings challenge the long-held assumption that digital transformation would lead organizations to gradually migrate toward a single preferred technology environment. Instead, their technology environments are becoming more distributed and complex as they prepare for AI. Mission-critical applications are distributed almost evenly across public cloud, private cloud, mainframe and on-premises environments, creating an increasingly hybrid enterprise. As digital transformation extends across the business, it must be underpinned by strategic, governance, and operational coordination — including a more integrated approach to cyber resilience as AI-driven threats accelerate and broaden.

Read more about Kyndryl’s 2026 Modernization Report.

From grit to growth: TELUS celebrates #StandWithOwners 2026 winners

Posted in Commentary with tags on October 1, 2026 by itnerd

Today, TELUS announced its 2026 #StandWithOwners winners. Through its annual #StandWithOwners program, TELUS has invested close to $7 million since 2020, providing the funding and technology to help small businesses thrive in an increasingly digital world.

This year’s winners embody the true spirit of Canadian entrepreneurship. They are the owners who have faced uncertainty with courage and an unwavering determination to grow. To help these leaders reach their next great milestone, TELUS and its partners are providing each grand prize winner with a $125,000 boost in funding, technology, and exposure to help propel their dreams to new heights.

TELUS is proud to announce their three 2026 Grand Prize winners:

  • Future Forward Award, presented by Samsung: Silverts Adaptive Clothing and Footwear – Acquired by Joshua Norris in 2024 alongside the purchase of award-winning Canadian designer brand IZ Adaptive, Silverts serves aging adults and people with disabilities across North America through magnetic closures, open-back designs and wheelchair-friendly cuts. Inspired by real-world feedback from care aides and residents, Silverts went beyond apparel to innovate specialized in-bed bathing systems that solve major daily caregiving challenges with dignity.
  • Business Growth Award, presented by Scotiabank: Atome Bakery – Led by owners Lucas Navilloz and Alice Couderc, Atome Bakery sells frozen, ready-to-bake goods directly to consumers and provides third-party fulfillment services for other small food brands.
  • AI Innovation Award, presented by Google: Innovatree Carbon Group Ltd. – An Indigenous–owned enterprise led by owners Darcy Lebourdais, Jackson Baron, Garrett Whitworth and Tanner Lebourdais. Leveraging cutting-edge LiDAR technology and AI-driven analytics, they advance climate-smart forestry, mitigate wildfire risks and drive economic reconciliation across Canadian communities.

Help us choose the People’s Choice Award winner

To wrap up this year’s celebration, TELUS and Salesforce are inviting all Canadians to help champion their favourite winner through the People’s Choice Award. Starting October 1, the public can cast their vote for their favourite 2026 winner from the nine grand prize and community award recipients—giving a deserving business an additional $25,000 boost in funding to fuel their growth.

Visit telus.com/winners to discover the winning businesses and cast your vote before October 8, 2026, at 11:59 PM ET. The final winner will be announced on October 15.