FBI pwned by ShinyHunters

Posted in Commentary with tags on September 22, 2026 by itnerd

It’s been reported today that threat actor group ShinyHunters have said to 404 Media via the story ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees:

A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse.

The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies who want to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety.

“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative of the group told 404 Media.

Denis Calderone, CTO, Suzu Labs Had This To Say:

“ShinyHunters has spent the last week picking fights. On Friday they took over Cl0p’s leak site and put up a ‘seized by ShinyHunters’ banner, and by Tuesday the same banner was on the FBI’s jobs portal. Both were framed as payback, one for threats from a rival gang and one for an FBI advisory that told victims not to pay them. The FBI hasn’t confirmed anything yet, but if this holds up, it doesn’t look like the ShinyHunters we’ve been seeing all year. Their model has always been breach, extort, then settle or leak, and that only works when the victim can pay. The FBI isn’t going to pay, and it isn’t going to pull an advisory because a criminal group demanded it. Not sure what’s going to happen in a week, but I seriously doubt the FBI will act on this threat.

“They also say this isn’t financially motivated, but I’d take that with a grain of salt. I have a hard time believing terabytes of FBI personnel data just sit on a shelf. Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data. Meanwhile, agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.

“That zero-day is where everyone else should focus, since ShinyHunters says they plan to use it more broadly. If you run PeopleSoft, don’t wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren’t reachable from outside. Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud.”

“Limiting your blast radius is the best precautionary play here.”

If the FBI did get pwned, then that’s a hell of a black mark on the FBI. You have to wonder what the FBI has to say about that. Let’s see if they dare to comment.

EU auditors find critical gaps in response to large-scale cyberattacks

Posted in Commentary with tags on September 22, 2026 by itnerd

The European Court of Auditors has found significant gaps in the EU’s ability to coordinate its response to major cybersecurity incidents, particularly when sharing timely and actionable information between national and EU-level organizations.

The audit found that cooperation between two key cyber response networks has still not been formally defined, while differences in national security laws and implementation of the NIS2 Directive can hinder information sharing. The European Cybersecurity Alert System was also not operational at the time of the audit, with two security hubs delayed by procurement issues and key cooperation agreements, technical standards and classification systems still missing.

Auditors also identified overlapping responsibilities among EU cybersecurity bodies and weaknesses in checks on organizations receiving EU cybersecurity funding. The findings come despite €1.4 billion being allocated to cybersecurity through the EU’s Digital Europe Programme for 2021–2027.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Critical infrastructure crosses borders faster than authority does. A state-backed attacker can probe the same router or remote-access service across energy, transport, healthcare, telecoms, and water. The first defender to see the intrusion needs a way to warn every operator running the same technology.

“The European Court of Auditors’ audit shows why that warning can stall. National response teams, EU-CyCLONe, and the European Union Agency for Cybersecurity operate across different security laws, NIS2 implementations, classifications, and mandates. During an active incident, a technical warning becomes a permissions problem.

“CISA’s Automated Indicator Sharing moves machine-readable indicators and defensive measures in real time. The Joint Cyber Defense Collaborative adds playbooks and rapid exchanges across government, industry, and international partners. Europe needs those functions tied to its existing institutions, with shared rules for confidence, urgency, and action.

“I would measure the investment by one clock, the time between an energy operator seeing a state-backed probe and every similarly exposed operator receiving something usable. Every unresolved permission is attack surface.”

John Strand, Owner, Black Hills Information Security:

“There is absolutely nothing about this report that surprises me. It really doesn’t matter what type of organization you’re dealing with. It could be nation-states trying to coordinate during an incident, or internal security teams working inside the same company. You’re going to see the same communication gaps, overlaps, and confusion.

“My recommendation is simple. Drill. Run incident response tabletop exercises regularly. Keep them terse. Keep them quick. Don’t make them overly complicated. Run multiple scenarios specifically designed to expose where communication starts to break down.

“Then document those gaps and build a plan of action and milestones to fix them. Communication problems during an incident aren’t unusual. I would expect to find them in almost any organization. The important question is whether you find them during an exercise or during a real incident.”

Seemant Sehgal, Founder & CEO, BreachLock:

“The audit findings track with a pattern that shows up in a lot of large organizations trying to coordinate incident response across independent teams. Frameworks describe how the handoffs should work, but during a live incident, the seams where responsibilities were never clearly assigned are where delays happen, and 1.4 billion euros in funding does not close that gap on its own if the operational agreements underneath it are still being negotiated.

“The useful question is whether the ECA report will apply enough pressure to get the European Cybersecurity Alert System operational and to define those handoffs before the next major incident, rather than during one.”

Co-ordinating any sorts of incidents is key to bringing them under control quickly. And if anyone has the will to do it, the EU does. So I hope that they don’t prove me wrong.

ESET Research: China-aligned FamousSparrow expands operations in Latin America, targets governments with new backdoor

Posted in Commentary with tags on September 22, 2026 by itnerd

ESET Research’s ongoing monitoring of FamousSparrow discovered that the China-aligned APT group had developed a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025. In what was probably China’s reaction to the U.S.showing increased interest in Latin America, FamousSparrow increased its extensive targeting of governmental organizations there. ESET researchers chose to name the backdoor SparroWocky because the first samples collected all contained the first stanza of “Jabberwocky,” a nonsense poem by English author, poet, and mathematician Lewis Carroll (author of Alice’s Adventures in Wonderland).

SparroWocky is a modular C++ backdoor. Its architecture and the techniques used by its authors indicate strong knowledge of anti-analysis tricks and Windows internals. With the switch to SparroWocky, FamousSparrow started to incorporate code from open-source projects directly into its malware.  “Fortunately, while advanced, SparroWocky’s inner workings are much less arcane than a ‘gyre and gimble in the wabe,’ so a ‘through and through [of] the vorpal blade’ allowed us to bring you a detailed analysis of the backdoor,” quotes ESET researcher Alexandre Côté Cyr from the world-famous poem. Côté Cyr made the latest discovery during his investigation of the China-aligned group.

This cyberespionage trend against high-profile targets in Latin America started no later than in July 2025 and has continued with the more recent introduction of SparroWocky. In fact, from mid-2025 and into 2026, 90% of the group’s targets registered in ESET telemetry have been located in the region. “We have seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. This represents a rare occurrence among the China-aligned APT groups that ESET tracks, which are generally observed throughout various world regions within such an extended time frame,” says Côté Cyr.

ESET believes that this undivided focus is not coincidental and likely reflects China’s reaction to various recent U.S.initiatives in the region. Indeed, U.S. President Donald Trump’s second term has brought about an aggressive reaffirmation of U.S. interests in Latin America, which threatens various long-term investments that China has cultivated throughout the continent over the last decade, in domains such as energy, mining, and telecommunications. FamousSparrow’s activities are probably intended to help China better monitor and anticipate the reaction of local governments to current U.S. pressures. In some cases, certain elements clearly seem to confirm this hypothesis. For instance, one of the Panamanian entities targeted is directly involved in the ongoing commercial dispute regarding two major ports located in the canal area, which were, until recently, operated by a China-based company. 

Some of SparroWocky’s notable features include the ability to launch arbitrary files, to act as a TCP proxy, and to execute commands. The backdoor also collects general information about the compromised machine, such as the computer name, username, domain name, Windows version, and IP addresses of its network interfaces. SparroWocky is also capable of exfiltrating files and taking screenshots periodically. Exfiltrated information is encrypted using RC4 and sent over the TLS protocol. Depending on its configuration, SparroWocky can establish persistence either by creating a dedicated service or an entry in a registry Run key. 

The malware employs a few techniques to complicate its analysis and to evade security software that may be in place.The backdoor manipulates low-level structures in memory, and patches code at runtime in order to avoid detection.FamousSparrow still uses open-source offensive tooling for its own malicious ends. Previously, these tools were mainly used side by side with the group’s backdoor. With SparroWocky, ESET researchers observe that it also has the development capabilities to integrate open-source code directly into its own custom backdoor. SparroWocky has the capability to load and execute Beacon Object Files, a special type of executable file supported by many red-teaming and penetration-testing tools.

FamousSparrow is a China-aligned cyberespionage group believed to have been active since at least 2019. ESET Research first publicly documented the group in a blogpost from September 2021, when it exploited the ProxyLogonvulnerability. The group was initially known for targeting hotels around the world but has also targeted governments, international organizations, trade groups, engineering companies, and law firms. 

ESET attributes the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor. Moreover, not only does the victimology match FamousSparrow’s previous targeting, but ESET also recorded attempts to deploy SparroWocky at many of the same organizations that had previously been targeted with SparrowDoor. FamousSparrow is the only known user of the SparrowDoor backdoor. 

For a more details and technical analysis of SparroWocky, check out the ESET Research blog post “Beware the SparroWock: The backdoor that bites, the commands that catch” on WeLiveSecurity.com.

GAO finds FAA aircraft communications vulnerable to hacking and jamming

Posted in Commentary with tags on September 22, 2026 by itnerd

A new U.S. Government Accountability Office (GAO) report found that communications between air traffic controllers and commercial aircraft remain vulnerable to cyber and electromagnetic threats, including interception, spoofing and jamming.

GAO also found that text-based aircraft communication systems have vulnerabilities related to authentication, encryption and protocol design. The agency found that while the FAA has identified spectrum-related threats, it lacks tools to continuously monitor for them in real time and can generally investigate incidents only after they are reported.

The Department of Transportation, responding on behalf of the FAA, agreed with all nine of GAO’s recommendations. The report was released the same day as a telecommunications failure involving a severed backup fiber line that caused the FAA to halt incoming flights at several major Northeast airports, contributing to roughly 7,000 delayed or canceled flights nationwide. The disruption was not attributed to a cyberattack.

Damon Small, Board of Directors, Xcape Inc.:

“Unencrypted and unauthenticated aviation data links expose national airspace operations to severe financial disruptions, safety risks, and systemic operational failures. A recent Government Accountability Office (GAO) report reveals that legacy text-based communications lack cryptographic authentication and protocol integrity, leaving air traffic control (ATC) systems vulnerable to active spoofing, jamming, and interception.

“The nine recommendations from the GAO are valid, but they also show how far behind the Federal Aviation Administration (FAA) is in protecting and maintaining its aging infrastructure, a frightening prospect given that millions of passengers and crew depend on it every day. Furthermore, a single fiber cut led to the disruption of ATC in the northeastern United States, demonstrating a severe lack of redundancy in these safety-critical systems. Aviation executives and government leaders must prioritize implementing cryptographic payload signing across aircraft messaging systems, deploying continuous automated spectrum monitoring tools, and engineering true physical resiliency into ground network backbones.

“Critical Takeaways:

  • Valid GAO recommendations highlight how far behind the FAA remains in securing legacy aviation infrastructure against radio frequency spoofing and jamming.
  • A single severed fiber line disrupting northeastern air traffic control exposes a critical lack of redundancy in safety-critical ground networks.
  • Aviation leaders must enforce cryptographic authentication on text communications and deploy real-time spectrum monitoring equipment.

“Relying on post-incident investigations for radio frequency jamming in aviation is like buying a smoke detector after the house burns down.”

John Strand, Owner, Black Hills Information Security:

“The biggest concern with this report isn’t necessarily the findings. It’s how difficult the recommended fixes may be to implement.

“With a lot of standard technology, you patch it, update it, and move on. But when you’re dealing with the FAA and critical infrastructure, these are real-time systems where the tolerance for downtime or errors is basically zero.

“Even changes that look simple on paper can become incredibly complicated and expensive because of the systems involved and the requirement to keep them running. I applaud the report. It looks like they found some very real issues. The problem is that fixing them could be extremely expensive and take a significant amount of time.

“And time is the part that worries me. We’re already seeing attackers targeting critical infrastructure. We don’t have the luxury of assuming they’ll wait for us to finish fixing it.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“As a pilot, I cannot treat a clearance like an email that can wait for a second look. Under Instrument Flight Rules (IFR), crews may be flying by instruments with limited outside visual reference while responding quickly to a tower or controller. If the channel becomes suspect, every clearance becomes a verification problem as well as an instruction.

“The Government Accountability Office (GAO) findings show the trust problem inside the communications system. FAA lacks continuous, real-time detection for all spectrum-related threats. Aircraft Communications Addressing and Reporting System (ACARS) and Controller Pilot Data Link Communications (CPDLC) still depend on procedural checks because they lack cryptographic authentication and message integrity. Voice confirmation adds workload without proving message origin or integrity.

“Monday’s fiber outage showed the visible failure mode. A broken link produces silence. Spoofing creates a harder failure mode because the link can stay open while the message is false. I would treat live monitoring and authentication as urgent fixes.

“The FAA needs to distinguish an unavailable link from jamming or spoofing during operations. Until then, pilots and controllers remain the last security control in the loop, manually compensating for a network that cannot authenticate its messages.”

I have to ask if this is being truly taken care of at in order to make this go away. That’s the real question and I hope that someone has an answer.

Operation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures

Posted in Commentary with tags on September 22, 2026 by itnerd

Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs.

Recently, the SOCRadar Threat Research Unit (STRU) uncovered Operation Conflict Compass, a targeted campaign by the DPRK-aligned actor Konni, aimed at gathering intelligence on the ongoing trajectory of the Russian invasion of Ukraine.

Key points: 

  • Spear-phishing ZIPs with LNK files disguised as PDFs, using Russia-Ukraine peace framework. Targeting potentially points to diplomatic entities, think tanks, and NGOs.
  • The chain sets up a scheduled task that runs a PowerShell downloader STRU named VelvetCake every minute. It keeps almost no capability on the host, pulling and running server-side scripts on demand, then wiping its artifacts.
  • A recovered second-stage script performs host enumeration and screen capture, exfiltrated over HTTP POST.
  • The same components were also delivered via a trojanized Zoom installer.
  • Attribution to Konni is moderate confidence: targeting, VelvetCake code characteristics, shared C2 and GitHub staging infrastructure, and operator time zone. 

For full details, the research can be read here: https://socradar.io/blog/operation-conflict-compass-konni-ukraine-lnk-lure/

npm Supply chain attack built trust before delivering malware

Posted in Commentary with tags on September 22, 2026 by itnerd

Checkmarx just disclosed an npm supply chain attack where a malicious package, indexed-btree, mimicked a legitimate B-tree utility and reached 2 million weekly downloads before detection, hiding its payload in the package’s prototype method and using a fabricated GitHub commit history to look credible. Related packages in the same campaign topped 5 million downloads before removal.

Checkmarx has a post about the incident here: Update: Ongoing Checkmarx Supply Chain Security Incident

Justin Beals, CEO & Founder, Strike Graph, an AI-native GRC and compliance automation platform had this to say:

“This campaign worked because the attacker understood what security teams actually check. They didn’t need a fast-spreading package that trips alarms. They built a GitHub history with real-looking commits and let the package earn trust the slow way, then hid the payload inside a prototype method nobody audits line by line. Two million weekly downloads means this package sat inside production code at a huge number of companies, and none of their vendor questionnaires or install-time scanners caught it, because the malicious behavior only fires when the code actually runs.

This is the same failure I keep coming back to with third-party risk. We ask vendors to attest that their code is safe and call that due diligence. A GitHub repo with a clean commit history is exactly the kind of thing that passes an attestation. It doesn’t tell you what the code does when it executes. Teams need to know what every dependency in their stack is actually doing at runtime, not just whether the maintainer looks credible on paper.

Package registries are going to keep getting hit this way because the economics work. A threat actor spends a few months building trust and walks away with hundreds of thousands of dollars and access to millions of environments. Until organizations start validating dependency behavior continuously instead of trusting a package because it looks established, this pattern repeats.”

You only are secure as those you work with. This is not a new thing that I’ve said. The question is, when will organizations get a clue about this and take the right action to make this less of a threat.

Sell Smarter, Not Louder: Intuit Mailchimp Research Shows Smarter Marketing Strategies Increase Sales During Peak Holiday Shopping Season

Posted in Commentary with tags on September 22, 2026 by itnerd

As Canadian businesses prepare for the 2026 holiday season, a new global report from Intuit Mailchimp unveils some unique insights and trends on how smart digital marketing can help online retailers cut through the clutter to increase leads and sales among Canadian online shoppers. Developed by Intuit Mailchimp and Datalily, the global report, Breaking Through Peak Season Noise, analyzed more than 44 billion emails, (1.85 billion emails from Canada) and 83 million text messages (1.2 million text messages sent by Mailchimp users in Canada) sent with Mailchimp during last year’s peak season, which spans Halloween through New Year’s Eve. The report found that Canadian online shoppers better respond to personalized emails compared to their global counterparts. During peak season, ecommerce stores that sent personalized emails saw a 33% higher average order value than those using generic emails. The impact of a personalized approach was even more prominent during Canadian Black Friday/Cyber Monday (BFCM) weekend, with ecommerce stores seeing a 49% higher average order value from tailored emails. Globally, personalized emails saw only an 11% lift in average order value during BFCM weekend.

Generative AI is playing a role in businesses getting to know their customers. According to the Canadian findings, emails that used generative AI saw a 4x higher order rate and a 4x higher conversion rate than those that didn’t. 

Furthermore, the importance of deepening client relationships and its impact on revenue is also evident from the research, especially in Canada. Nearly two-thirds (67.3%) of email orders among Canadian Mailchimp customers during BFCM came from repeat customers. While globally, repeat customers accounted for only 41%.

However, attracting new customers still matters. Canadian Mailchimp customers added 18.3 million new email subscriptions during the peak season. This represents a significant opportunity to build long-lasting relationships with those first-time customers by using smarter choices around targeting, timing, and channel strategy, helping brands find an edge during the most competitive marketing season of the year.

Additional Key Findings from the Global Report

  • Use data and automation to increase relevancy. Globally, campaigns using abandoned cart content blocks also saw 36% higher open rates and 28% higher click rates, showing the potential of using customer data and automation to reach shoppers with more relevant messages.
  • Email and SMS played different but complementary roles. Email sustained communication and drove more revenue overall, while SMS captured attention during high-intent, time-sensitive moments. At peak, SMS delivered up to 6x higher order rates than email and 3x higher revenue per message. Among Mailchimp customers using both channels during BFCM, SMS drove nearly 20% of their total combined ecommerce revenue. 
  • Generative AI emails saw stronger performance. During peak season, 450 million emails used generative AI. Emails using the feature saw a 50% higher order rate and 33% higher conversion rate than those sent without it, pointing to the potential of AI to help marketers create content that performs.
  • Lower-volume days revealed overlooked opportunities. Weekend order rates were 2x higher than weekday rates, even though brands sent roughly 60% fewer messages on weekends. Around BFCM, shoulder days also drove stronger engagement, while the Sunday between Black Friday and Cyber Monday saw 59% fewer emails and 82% fewer text messages than Black Friday.

Download Breaking Through Peak Season Noise for interactive charts, practical recommendations, and full methodology.

About Intuit

Intuit is the global financial technology platform that powers prosperity for the people and communities we serve. With approximately 100 million customers worldwide using products such as TurboTax, Credit Karma, QuickBooks, Mailchimp and Intuit Enterprise Suite, we believe that everyone should have the opportunity to prosper. We never stop working to find new, innovative ways to make that possible. Please visit Intuit.com and find us on social for the latest information about Intuit and our products and services.

Methodology

This report was created in collaboration with Datalily. Unless otherwise noted, metrics presented in this report are based on internal aggregate global data of active Mailchimp free and paid plan users evaluated across two primary observation windows: Peak Season 2025 (October 31, 2025, to December 31, 2025) and Black Friday Cyber Monday (BFCM) 2025 (November 28, 2025, to December 1, 2025). All revenue, gross order value, Average Order Value (AOV), order rate, and conversion rate metrics apply specifically to Mailchimp users with a connected e-commerce store. Revenue metrics reflect gross e-commerce sales synced to Mailchimp and attributable to email and/or SMS campaigns (excluding orders synced via the QuickBooks integration). SMS metrics reflect markets where Mailchimp SMS was commercially available during the observation period. Past performance does not guarantee future results. Individual results and regional feature availability vary. 

Wagepoint ends the two-system workaround for Québec payroll with new launch

Posted in Commentary with tags on September 22, 2026 by itnerd

Wagepoint, a leading provider of payroll software for small businesses (SMBs) across Canada, today launched unified Québec payroll compliance with complete platform functionality in both French and English. Businesses with employees in Québec no longer need a second payroll system or a manual process. Québec-specific requirements can now run inside the same workflow used across the rest of Canada.

Québec is one of Canada’s largest small-business markets, with more than 228,000 small employer businesses with 1 to 99 employees, according to the latest ISED Canada Key Small Business Statistics report. For many small businesses, Québec payroll has meant extra work for a long time. Québec is the only province that administers its own income tax, so employers remit separately to Revenu Québec on top of Canada Revenue Agency. As a result, businesses with staff in Québec and elsewhere in Canada often face duplicative efforts in managing separate provincial programs and contributions, including the Québec Pension Plan (QPP), Québec Parental Insurance Plan (QPIP) and Health Services Fund, with remittances handled through Revenu Québec.

That complexity compounds an already common problem: 75% of Canadian employees experience a payroll error in a given year, according to Deloitte and the National Payroll Institute. Wagepoint is built to close that gap for small businesses and for the accounting and bookkeeping firms who support them.

Québec payroll, built into the same workflow

Key Québec payroll requirements are now handled inside the platform, in the same workflow used in every other province:

  • Revenu Québec remittances
  • CNESST, Health Services Fund, QPP and QPP2, and QPIP calculations and remittances
  • RL-1 reporting
  • Québec statutory holiday pay using the 1/20 rule
  • Québec income, deduction and benefit codes, with the option to build custom codes
  • A complete workflow in English or French set at the user level
  • Simple, comprehensive pricing with no add-on fees for accounting software integrations, reporting, timesheets, or multi-province support

Wagepoint has worked with small businesses in Québec — and the accounting and bookkeeping firms that serve them — for years, handling payroll realities not found anywhere else in Canada. This launch brings that work fully into the same platform used across the country in the language of choice for employers and employees alike.

For owners in retail, food service, health services and professional services, who run payroll themselves alongside everything else in the day, that means one system and one process no matter where their employees are. For multi-province accounting and bookkeeping firms, it means Québec clients can move onto the same platform as the rest of their client base, while still getting the Québec-specific functionality they need.

Québec payroll is included in Wagepoint at no additional cost.

See how simple Québec payroll can be. Book a demo in French at https://www.wagepoint.com/fr/reserver-une-demo/

Darktrace announces Secure AI, brings behavioral security to enterprise AI 

Posted in Commentary with tags on September 22, 2026 by itnerd

Darktrace announced the general availability of Darktrace / SECURE AI, extending its self-learning, behavioral approach to AI systems, agents, development environments and shadow AI. Please find the press release here, and screenshots of the product attached.

Key details include:

  • Shadow AI Management: Identifies unsanctioned AI activity through Darktrace telemetry and SASE integrations, including Microsoft Entra Global Secure. Security teams can distinguish unauthorized tools from approved services, address blind spots and refine policies that reduce risk.
  • AI Prompt Analysis: Monitors prompts, sessions and responses across supported platforms in real time. It detects attempted jailbreaks, sensitive data exposure and potential indirect prompt injection, then ranks sessions by risk so analysts can focus investigations.
  • Policy Management: Allows security teams to upload free-form, organization-specific policies, assess how well those controls work and refine governance beyond standard frameworks.
  • AI Agent Identities and Actions: Connects AI activity to agents and human users across supported environments, with visibility into identities, permissions, roles, access and relationships.
  • AI Agent Development Risk Management: Extends monitoring across low-code and high-code development platforms to identify agent identities, excessive permissions, misconfigurations and anomalous activity. It also connects how agents are built with how they behave after deployment.

During one 28-day period, Darktrace also identified 2,945 instances of sensitive data entered into AI prompts across roughly 28,000 users, with more than 70% involving credentials, passwords or API keys.

Samsung Canada survey finds tech helps Canadians move faster, but digital busywork is still getting in the way

Posted in Commentary with tags on September 22, 2026 by itnerd

New research from Samsung Canada reveals a growing productivity paradox, with technology amplifying both capability and complexity in everyday life.

Three-quarters (75%) of Canadians say technology helps them get things done faster, yet 68% say it also gives them more to manage, according to a new survey of 1,547 adults. The tension even extends to Gen Z, as more than half say manual steps and app switching stand in the way of getting things done.

The data points to a clear expectation from Canadians: Technology should not only help them accomplish their goals, but also simplify the steps along the way. More than half (57%) agree that the more digital tools they use, the more they have to manage.

Digital Friction Creates Extra Work

For many Canadians, extra work shows up in routine digital tasks at least a few times a week:

  • Messages and notifications: 77% say managing messages and notifications creates unnecessary effort or slows them down
  • Searching for information: 70% say searching for information they know they’ve already received or seen creates unnecessary effort or slows them down
  • Competing demands: 66% say keeping track of multiple tasks or conversations at once creates unnecessary effort or slows them down.
  • Switching between apps: 62% say moving between apps or digital services creates unnecessary effort or slows them down

The effects extend beyond time lost. At least a few times per week, 59% of Canadians say they feel mentally drained or overwhelmed when technology, information or competing priorities make it harder to get things done, while 57% spend more time deciding what to do next than actually doing it. And nearly half (46%) agree they often end the day feeling busy without feeling as productive as expected.

The findings reveal an opportunity for mobile experiences to reduce some of those everyday challenges. Samsung Galaxy devices bring AI-powered features into the moments people need them, with tools like Now Brief[1] and Now Nudge helping users stay on top of relevant information and trim their to-do lists in fewer steps.

Gen Z Is Ready For AI To Do More

Even for Gen Z, growing up with technology hasn’t eliminated digital friction. More than half of Gen Z (58%) agree to spending too much time on manual steps just to make technology work, while 51% say switching between apps or digital services creates unnecessary effort or slows them down at least daily. More than half (53%) feel mentally drained or overwhelmed at least daily when technology, information or competing priorities get in the way.

At the same time, Gen Z is highly receptive to AI that works harder for them: 83% selected at least one AI feature as potentially valuable for helping them get things done with less effort.

Canadians Want AI To Tackle Busywork

Two-thirds of Canadians (66%) selected at least one AI feature as being potentially valuable for helping them get things done with less effort. They see value in simplifying information, automating repetitive tasks, supporting decision making and bringing information together across apps and services.

The same desire for simplicity extends to everyday mobile experiences. Reducing the number of steps needed to complete a task was the most frequently selected improvement (38%), followed by bringing relevant information together rather than searching across apps (30%).

Other priorities included completing more tasks without switching devices (29%), moving between tasks without losing their place (29%), reducing distractions (25%) and viewing multiple pieces of information at once (23%).