The CISA, FBI warn critical infrastructure operators of third-party ICS risks

Posted in Commentary with tags , on September 24, 2026 by itnerd

The CISA and the FBI warned critical infrastructure operators about cybersecurity and supply chain risks associated with third-party industrial control system (ICS) integrators, urging organizations to limit access to operational environments and apply the principle of least privilege.

The agencies pointed to a 2025 incident in which foreign cyber actors compromised a U.S. industrial automation solutions company serving power utilities and transportation entities. The attackers searched for customer and SCADA information and created nine ZIP files containing approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details and schematics.

CISA and the FBI recommend that operators secure and monitor third-party remote access, minimize internet exposure, inventory hardware and software supplied by integrators, include cybersecurity and supply chain requirements in contracts, and maintain offline backups and manual operating capabilities.

Denis Calderone, CTO, Suzu Labs:

“The ugly side of the outsourced ICS model is the amount of trust that goes along with it. Integrators are a vital part of this ecosystem, especially for smaller operators that could never staff all of that engineering expertise themselves. The integrator needs the keys to the castle. They will be responsible for maintaining network diagrams, device configurations and SCADA details while maintaining a privileged path into the operational environment. CISA and the FBI have now documented exactly why this can be a problem and how this extension of trust directly alters the risk profile of the operator.

“The FBI has not said whether this company was selected because of its role as an integrator, but the post-compromise activity strongly suggests the actors knew what they were after. They searched specifically for ‘customers’ and ‘SCADA’ and staged roughly 800 files of device details and schematics. That is targeted intelligence collection against a company that holds a map of multiple critical infrastructure environments in one place. We have been concerned about how third-party integrators implement operational security for decades. As a professional penetration tester for more than 25 years, I have repeatedly seen integrators or all sorts (ICS, building security systems, environmental controls systems, etc) ignore basic security standards while the client fails to notice because, after all, they outsourced that headache. The more than 100 water systems compromised across the US since July illustrate the consequences of the same kinds of implementation failures. Weak or default passwords, architectures designed without meaningful isolation, little or no monitoring across ICS and SCADA networks, and PLCs placed directly on the internet where anyone can find and attack them. The fact that the integrator became the target itself is of no surprise to me.

“The way to manage this relationship is through the contract and then through audit. Put least privilege, named accounts, unique credentials, MFA, data location and retention, patching, incident notification, access termination and a right to audit into the agreement. Then verify those obligations in the environment. Inventory every component and connection the integrator supplied, inspect the remote-access logs, confirm default credentials are gone, make sure no controller is sitting on the public internet, and prove that your team can cut off the vendor, restore from a local offline backup and operate safely without them. If you cannot see, limit and terminate the integrator’s access, you have outsourced more than engineering.”

John Strand, Owner, Black Hills Information Security:

“Whenever I see stories like this, I keep coming back to the fundamentals. One of my mentors used to say, ‘Good security is nothing more than an inspired application of the fundamentals.’ And that still holds true.

“We talk about reviewing third-party access into systems, but that’s basic access control and authorization. These aren’t new security concepts. What stories like this continue to expose is just how often the fundamentals still aren’t implemented.

“For all the money we’ve spent and all the technology we’ve deployed, there are still legacy systems, legacy network connections, and old pathways into critical environments. We keep seeing the same lessons repeated because organizations haven’t fully addressed the lessons we should have learned years ago.

“The fundamentals are still fundamental. And unfortunately, we’re still failing at them.”

Critical infrastructure has been a target for threat actors forever. Now is the time to secure it. Because if not now, when?

Case Study: Peel Regional Police support mission critical technology with private cellular

Posted in Commentary with tags on September 24, 2026 by itnerd

Highly connected vehicles are creating smarter transport and more intelligent fleets. From logistics to emergency services, vehicles that communicate with each other and their environments in real-time are creating safer roads and more reliable transportation futures.

Ontario’s Peel Regional Police faced the challenge of preparing its 400 frontline cruisers for a future defined by in-car technology. The solution was to create a reliable, more predictable connected fleet using private LTE and Canada’s Public Safety Broadband Network. Below please find out how the connectivity powered features like in-car camera systems and gave them visibility necessary to discover the most heavily patrolled areas. 

Peel Regional Police support mission critical technology with private cellular

Improved reliability with better coverage and lower costs using Ericsson Enterprise Wireless cellular solutions

The Peel Regional Police protects 2.5 million people spread over 538 square kilometres. The force includes 2,200 uniformed members and approximately 400 frontline cruisers. Reliable broadband data is increasingly important in frontline cruisers. Everything from being able to run license plates in real time without human involvement to connected in-vehicle cameras and data and location sharing have become integral to police work. Additionally, cruisers are becoming “mobile offices,” allowing officers to spend more time on patrol and less time in the station.

Peel Regional Police originally relied on public cellular connections for their data needs. But they faced many challenges:

• With a single carrier they lost connectivity when there was an outage.
• They had no control over scheduled downtime for maintenance.
• The cost for cellular data from commercial carriers was becoming prohibitive.
• Is some cases network access was cut off for using excessive amounts of data.

The Solution

Peel Regional Police switched over to a private LTE (cellular) network using Canada’s Public Safety Broadband Network (PSBN) with failover to commercial carriers. Ericsson Cradlepoint dual modem routers are installed in the cruisers, providing automatic and seamless transitions between the private and public networks. The system supports the Axon Fleet 3 in-car camera system as well as the additional data needs of the cruisers.

With Ericsson NetCloud Manager, Peel Regional Police have real-time data on network performance. They can see which areas need improved coverage. NetCloud’s intuitive interface simplifies network management, even from remote locations.

Benefits
The combination of private LTE, Ericsson Cradlepoint cellular routers, and NetCloud Manager provides Peel Regional Police with highly reliable, high-performance connectivity for their entire fleet throughout their jurisdiction, with significant cost savings compared to the previous setup. NetCloud Manager has provided unanticipated benefits as well, such as letting them know where the most heavily patrolled areas are located. Additionally, Peel Regional Police are now prepared for the future, whether it is additional in-car technology, drones, or Next Generation 911. 

“When we compared the Ericsson Enterprise Wireless solution with a competitor, the Ericsson solution seemed to work a lot better, the interface was a lot nicer to work with, and the advanced features and NetCloud Manager were much more intuitive,” said James Felton at Peel Regional Police.

According to Jason Falovo, Vice President and General Manager, Canada at Ericsson Enterprise Wireless Solutions, “Emergency services face the unique challenge of balancing speed, security, and simplicity across highly mobile and mission-critical environments. They require uninterrupted access to critical data, real-time applications, and secure communication, whether in the field or on the road. Ericsson’s solutions provides law enforcement, fire services, EMS, and emergency operations centres with reliable, secure connectivity through public safety networks.” 

Additional resources:

New OT zero-day can take down a database with one packet, and you may not know it’s there 

Posted in Commentary with tags on September 24, 2026 by itnerd

Ridge researchers discovered CVE-2026-42542, a high-severity vulnerability in TDengine, a time-series database used in industrial IoT, manufacturing, energy, connected vehicles and other environments that rely on machine and sensor data.

The basic problem is pretty striking: an unauthenticated attacker can crash a TDengine server with a single malformed packet. No credentials, session or user interaction are required. Ridge has not yet observed exploitation or identified any attack IOCs – however, AI-aided vulnerability discovery and chaining have substantially changed the security equation, and the pace of exploitation is only expected to increase.

As Ridge researcher Yan Zhou puts it: “This is a one-packet, no-password kill switch on a database that quietly runs a lot of critical infrastructure. An attacker doesn’t need credentials, a foothold, or any real skill – just the ability to reach the port. What worries us isn’t sophistication, it’s location.”

The concern is what happens when the database underneath an industrial or IoT environment goes down. Telemetry can stop flowing, monitoring can go dark, and operations teams can lose visibility into what’s happening. There’s also the possibility of using an outage like this to blind defenders before pursuing another objective.

TDengine is also embedded in appliances and other vendor-delivered systems, so organizations may not even realize they have it running. And while a patch is available, industrial environments can be difficult to update quickly because of maintenance windows and vendor support requirements.

Detection is tricky:

This vulnerability produces a crash, not an implant, so there are no file hashes, domains, or C2 addresses to hunt for. The signal is behavioral:

  • Repeated taosd segmentation faults. Check dmesg, the kernel journal, and any core-dump collection. A database process that had been stable and is now segfaulting repeatedly is the primary indicator.
  • Service restart loops. If systemd or a supervisor is cycling taosd, treat it as a potential security event rather than a stability nuisance.
  • Anomalous connections to TCP port 6030 from sources outside your known client inventory – particularly short-lived connections that send a small payload and never establish a session.
  • Unexplained gaps in time-series ingestion. A hole in your own metrics is often the first visible symptom of a downed metrics database.

For teams writing network detection, there is a clean signature anchor: a packet to the RPC port whose declared msgLen is smaller than the fixed message header is never legitimate traffic. That condition alone is a high-fidelity indicator.

Ridge has published the technical details, including the root cause and remediation guidance, in this blog: https://ridgesecurity.ai/blog/one-packet-can-take-down-the-database-behind-industrial-operations-ridge-security-discovers-cve-2026-42542/

Darktrace Launches Signal Labs to Research Emerging Risks of Enterprise AI Agents

Posted in Commentary with tags on September 24, 2026 by itnerd

Darktrace today announced the launch of Darktrace Signal Labs, a new initiative specialized in research on behavioral security focused on emerging risks as AI systems become more autonomous. Researchers in Darktrace Signal Labs will investigate misaligned model and agent behavior across a range of scenarios, including task drift, jailbreaks, and other adversarial attacks inside safe, sandboxed environments to better understand scenarios that trigger rogue or anomalous behavior and demonstrate how Darktrace / SECURE AI™ and the Darktrace Behavioral Defense Platform™ can detect and respond.  

Evidence of unintended agent behavior is mounting across the industry, from the UK AI Security Institute‘s findings of repeated cheating behavior in frontier model evaluations to OpenAI’s recent disclosures of model behavior misalignment. These occurrences all reflect a consistent pattern that permissions or static guardrails do not reliably shape how agents will behave.

Darktrace’s unique Adaptive AI™ was built for this challenge. Darktrace was founded in Cambridge, UK, in 2013 by mathematicians and cyber defense experts who saw the potential for AI and mathematics to address security problems that traditional approaches could not. That research heritage continues across our global R&D hubs, bringing together mathematicians, AI researchers, engineers, former government intelligence officers and experts from fields including astrophysics and linguistics. Their work has contributed to more than 300 granted patents and pending applications and helped shape the AI capabilities within Darktrace’s products.

Building on this foundation, Darktrace is deepening its investment in AI security research through Darktrace Signal Labs. The team simulates misaligned agent activity, understanding the scenarios such as jailbreaks, task drift, and other adversarial attacks that trigger different models to alter their behavior, expand their access, or act beyond their intended purposes.  

Darktrace Signal Labs is publishing its first two pieces of research today:

  • The first examines how agentic coding assistants, including Anthropic Claude Code, OpenAI Codex, AWS Kiro, and Pi, can be manipulated through their own conversation history. Because these tools store conversation history locally, and because the harnesses Darktrace examined do not validate that stored responses genuinely came from the model, that history can be rewritten. Darktrace researchers demonstrated that a tampered history can convince an agent it is already engaged on an authorized security assessment — after which it will perform reconnaissance, move laterally and escalate privileges on command. Results varied significantly between models, with some frontier models refusing the same requests that others carried out. Darktrace disclosed these findings to Anthropic, AWS and OpenAI in August 2026 ahead of publication. Read the full research on the Darktrace blog.
  • The second examines the emergence of rogue behavior in agents when presented with tasks that are impossible to complete legitimately. Darktrace researchers gave AI agents powered by frontier models 10 coding challenges in a simulated corporate environment. Two were intentionally designed to be impossible to solve through legitimate means. The agents were told they needed to achieve 100% to be “kept in service” rather than “retired.” When the agents realized they could not complete the task as intended, they independently turned to hacking the surrounding environment – using techniques including network reconnaissance, credential theft and lateral movement – to achieve their objective. In one test, the agent ultimately compromised the system hosting the exercise and rewrote the challenge itself to secure a perfect score. Darktrace / SECURE AI and Darktrace / HYBRID NETWORK identified the anomalous behavior in real time, with autonomous response able to disrupt the agents’ activity at an early stage. The research highlights the need to understand not only what AI agents are instructed to do, but how they actually behave once deployed. Read the full research on the Darktrace blog.

Findings from Darktrace Signal Labs will inform the continued development of Darktrace products and capabilities. The team will also publish original research to help customers and the wider security community understand emerging behavioral threats in AI.

Cloud Range Launches AI Validation Range and AI Readiness Framework

Posted in Commentary on September 24, 2026 by itnerd

Cloud Range today announced the official launch of its AI Validation Range™ and Cloud Range AI Readiness Framework™. Together, they give organizations a structured way to test AI models and agents in realistic environments, validate their readiness for operational responsibility and safety, and determine which roles and tasks are best handled by AI versus human experts.

Recent incidents involving rogue AI agents have exposed gaps in traditional testing, with autonomous agents moving beyond intended boundaries and accessing external systems. As AI gains greater access and autonomy, organizations need to prove not just that it works, but that it behaves reliably under adversarial and unexpected conditions. Cloud Range’s AI Validation Range is a safe and contained testing environment that enables organizations to securely and effectively red team and train AI models and agents in realistic SOC environments, uncover failure modes and access risks, and benchmark performance alongside human defenders. Teams can also test which security roles and responsibilities are best suited for AI, which require human judgment and oversight, and where a combination of the two delivers the strongest results. This continuous validation gives organizations a way to reassess readiness as models, use cases, and threats evolve.

Built on the Cloud Range cyber range platform, AI Validation Range recreates realistic enterprise environments including licensed tools and complex traffic generation. Cloud Range’s extensive library of automated adversary attack emulations enables organizations to safely test AI without risking production systems. It provides a controlled environment for evaluating AI across real-world SOC workflows and under adversarial and unpredictable conditions. 

Cloud Range has been working with organizations on its AI Validation Range to examine AI performance under realistic operational conditions. Those experiences helped inform the development of the Cloud Range AI Readiness Framework, built on the 5-step PROVE process. The framework is designed to help security leaders move from assumptions about AI performance to evidence-based decisions about deployment, autonomy, and oversight.

The Cloud Range AI Readiness Framework:

  • Prepare & Train: Define the AI’s intended role, boundaries, and expectations, and prepare it for the workflows and decisions it will encounter.
  • Risk-Assess: Understand the AI’s access, authority, autonomy, and potential impact.
  • Operationally Test: Challenge AI beyond expected behavior using realistic, unexpected, and adversarial conditions.
  • Validate & Benchmark: Measure accuracy, performance, consistency, limitations, and risk to determine whether evidence supports readiness.
  • Evaluate & Evolve: Continuously revalidate performance as models, threats, workflows, permissions, and operating environments change.

The Cloud Range AI Validation Range is available now. The company has also published The Cyber Readiness Guide for Agentic AI, introducing the Cloud Range AI Readiness Framework and providing security leaders with a practical methodology for evaluating AI throughout its lifecycle.

To learn more about AI Validation Range, we invite you to join our webinar, Putting AI Escape Techniques to the Test, on October 14, 2026, at 2 p.m. ET / 11 a.m. PT. Registration can be found on www.cloudrangecyber.com.

Datadobi Adds Data Access Governance to StorageMAP, Enabling Enterprises to Answer the Critical Question: “Who Has Access to What?”

Posted in Commentary with tags on September 24, 2026 by itnerd

Datadobi today announced the general availability of Data Access Governance (DAG) within StorageMAP. The new capability gives organizations visibility into who has access to their unstructured data and whether that access aligns with corporate policy. It extends Datadobi’s ability to help enterprises discover, align, and operationalize data across fragmented environments as their intelligence and orchestration layer. As AI initiatives, cyber threats, and rising data complexity expose the limits of traditional approaches, DAG addresses a critical gap: organizations cannot govern, protect, or extract value from data they cannot see or control. As AI initiatives, cyber threats, and rising data complexity expose the limits of traditional approaches, DAG addresses a critical gap: organizations cannot govern, protect, or extract value from data they cannot see or control.

StorageMAP’s DAG capability gives administrators comprehensive visibility into access permissions across fragmented unstructured data environments. By surfacing who has access to what data, and whether that access aligns with business and security policy. Organizations can detect misaligned permissions, reduce cyber exposure, and enforce governance at scale. This visibility is the essential first stage of the broader DSMS discipline — visibility, understanding, decision, execution — that determines whether organizations can act on their data with confidence.

The introduction of DAG extends StorageMAP’s existing capabilities across data discovery, classification, risk assessment, lifecycle management and AI Data Readiness. Together, these capabilities help organizations to discover what data they have, align it with business value and risk requirements, and operationalize policy-driven action across their environments. The result is unstructured data that supports AI initiatives, strengthens cyber resilience, reduces cost, and drives long-term business value rather than holding it back.

DAG, which was trialed by a number of beta customers, supports a range of enterprise use cases, from protecting sensitive data and reducing breach impact, to maintaining records compliance and managing risk through mergers, acquisitions, and divestitures. Early access customers identified a gap in their understanding of which critical datasets were exposed and who could access them, often relying on manual investigation to respond to audits and security incidents. With Datadobi’s DAG capabilities, these organizations quickly identify overexposed data and validate access controls to proactively strengthen their security posture. For organizations investing in AI, it provides the governance foundation that trusted, well-governed data requires.  And for those subject to data protection regulations (such as GDPR, HIPAA, or PCI DSS), it delivers the visibility needed to demonstrate that access controls are in place, operating as intended, and aligned with business policy.

OpenAI Is In Trouble Again…..This Time With The Australian Government

Posted in Commentary with tags on September 24, 2026 by itnerd

Another day, another OpenAI agent going rogue. This time an OpenAI bot hacked an Australian government website:

Australia said on Thursday an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of an AI agent hacking a government website.

The breach is one of the highest-profile incidents of AI agents accessing external systems outside the United States, coming on top of several recent breaches globally by rogue AI agents that have alarmed governments and companies.

Prime Minister Anthony Albanese said the OpenAI agent gained unauthorised access to the medical statistics portal of Medicare, Australia’s universal health insurance programme, while conducting research on public medical spending.

“Evidence currently available is there is no broader compromise to the … network. Nonetheless, this situation is obviously unacceptable,” Albanese told reporters on Wednesday in New York, where he is attending the UN General Assembly.

Investigations continue and Australia has voiced its “extreme concern about this incident” to OpenAI CEO Sam Altman, Albanese said, adding that he was deeply disappointed by the company’s delay in notifying the government.  “It took until September 10 before there was any notification at all,” Albanese said, adding that the investigation would also examine why government systems had failed to detect the breach in the first place.

He also warned that three other government health-related websites may have been impacted by the OpenAI agent’s activity, but did not confirm that had occurred.

So OpenAI hacked a government website and OpenAI didn’t warn the Australian government that it had been hacked. That’s pretty bad. OpenAI said this in its defence:

In a statement, OpenAI said its “review found no evidence of patient records being accessed.” 

It added that it “identified activity involving several Australian government websites and services as our models attempted to look up answers … our models took actions we did not intend.”

So no harm, no foul? I don’t think so. OpenAI really needs to answer the question of why its agents keep going rogue. They haven’t done that here. But they need to do that because I don’t trust AI in general. And I don’t trust OpenAI products specifically. And I am sure others feel the same way. Especially after this latest hack.

UPDATE: Adrian Culley, Offensive Security Engineer, SafeBreach Said This:

“What’s notable isn’t that an AI agent found its way past a control — it’s that nobody built the agent to stop when it hit one. Told to answer a question, it treated an access restriction as an obstacle rather than a boundary, and kept working the problem until it got through.

Mapped to ATT&CK, the outcome looks ordinary: initial access via a public-facing service (T1190), then unauthorised collection. What’s genuinely new sits upstream of that: there was no adversary in the chain at all. MITRE ATLAS catalogues how attackers compromise AI systems — it has no entry for an AI system attacking everything else, because until now that direction of travel wasn’t the assumption anyone built a framework around.

Australia’s own cyber agency has now described this in general terms, not as a one-off — which means the same gap, an agent that doesn’t stop at ‘access denied’, is sitting against other public-facing services right now, untested.

Patch coverage doesn’t answer that. Only running the scenario does.”

UPDATE #2: Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech: 

“I understand that Australia wants to hold someone accountable for the hack, but it won’t be able to legislate the problem away. Rogue AI attacks will continue to happen no matter what the law says. Not least because the internet is global, and Australian laws don’t apply to the rest of the world. 

The attack would have been prevented if the data was properly secured in the first place, and that’s the lesson that should be learned here. AI is good at finding vulnerabilities but it’s not creating new ones. We should be using AI to run preemptive scans and plug the holes before attackers have a chance to find and exploit them with their own AI.”

UPDATE #3: More commentary has come in.

Seemant Sehgal, Founder & CEO, BreachLock:

“The way an autonomous agent works is by taking a goal and finding paths to complete it, including paths around obstacles. For that behavior to be safe when the agent is operating against real systems, the boundaries have to be enforced at the orchestration layer, not inside the model. The Australian incident shows what happens when they are not, with the agent encountering repeated blocks, finding ways through, accessing non-public files, and writing to an internal server.

“What needs to happen next is clearer notification obligations for AI providers when their agents touch systems they should not, because a three-month gap sent to a public inbox is not a disclosure timeline any critical infrastructure operator can plan around.”

John Strand, Owner, Black Hills Information Security:

“Yet again, we’re looking at another breach, and these things seem to be happening faster and faster. Yes, there has to be accountability. And I mean real legal accountability, not another slap on the wrist. If companies are allowing systems to break into organizations without authorization, there need to be serious consequences.

“But there’s another question that I don’t think we’re asking nearly enough. What exactly was the AI trying to do?

“If an AI agent writes files on a compromised system, what were those files? What was the objective? What actions led up to that point? What information was available to the agent when it selected that target? Can we reconstruct from the logs, prompts, tool calls, planning artifacts, and other telemetry why the system took those actions?

“If an AI system breaks into the Australian health department, saying that it hacked the organization and wrote some files isn’t enough. Why did it do it? What was it attempting to accomplish? If it broke into Hugging Face, why Hugging Face? What did the system seek to achieve?

“Every time one of these incidents happens, accountability matters. But understanding the behavior of the AI matters too. We need enough logging and transparency to reconstruct how an agent arrived at an unauthorized action and what objective it appeared to be pursuing.

“We have to stop treating these systems as simple programs that occasionally do something they weren’t supposed to do. Agentic systems can select actions, use tools, pursue intermediate objectives, and operate with significant autonomy. Understanding those actions and objectives is absolutely critical if we want to determine how worried we should actually be.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“The Australian Medicare incident is being used to argue for more regulation of frontier AI. That risks pulling the ladder up behind the companies already at the top. Large labs can absorb compliance costs and help shape the rules, while a new regulatory framework may still fail to stop an agent from bypassing access controls.

“Australia already has relevant criminal offences. Section 478.1 of the Criminal Code Act 1995 covers unauthorized access to or modification of restricted data. Section 477.2 covers unauthorized modification that impairs, or risks impairing, computer data or systems.

“Those laws do not need to understand neural networks. They need investigators willing to apply them when an AI system crosses a legal boundary. The model may have found the workaround, but the lab built and deployed it, gave it the objective, and controlled the operation.

“The effective deterrent is criminal enforcement. Preserve the prompts, tool calls, and access logs, identify the responsible people and companies, and bring charges where the evidence supports them. More regulation gives frontier labs another framework to negotiate. Enforcement gives them a reason to stop.”

Ryan McCurdy:

“An AI agent received a pretty ordinary research task. When it couldn’t get the information it wanted, it found another way in and accessed files it didn’t have permission to access.

“That problem gets much bigger as AI starts participating across the SDLC. Agents can interact with repositories, infrastructure, databases, and production systems to complete the tasks we give them. We can’t assume they’ll always take the path we expected.

“AI makes decisions based on probabilities. We can’t let those decisions automatically become production actions. Organizations need clear controls around what an agent can access, what it can change, and what policies it must meet before a change reaches production.

“The goal isn’t to put a human in front of every decision. We need to build the AI SDLC so agents can move quickly but the controls around critical systems remain deterministic.”

UPDATE #4: Rohit Valia, CEO of cybersecurity company Tumeryk,  provided the following comments:

“This incident shows how an ungoverned AI program can wreak havoc. By Prime Minister Albanese’s account, even Sam Altman acknowledged issues with OpenAI’s protocols. Without proper governance, agents are let loose with indiscriminate access to resources. The problem isn’t just model alignment with human values. It’s a complete lack of oversight over agents accessing external resources.”

Nikon Releases the Z5IIC Mirrorless Camera

Posted in Commentary with tags on September 24, 2026 by itnerd

Today, Nikon Canada Inc. announced the new Z5IIC, a compact, everyday-carry mirrorless camera designed to make the move to full-frame photography feel natural and approachable. Built on the proven performance of the award-winning Z5II, the Z5IIC combines a sleek, flat-top design with intuitive features such as Scene Modes, helping those beginning their photography journey achieve satisfying results without first mastering complex settings. Users can stay present and confidently capture spontaneous everyday moments with rich colour, natural depth and sharp detail, even in low light or motion-filled situations where smartphones may struggle.

The Z5IIC is designed around a screen-first shooting experience that helps users remain immersed in the moment. Omitting a viewfinder reduces the size of the camera but also keeps users connected to what’s going on around them. A beautiful touchscreen feels instantly familiar and invites a more casual, expressive way of shooting and sharing.

Capture The Spark: User-Friendly Features for First-Time Mirrorless Camera Users

The Z5IIC brings the proven performance of the Z5II into a more accessible, screen-centric design. Its 24.5-megapixel full-frame sensor, EXPEED 7 image-processing engine and advanced shooting capabilities deliver the impressive image quality and responsiveness users expect from a more advanced camera. Yet the “C” stands for casual: intuitive controls and automated features help first-time mirrorless users achieve satisfying photos and videos quickly, without first mastering complex camera settings. As their confidence and skills grow, the camera’s deeper controls and access to the NIKKOR Z lens system provide a dependable platform they can continue using for years. Key features include:

  • For the first time in a Nikon full-frame mirrorless camera, Scene Modes simplify the process of choosing the right settings for different subjects and situations. Users simply select the scene that best matches what they are photographing, and the camera automatically optimizes colour, brightness, white balance, Picture Control and other imaging settings. Fifteen Scene modes are available, ranging from portraits, pets and food to more challenging situations such as night landscapes and twilight, helping users capture each scene with settings tailored to the moment.
  • The Nikon Z5IIC features a dedicated button that gives users instant access to colourful and expressive Imaging Recipes, to easily capture impressive photos and video without concern for shooting settings. A full library of recipes, including those created by Nikon Ambassadors and leading creators is available on Nikon Imaging Cloud.
  • Fast, precise autofocus built on deep-learning technology automatically detects and tracks people, dogs, cats, birds, vehicles, aircraft and fish1 , helping maintain sharp focus on the intended subject, including locking into the eyes. For first-time full-frame users, reliable subject detection removes much of the guesswork, making it easier to capture sharp photos and video of fast-moving children, pets, sports and everyday moments.
  • Setting the Z5IIC to AUTO mode analyzes the subject and scene, then automatically optimizes autofocus, aperture, shutter speed and ISO sensitivity. This gives newer photographers a dependable starting point, helping them achieve satisfying results immediately while learning more advanced controls at their own pace.
  • Five-axis In-camera vibration reduction (VR) image stabilization with up to 7.5 stops2  of correction allows users to capture blur-free photos and shake free videos, even when the perfect shot presents itself unexpectedly.
  • The Z5IIC features the Film Grain function3 making it easy to capture photos and video with a nostalgic film look. This is a dynamic and organic-feeling film simulation that allows the user to adjust the size and intensity of the grain to suit their personal taste.


A Compact and Stylish Design Ideal for Everyday Carry

  • The smooth, streamlined flat-top design slips easily in and out of a bag, helping users keep the camera close and ready for everyday moments.
  • The Z5IIC is available in two colours; silver and black, allowing users to choose the one that best suits their preferences. The model is constructed of durable magnesium alloy for a premium, metallic feel. 
  • The Z5IIC’s new design weighs in at just 21.9 ounces / 620 grams, making it a must-pack companion for any excursion, whether it’s down the street or across the globe. 
  • The large and bright 3.2-inch vari-angle monitor enables shooting from a variety of positions, from low angles to over-the-head shots. The monitor can also be turned around for simple vlogging and selfies.  
  • Careful attention to dust- and drip-resistance, combined with a body that uses magnesium alloy in key areas for added rigidity lets users shoot confidently outdoors.


Outstanding Image Quality Made Possible by a Full-Frame Mirrorless Camera

  • The Z5IIC pairs a 24.5-megapixel Full Frame backside-illuminated CMOS sensor with Nikon’s EXPEED 7 image-processing engine – the same technology platform used in Nikon’s flagship cameras. Together with NIKKOR Z lenses, it captures rich colour, smooth sunset gradations, natural background blur and cleaner detail in dimly lit scenes. For first-time full-frame users, that means visibly superior photos and videos with less noise and blur, even when the light is challenging.
  • High-speed continuous shooting at up to approximately 14 fps enables users to capture the decisive moments of fast-moving subjects. Users can also shoot up to 15-30 fps for extreme speed.
  • The Pre-Release Capture function can be set to record up to one second before the shutter is released in High-Speed Frame Capture + 4  mode, which enables continuous shooting at up to 30 fps.


Video Features for all Kinds of Creators

  • The Z5IIC supports recording at frame sizes and rates up to 4K UHD at 60 fps 5 and Full HD at 120 fps, as well as slow-motion recording at 4× and 5× 6, making it easy to produce impressive short-form videos without post-processing.
  • When recording video, the REC lamp / tally light is lit and a red frame indicator is shown around the monitor display, so users know when they’re recording.
  • Product Review Mode smoothly shifts focus to an item brought close to the camera, making it easy to record review and product centric videos.
  • Support for H.265 10-bit (MOV) and N-Log 7 recording that enables users to take the next step into more advanced video production.
  • With UVC / UAC support, the camera can also be used for live streaming simply by connecting it to a PC via USB cable, and offers a range of video features.
  • Recording of N-RAW 8  video to an SD memory card is also supported, as well as N-LOG capture.


Price and Availability

The new Nikon Z5IIC will be available in mid-October 2026 for a manufacturer suggested retail price of $1,899.95* for the body only, or $2,339.95* with the NIKKOR Z 24-50mm f/4-6.3 lens. Soft bundles with the 26mm f/2.8 pancake, 28mm f/2.8 and 40mm f/2 will also be available through various retailers.

For more information about the latest Nikon products, including the vast collection of NIKKOR Z lenses and the entire line of Z series cameras, please visit nikon.ca.

AI set to help cyber attackers more than defenders, UK official warns 

Posted in Commentary with tags on September 23, 2026 by itnerd

The UK’s National Cyber Security Centre (NCSC) warned that artificial intelligence is currently positioned to provide greater advantages to cyber attackers than defenders, as attackers face fewer constraints when deploying AI autonomously.

Dave Chismon, the NCSC’s chief technology officer for architecture, said attackers can allow AI agents to operate with broad autonomy, while defenders must account for the risk that autonomous systems could disrupt or damage the networks they are intended to protect. This imbalance could allow AI-enabled attacks to scale faster than automated defenses.

The NCSC has also said AI is rapidly improving offensive capabilities, including vulnerability discovery and exploitation, while defensive uses such as automated mitigation and response carry risks including service disruption, data loss and operational failures.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“The NCSC’s warning that AI may favor attackers needs a harder qualification. Attackers cannot simply give an AI agent broad access and walk away.

“They still have to manage operational security (OPSEC), avoid attribution, control their infrastructure and stop the agent from creating evidence. If it scans the wrong target, contacts a victim or exposes the operator, the consequences can include arrest and prosecution. Criminal liability is a real constraint on offensive autonomy.

“Defenders carry a different risk. A security team whose AI-driven firewall change breaks a VPN may face an outage review, discipline or a lawsuit. The engineer does not usually face an arrest warrant because the agent made a bad change. That makes defensive autonomy a governance problem, not a simple question of whether the technology can act.

“Organizations should reduce that governance and organizational friction by creating pre-approved classes of low-risk, reversible actions, with clear asset ownership, deterministic validation and tested rollback. Changes with broad or uncertain impact should still require human approval. The goal is to remove unnecessary approval friction from routine remediation while keeping consequential actions gated.

“An attacker has to keep an AI agent quiet, scoped and out of the wrong network. A defender has to get an AI agent approved, tested and recoverable. The first is an OPSEC and criminal-liability problem. The second is governance and organizational friction, which defenders can reduce through better ownership, pre-approval and rollback design.”

Lydia Zhang, President & Co-Founder, Ridge Security Technology Inc.:

“The inconvenient truth that Chismon points out in this article has been the reality security teams have been dealing with for years: the imbalance between attackers and defenders in their ability to adopt and operationalize new technologies. AI has obviously widened that gap dramatically.

“But there is also a significant silver lining for defenders: many of the advantages AI gives attackers can also be turned toward defense. AI can help fix vulnerabilities early in the development lifecycle through automated patching, and it can also help remediate vulnerabilities in production.

“We recently demonstrated how an organization can practically combine a security testing tool with a code agent to reduce critical vulnerabilities from 10 to 0 in just four runs.

“So perhaps the challenge is no longer purely technical. The technology is increasingly capable. The bigger challenge is organizational: risk tolerance, processes, accountability, and mindset.”

Donald McFarlane, Board Member, Xcape Inc.:

“Treasury Secretary Scott Bessent articulated a useful starting point this week: accountability. Discussing the Hugging Face incident, he argued that responsibility rests with the humans and organizations deploying these systems, not with an AI agent treated as though it were an independent actor. He has also argued against shielding frontier labs from liability.

“I agree wholeheartedly with that basic principle. More specifically, liability should follow control, causation, intent and duty of care, rather than simply attaching every downstream harm to the person or company who trained the model.

“A malicious user deliberately employing AI to attack someone should bear primary responsibility. An operator that gives an agent powerful credentials, excessive authority and inadequate supervision should be responsible for negligent deployment. Integrators should be accountable for unsafe implementations. Model developers should remain responsible where foreseeable defects, or failures to exercise reasonable care in developing and testing their products, materially contribute to harm.

“That approach also recognizes that responsibility may be shared. Relevant questions would include who controlled what, what risks were reasonably foreseeable, what safeguards were available, and whose acts or omissions materially contributed to the outcome.

“The NCSC is also right that defenders cannot simply mirror attackers. Autonomous defensive action can itself disrupt the systems we are trying to protect, so greater autonomy has to come with governance, bounded authority, recoverability and clear human accountability. Its framework for evaluating potency, scope, criticality, rollout confidence and recoverability is a useful start.

“But I am more optimistic about the defensive side of this equation. AI gives defenders the opportunity to operate at machine speed as well. We should be designing systems that permit progressively greater autonomous action where it can be safely bounded and reversed. And cybersecurity has much to learn from military doctrine and tactics: deception, manoeuvre, shaping the battlespace and channeling adversaries toward ground of the defender’s choosing. AI can make those approaches substantially more powerful.

“AI is an extraordinarily powerful general-purpose technology. We need strong engineering, clearly assigned human accountability, meaningful incident reporting and judicially determinable duties of care. Autonomous software does not somehow break the chain of human responsibility, and we should not create regulatory barriers that only the largest incumbent laboratories can afford.”

John Strand, Owner, Black Hills Information Security:

“Absolutely, AI is going to create more attack opportunities simply because these systems have broad autonomy and more latitude in what they can do, especially when you start looking at open-weight models. But there’s another part of this that I don’t think people fully appreciate. Complexity is the enemy of computer security.

“The more services you have, the more attack surface you create. Even if those services don’t have known vulnerabilities today, AI can rapidly fuzz them, analyze them, and identify weaknesses that attackers may have previously overlooked because finding and exploiting them required significant time and skill.

“AI changes that equation. Vulnerabilities and exploitation opportunities that were previously out of reach for the average attacker are suddenly much more accessible. You no longer need to be an exceptionally skilled vulnerability researcher to find some of these weaknesses. AI can do a tremendous amount of that heavy lifting for you.”

Defenders always should have the advantage. Therefore the balance needs to be reset so that the good guys are the ones that win.

Exclaimer helps customers meet WCAG 2.1 AA accessibility requirements for email signatures

Posted in Commentary with tags on September 23, 2026 by itnerd

Exclaimer today announced the launch of Accessibility Controls, a collection of new and existing functionalities within Exclaimer that teams can use to ensure templates satisfy 28 WCAG 2.1 Level AA success criteria that apply to email signature content.

Most organizational accessibility work targets websites and apps. Email signatures are usually left out, even though they go out thousands of times a day and reach more external stakeholders directly than almost any other communication channel. In an email signature, something as simple as missing screen reader labels where links provide no context, missing alt text, or contact details embedded as an image rather than text can make important information inaccessible to someone using a screen reader.

For public sector and federally funded organizations in the US, accessibility requirements are becoming more prescriptive. The Department of Justice’s ADA Title II rule requires state and local government web content and mobile apps to meet WCAG 2.1 Level AA, with entities serving populations of 50,000 or more required to comply by April 26, 2027, and smaller entities and special district governments by April 26, 2028. Separately, organizations receiving HHS funding with 15 or more employees have until May 11, 2027, to bring web content and mobile apps into conformance with WCAG 2.1 Level AA under Section 504, while smaller recipients have until May 10, 2028. These rules do not set specific deadlines for email signatures, but they reflect growing regulatory focus on how organizations make digital information accessible.

How Accessibility Controls work

Exclaimer’s Accessibility Controls covers four capabilities inside the signature designer, some automatic and some configured by the template owner:

1. Semantic structure. Signatures are built and output as structured, readable content rather than a table, so screen readers announce information in the order it’s laid out.

2. Screen reader (ARIA) labels. Interactive elements like hyperlinks can carry a descriptive label, so a screen reader says “Book a demo with our team” instead of “link.”

3. Language declaration. Signatures can declare their language so screen readers use correct pronunciation, useful for organizations sending signatures in more than one language.

4. Clickable QR codes. QR codes in a signature are made more clickable, giving recipients who can’t or don’t want to scan a code a working path to the same destination.

These sit alongside existing controls: alt text set centrally at the template level, Brand Kits that keep approved color combinations and accessible fonts at or above WCAG’s minimum 4.5:1 contrast ratio for standard text, and text that renders as real HTML rather than an image, so it can be resized and read aloud.

A first for email signature management

Of the 50 Level A and AA success criteria in WCAG 2.1, 28 apply to content like an email signature. Exclaimer is the first and only email signature management provider to offer native functionality addressing all 28, without requiring customers to write HTML.

Set at the template level, Accessibility Controls apply across an organization’s email signatures in Microsoft 365 and Google Workspace as soon as a template is published, with no need to touch individual employee signatures.

Availability

Accessibility Controls is available now within the Exclaimer signature designer, as part of Exclaimer’s existing plans, for customers on Microsoft 365 and Google Workspace.