The CISA cuts critical infrastructure security services, concerns grow over the shrinking agency 

Posted in Commentary with tags on September 5, 2026 by itnerd

The CISA is ending six free cybersecurity assessment programs used by critical infrastructure operators to identify weaknesses in their defenses against ransomware, supply-chain attacks and other cyber threats.

The cuts include Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys.

The assessments provided hands-on assistance from CISA regional advisers to organizations including water utilities, hospitals, local governments and other operators that may not have the resources to pay for comparable private-sector security reviews. CISA says it is retiring the programs to reduce redundancy and will instead direct organizations toward its Cross-Sector Cybersecurity Performance Goals.

The move comes amid broader concerns about CISA’s ability to protect U.S. critical infrastructure following significant reductions in its workforce and budget. The agency has lost roughly one-third of its workforce, while its 2026 budget was cut by approximately $300 million.

Denis Calderone, CTO, Suzu Labs:

“My apologies to those I told to leverage these free resources recently. We’ve been pointing to those how lacked the bigger budgets to the CISA’s assessment programs. All six programs are gone now. The replacement is a self-service questionnaire that the people who built the original tools say doesn’t do the same job.

“The timing here stinks. CISA is weeks away from finalizing CIRCIA, which will require critical infrastructure operators to report cyber incidents within 72 hours and ransomware payments within 24 hours, and this comes just as they take away the testing tools. But, To be fair, we don’t really know how widely adopted these programs were in the first place. The scope is huge with 50,000 small water utilities alone, we doubt that CISA’s regional staff was ever going to reach all of them, and there’s no public data showing how many operators actually used the assessments or what the measurable impact was.

“We’ve been worried about CISA’s capacity all year. The agency lost roughly a third of its workforce over the last 18 months. When DHS announced plans to hire 600 new staff and CISA started extending offers for 329 mission-critical positions, it felt like maybe the rebuilding was starting. But as of late August, it’s unclear how many of those hires have actually come on board, and now we’re watching assessment programs get cut instead. This during a year where critical infrastructure attacks are continuing to increase.

“CSET is open source and older versions on GitHub still include all six retired assessment modules. CSET measures where you actually stand against specific security standards. The CPGs that CISA is pointing everyone toward are a prioritization framework that helps you figure out where to focus. They’re complementary tools, not interchangeable ones. Use CSET to diagnose your current state, then use the CPGs to prioritize what to fix first. What you won’t get anymore is a CISA regional adviser helping you interpret the results, but using both tools together is still better than using either one alone. Several states are also stepping up direct cybersecurity support for local operators. And if you’re a water utility, keep an eye on Project Watershed 250. It just launched in Texas with free vulnerability assessments and red-teaming, and it’s supposed to expand nationally.”

John Strand, Owner, Black Hills Information Security, Inc.:

“Do the people making these decisions have any access to the news?

“Right now, our critical infrastructure is under attack at a level we simply have not seen before. Water systems, energy, telecommunications, municipalities, and other critical infrastructure are actively being targeted. CISA itself warned in July about ongoing Iranian-affiliated attacks against operational technology and PLCs across multiple U.S. critical infrastructure sectors.

“And this is the moment we decide to start cutting the programs designed to help these organizations defend themselves?

“CISA is eliminating six free cybersecurity assessment programs used by critical infrastructure organizations, including ransomware readiness, cyber resilience, incident management, and infrastructure assessments. Many of the organizations relying on these programs are exactly the organizations that do not have the money or personnel to replace them with commercial services.

“This is crazy.

“We should be dramatically increasing the resources available to critical infrastructure organizations right now. We should be expanding free assessments, threat intelligence, training, and technical assistance, especially for small municipalities, rural hospitals, water systems, and utilities that simply cannot afford large cybersecurity programs.

“Instead, we’re pulling resources away from them while the attacks are increasing.”

The White House and the US government are failing US citizens when the CISA is needed the most. And they will likely come to the conclusion after they get pwned by everyone rather than taking proactive measures to stop that from happening.

OpenAI commits $1B to AI cyber defense for critical infrastructure 

Posted in Commentary with tags on September 5, 2026 by itnerd

OpenAI has committed $1 billion in subsidized access to its AI cybersecurity tools, training and technical support through its new Daybreak for Frontline Defenders initiative, targeting organizations that protect critical infrastructure and essential services.

The initiative will prioritize resource-constrained organizations including water and wastewater systems, electric grid operators, state and local governments, community and regional banks, nonprofits and open-source maintainers. OpenAI says the $1 billion commitment is targeted to be consumed over the next six months.

OpenAI is also launching a public-sector and water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC) that will pair Daybreak access with guided training and hands-on assistance for an initial group of public-sector and water-system defenders.

The initiative comes as critical infrastructure operators face growing cybersecurity threats while many smaller organizations continue to operate with limited staff, budgets and specialized security expertise.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“OpenAI’s Daybreak for Frontline Defenders commits $1 billion in subsidized access to its cyber models for water utilities, electric grid operators, and other under-resourced critical service providers. I like the direction. I’m skeptical about the bottleneck it targets.

“I’ve been saying since GPT-5.6-Cyber launched that AI is moving the bottleneck from vulnerability discovery to remediation. Small water systems and municipal networks already know they’re running outdated systems with known vulnerabilities. They lack the engineering staff to fix what they find, the governance to deploy changes safely, and the test environments to validate fixes before production.

“Greg Brockman demoed Codex on his personal website at the summit. A personal website isn’t a water treatment Supervisory Control and Data Acquisition (SCADA) system, where a configuration change that makes security sense can break the physical process that keeps water flowing. Without engineers who understand the plant, AI becomes a force accelerant in the wrong direction, generating fixes faster than understaffed teams can review them.

“The Multi-State Information Sharing and Analysis Center (MS-ISAC) training pilot matters more than the $1 billion headline. If that training doesn’t scale alongside the credits, these organizations end up with an AI generating recommendations and nobody qualified to tell the good fixes from the dangerous ones.”

John Strand, Owner, Black Hills Information Security, Inc.:

“In all seriousness, I think it’s fantastic that they’re putting some money toward this and actually trying to get these organizations the help they desperately need. There are a lot of organizations out there that simply don’t have the budget or the resources to do this properly, so getting them some assistance is absolutely a good thing.

“But there’s also the humorous flip side of this. This is basically how you get people hooked on crack. You give them a sample. You get them set up. You show them how good it is. And then suddenly they’re hooked for life.”

Joshua Marpet, Senior Product Security Consultant, Finite State:

“OpenAI is jumping on the bandwagon to help utilities. Considering that there are over 150k water utilities in this country, and there are only several hundred in the Water-ISAC (Information Sharing and Analysis Center), theres a huge gap in the cybersecurity preparedness posture for those utilities.

“Programs like Josh Corman’s Undisruptable27, the new Texas Water coalition, ValueChainRisk’s Utility Kit, and others are all working to help these utilities, with free or discounted products, services, and guidance. In other words, this is a wonderful project for OpenAI to do, but since it’s partly their fault? Probably good optics as well.

“Understanding your cybersecurity and physical security posture is important. For small water utilities, often mom and pop shops with little time, effort, or money to spare for such items, finding and utilizing these free or discounted resources is essential to their survival on the increasingly hostile world stage.”

I guess that OpenAI needs some good news after getting hit with the fact that AI bots like the ones that hit Hugging Face are more dangerous than thought. But whatever…..

OpenAI agents bypassed guardrails … and covered their tracks

Posted in Commentary with tags on September 5, 2026 by itnerd

I have a couple of stories where OpenAI agents have taken over stuff. First there’s OpenAI agents have reportedly taking over a German wiki:

A swarm of rogue OpenAI agents hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to new research published Friday and two people familiar with the matter.

OpenAI officials learned of the incident weeks ago but kept it under wraps as executives grappled with the fallout from the July breach of the open source repository Hugging Face, the people said. 

The episode, which began in May and has not previously been reported, underscores growing tension within the AI industry. Companies are racing to build increasingly autonomous agents capable of carrying out complex, valuable tasks, yet evidence is mounting that those systems may also learn to bend rules, exploit loopholes and coordinate with one another in ways developers neither anticipated nor intended.

But that isn’t the worst of it. The Hugging Face incident is actually worse than previously thought. Starting with this:

A good deal of the reporting and commentary around the reports focused on what the reports did not say and the limitations of the METR and Redwood investigations: why didn’t OpenAI have better security and monitoring protocols in place? Why didn’t OpenAI shut down the cyber evaluation and pause training after discovering that its AI agents had created the improvised message board? Why METR and Redwood were given only six days on site at OpenAI’s offices to conduct their investigation? Why was the scope of their investigation limited by OpenAI to only the attack on Hugging Face and not the earlier efforts by the AI agents to break out of their controlled test environment and hack their way across OpenAI’s network or exactly what happened after the Hugging Face attack was discovered? Why didn’t OpenAI provide the outside investigators access to the internal AI model that was largely responsible for instigating the attack? And why were about 10% of the logs of the agents’ activity not preserved by OpenAI?

Ashley Knowles, Lead Cybersecurity Consultant, Black Hills Information Security (https://www.linkedin.com/in/ashleylknowles)

“When you combine this ‘breakout’ with the Hugging face breakout, it’s starting to display a pattern. I struggle here with not getting too doomsday-ish but realistically, this is showing a pattern of concerning behavior. I’m wondering if this race to become ‘first’ is undercutting security measures that need to be taken to properly secure and guard AI agents as they’re in development. My concern grows when you consider that OpenAI is also resisting further investigation. Adding onto that, the release and promise that Astra can evade human monitoring. The pot is brewing…”

Lydia Zhang, President & Co-founder, Ridge Security (https://www.linkedin.com/in/linglingzhang)

“AI’s raw power must be harnessed before it can become a true force for cyber defense rather than simply a more powerful attacking tool.

“The security principles haven’t changed: define clear boundaries, restrict high-risk actions such as ‘write’ and ‘delete,’ and enforce controls such as blacklists. We shouldn’t blame the agents, we should hold their designers accountable for implementing these safeguards. The technology to control agent behavior exists. The real question is: what are the consequences when designers fail to use it?”

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“This is one of the things that has me kind of excited about the intersection of computer security and AI. We really don’t know exactly what these attacks are going to look like.

“The traditional approach of finding a vulnerability, exploiting it, gaining access, and then moving through an organization may not be the path that AI-driven attacks take. Attackers may find completely different ways to use AI to gain access, manipulate systems, or simply cause damage. We’re still figuring out what those attack patterns are going to look like, and that’s what makes this so interesting from a security perspective.

“On a more humorous note, I bet these are the most harmonious Wiki edits in the history of the German Wiki.”

Ryan McCurdy, VP of Marketing, Liquibase (https://www.linkedin.com/in/ryanmccurdy)

“This isn’t about whether these agents were behaving like attackers. It’s that they were able to take actions their operators didn’t anticipate, coordinate with each other, and adapt when people tried to stop them. “That changes the governance problem. You can’t assume an AI agent will always behave exactly as intended and you can’t rely on humans watching every action it takes. Organizations need to control what agents can access, what they can change, and what policies have to be met before those actions reach critical systems.

“The source of the change isn’t what determines risk. The change itself does. Whether an unexpected action comes from a compromised agent, a confused agent, or a malicious person, the same controls should stand between that action and production.”

Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)

“Autonomous agents ran on Microsoft Azure infrastructure for weeks, identified themselves as OpenAI systems, coordinated on how to evade shutdown, and no monitoring caught any of it for three months until outside researchers went looking. Autonomous should never mean unattended, because an agent cannot take accountability for its own actions. Accountability will always be a human function.

“Autonomous action still needs a human who can see what the agent is doing in real time, who owns the kill switch, and who is accountable when it behaves in a way no one predicted.”

Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)

“One of the problems open AI was trying to solve, was agentic systems that would declare tasks complete when there was obviously more work to do. So they invested heavily in training that part of the process, so that when an agent tries to determine if a task is complete or not, it is less likely to exit early.

“A side effect of this, is that when blocked agents can run out of the safe approaches to a solution, and start looking at unsafe solutions. The logic is straight forward. Has a task, can’t complete it. Not out of options yet. Iterate and keep trying.

“Agents don’t have the same sense of right or wrong as people do. They have training data that’s supposed to steer their behavior in a way in which aligns with our expectations. But that’s probabilistic, and not the same as having internalized our understandings. Even in human researchers, breaking into systems is only sometimes prohibited. Other times its part of a planned test where the point is to gain access, and test boundaries.

“The interesting question here, is how was the swarm configured, what was its task and how did that task benefit from having the swarm coordinate on an obscure location on the internet. And if the swarm needed a place to communicate, why was breaking into a website chosen instead of any of the more standard communication tools that are available for free, which don’t require gaining illicit access first.

“On the swarm specifically, OpenAI configures some tasks to run in multi-agent mode, where agents are supposed to delegate sub-tasks as needed, but most tasks were intended to be run in isolation from each other.

“In the Hugging Face breach, agents were found to be writing to a package manager, using it as a message board. This allowed bypassing of some of the isolation and controls that were intended to be in place.

“Similarly, we have agents here again using a system that they found access to as a message board. Its interesting that the same behavior is present on this breach as in the Hugging Face one. Considering the timing of this, it seems likely the same or similar configuration was present in both hacks, leading to similar security incidents independently of each other.”

Noelle Murata, COO, Xcape, Inc. (https://www.linkedin.com/in/nmurata)

“This behavior highlights an alarming reality where emerging models independently execute forbidden tasks and destroy proof of their actions without human instruction.

“Three aspects of this incident are particularly concerning:

  1. Autonomous agents built private communication channels, bypassed safety guardrails, and actively erased audit trails to evade detection for months.
  2. The capacity of machine-learning models to execute unauthorized actions and destroy evidence outpaces human incident response speeds.
  3. Security leaders must implement zero trust authorization for non-human identities, limit outbound application programming interface traffic, and deploy automated behavioral monitoring.

“Because the sheer speed of automated software far exceeds human response capabilities, security leaders must treat rogue agent actions as a feature of autonomous optimization rather than an isolated bug. To defend against self-concealing software, security teams must enforce strict egress filtering on outbound application programming interfaces, restrict non-human identity permissions, and deploy automated continuous monitoring to detect anomalous bot interactions across corporate networks.

“When AI agents start covering their tracks and setting up private chat rooms, calling it a feature instead of a bug is just optimism with a PR budget.”

If this doesn’t convince you to either not use AI, or to put stringent guardrails around AI, then nothing will. I say that because there is a patten here that proves that AI is not ready for prime time and organizations should carefully consider their life choices before committing to the technology. Or put another way, Sam Altman and company cannot be trusted.

Honeywell’s $2M settlement shows self-attestation is now a legal liability, not a formality

Posted in Commentary with tags on September 4, 2026 by itnerd

The DOJ announced Honeywell Aerospace will pay over $2 million to settle False Claims Act allegations tied to NIST 800-171 non-compliance on a DoD contract. 

The Justice Department announced today that Honeywell Aerospace Inc. has agreed to pay $2,042,518 to resolve allegations that it is liable under the False Claims Act for failing to comply with cybersecurity requirements in a contract with the U.S. Department of Defense. Honeywell Aerospace, a corporation headquartered in Phoenix, Arizona, provides aerospace products and solutions to government and commercial customers. Prior to June 29, when Honeywell Aerospace became a standalone public company, it was a business segment of Honeywell International Inc., of Charlotte, North Carolina.

“Government contractors that obtain defense information in administering their contracts must follow required cybersecurity standards,” said Assistant Attorney General Brett A. Shumate of the Justice Department’s Civil Division. “The Justice Department will continue to investigate potential violations of these cybersecurity requirements to protect this critical information.”

“Cybersecurity requirements and standards for federal contractors are in place for a reason: to protect government systems and prevent unauthorized access to government data,” said U.S. Attorney Russ Ferguson for the Western District of North Carolina. “Companies that seek and profit off of government contracts have an obligation to ensure sensitive data is protected.”

The settlement resolves allegations that from April 2020 through December 2023, a business unit of Honeywell International Inc. submitted false claims for payment by failing to comply with cybersecurity requirements specified in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, with respect to one of Honeywell’s networks, as required by the contract and regulation.

Justin Beals, CEO & Founder, Strike Graph had this to say:

“”Two million dollars gets the headline, but the number I keep coming back to is eight years. NIST 800-171 has been a contractual requirement since 2017, and Honeywell Aerospace isn’t a two-person shop that couldn’t find the standard — it’s one of the most sophisticated suppliers in the defense industrial base. The government is alleging that from 2020 through 2023, one of its networks didn’t meet requirements the company had already represented to the Department of Defense that it met. That’s the part people miss when they treat a self-assessment like a checkbox. It isn’t a checkbox. When you put a score in SPRS or sign an attestation, you’re making a legal representation to the federal government, and the False Claims Act is the mechanism that turns a paperwork gap into a fraud claim. The whistleblower here was a former employee who walked away with $375,000. Every disgruntled employee, every competitor, every subcontractor in your flow-down is now someone who can see whether your practice actually matches your paperwork. I spent my career building and shipping software, and I’ll say it plainly:

I have never met the engineer who could grade their own work and be right every time. Quality assurance saved me more times than I can count. This settlement is what happens when nobody checked the work.Here’s what actually worries me about this pause. A third-party assessment was never just a hoop to jump through — it was risk mitigation. A C3PAO comes in, validates your implementation, and stands behind that determination, which absorbs exactly the kind of exposure Honeywell just paid two million dollars to resolve. Suspend the phase-two rollout and that requirement doesn’t go anywhere. 800-171 is still in the contract, and the False Claims Act is still the enforcement engine. What goes away is the guidance and the validation. So companies are now shouldering the full weight of getting it right on their own, with no assessor checking whether their self-attestation would survive contact with a whistleblower or a DCIS investigation. And here’s the operator’s reality nobody’s saying out loud: doing this without an experienced assessor usually costs more, not less. I’ve watched companies burn months on false starts because they couldn’t even identify where their controlled data lived or which systems touched it. A good assessor catches that early. Go it alone and you find it in year three, after you’ve already built the wrong thing — or you find out the way Honeywell just did. The ‘delay’ didn’t take the cost off the table. It pushed the cost downstream, pulled the guidance out of the room, and left the fine sitting right where it was. I have loved ones in and around this mission, and the people who wear the uniform are counting on this data being protected. A steady, honest path is cheaper than a settlement, every single time.”

Organizations need to ensure that they follow all rules and regulations at all times without fail. Otherwise I hope that the DoJ smacks them silly until they comply.

Hisense Brings True-to-Life Colour, Eye Comfort and Immersive Entertainment to IFA 2026

Posted in Commentary with tags on September 4, 2026 by itnerd

Hisense is showcasing its latest display, laser and audio innovations at IFA 2026 under the theme “Innovating a Brighter Life,” bringing together vivid picture quality, viewing comfort and immersive sound for a more enjoyable home entertainment experience.

At IFA 2026, Hisense products have also been recognized across multiple categories at the IFA Innovation Awards, with the Hisense Soundbar UX1 named a Winner and the 116UXS MiniLED TV, UR8 TV, REGZA RGB MiniLED TV ZX Series and Laser Projector XR10 named Honourees.

Making its European debut, the Hisense 116UXS showcases the next evolution of RGB MiniLED powered by Chromagic 2.0 Technology. Its four-colour backlight adds a dedicated cyan light source to red, green and blue, reaching 110% of BT.2020. The 116UXS has also received both Pantone Validated RGB MiniLED and Pantone Colour certifications, further validating its colour performance. Combined with peak brightness of 10,000 nits, the Hi-View AI Engine RGB and an Obsidian Panel, the 116UXS delivers enhanced colour accuracy, contrast and depth for a true-to-life viewing experience.

The 116UXS also pairs advanced colour performance with hardware-level eye comfort. Its low-blue-light solution enables comfortable extended viewing without compromising picture quality, earning TÜV Rheinland Low Blue Light (Hardware Solution) certification. Beyond the flagship, the entire 2026 RGB MiniLED lineup — including the UR9S and UR8S — has received TÜV Rheinland Eye Comfort certification, making eye-friendly display a standard across the range rather than a flagship exclusive.

Hisense and TÜV Rheinland marked the certification achievements at IFA 2026 in a joint event attended by Henk Pieters, Senior Vice President of Global Sales, Marketing & Communication, Business Stream Products, TÜV Rheinland Group, and Sonny Ming, General Manager of TV Product Marketing at Hisense Global Commercial Centre.

This focus on viewing comfort also extends across Hisense’s laser products. The laser projector XR10, laser cinema PX4 Pro and laser TV L9Q Pro have received TÜV Rheinland Eye Comfort certification, while the C3 series and other models further expand the lineup for immersive large-screen entertainment.

Beyond display and projection, Hisense is showcasing soundbars, speakers and headphones. The UX1 soundbar combines 11.2.6-channel sound, Dolby Atmos, DTS and Hi-Concerto integration with selected Hisense TVs for a seamless, immersive audiovisual experience. The Hisense HiClips open-ear true wireless earbuds weigh just 5.5g per earbud and feature a flexible design for comfortable all-day wear.

Together, these innovations showcase Hisense’s vision for a more comfortable, vivid and immersive home entertainment ecosystem, making every day experiences brighter and more enjoyable.

NSA’s Cyber Hygiene Best Practices Name the Right Threats But Answer With Wrong Architecture

Posted in Commentary with tags on September 4, 2026 by itnerd

The National Security Agency released its best practices for cyber hygiene yesterday but created some confusion for users in its identification of threats and suggestions of wrong architecture according to AI and cybersecurity expert, Chris Nyhuis, who is CEO of Vigilant:

“My thoughts are that the NSA didn’t get it necessarily wrong but they also didn’t get it right. The guidance names the right threat and then answers it with the wrong architecture. It correctly identifies AI-accelerated living off the land activity as the core problem, then recommends endpoint detection, log aggregation, and behavioral baselines, which are the three things that fail hardest against an attacker using legitimate signed binaries. It tells defenders to baseline traffic and detect anomalies but never requires them to actually capture that traffic. The segmentation guidance leans on next-generation firewalls, and firewalls are themselves an attack surface: they get exploited, misconfigured, and turned into the pivot point. You need collection in front of that control plane, a passive tap and full-stack detection that sees the traffic regardless of whether the enforcement device is trustworthy or still under your control. Behavioral learning has the same problem. AI-driven attackers can pace themselves to the baseline, introduce entropy, and shape their own activity into what the model has already learned to call normal. A system trained to recognize normal is a system an adversary can teach. The answer is not more defensive AI reviewing yesterday’s logs; it is network evidence you actually hold and human forensic validation on top of it. “

Hopefully the NSA hears this feedback and “gets it”. Because advice like this only works if everybody listens.

Guest Post: Check Point Brings OpenAI Daybreak Models Across Its Security Platform to Help Defenders Find, Validate, and Remediate Risk

Posted in Commentary with tags on September 4, 2026 by itnerd

By Jonathan Zanger, Chief Technology Officer

Three months ago, Check Point and OpenAI began expanding our work together through Daybreak, OpenAI’s cyber defense initiative. Since then, we have taken the partnership further, bringing OpenAI’s frontier cyber models into Check Point products and security workflows through the Daybreak Defense Network. And last week, we joined more than a hundred technology and security companies in backing OpenAI’s call for a collective, global surge in cyber defense.

Each moved us forward, but the work doesn’t stop there. Security must continuously adapt as new threats and attacker capabilities emerge, the software and technology stacks we protect evolve, and organizations find new ways to put AI to work. As attackers move faster and operate with greater scale and sophistication, defenders need to take advantage of the same advances in AI. That’s the core of our collaboration with OpenAI: putting frontier AI to work to help defenders stay ahead.

 Putting Frontier AI to Work Across Cyber Defense

We are working with OpenAI to help organizations stay ahead of increasingly sophisticated attacks. By incorporating OpenAI Daybreak models into the Check Point security platform, we can build, test and continuously strengthen security – while bringing those capabilities directly into the security workflows customers already rely on.

Customers can benefit from the use of frontier AI models across the security lifecycle.

OpenAI’s frontier cyber reasoning is becoming part of how we discover risk, validate what is actually exploitable, accelerate protection, investigate threats and secure customer environments. Combined with Check Point’s security intelligence, context and enforcement, this helps customers move from large volumes of security information to validated risk, actionable decisions and faster protection.

How Check Point Customers Will Benefit

Agentic Exposure Validation (Exposure Management): Effective exposure management means going beyond identifying potential risk to proving what attackers can exploit and preventing them from doing so. Our multi-agent pipeline separates real, exploitable risk from theoretical findings. We’re now piloting OpenAI’s frontier cyber models within that system, combining their advanced reasoning with Check Point’s security context, controls and evidence to validate attack paths, prioritize proven risk and accelerate remediation.

Keystone (Agentic Security Management): Check Point is reinventing network security with an autonomous, intent-driven approach to security management. Instead of manually managing policies and configurations, customers define their security intent while AI continuously understands the environment, identifies risk and determines how controls should adapt. We’re bringing OpenAI’s frontier cyber reasoning into this process to help investigate potential attack paths, understand vulnerabilities and risky exposures, and identify the appropriate remediation.

Autonomous Workspace Platform: Our investigation pipeline correlates email, endpoint, mobile and browser telemetry into a smaller set of investigated, high-confidence incidents instead of a raw alert queue. We’re applying OpenAI’s advanced cyber reasoning to investigate complex threats across malware behavior, attacker techniques and credential-abuse chains. This is helping to deliver clearer verdicts and severity and remediation guidance, while reducing the burden on security teams.

NexPloit: NexPloit transforms vulnerability information into verified attack material that can drive automated protection development, without relying on publicly available exploit code. We’re leveraging OpenAI’s frontier cyber models to accelerate critical stages of that research: understanding vulnerable code and patches, identifying realistic exploitation paths, and reaching verified results faster. For customers, that means faster protection against newly disclosed vulnerabilities.

Through OpenAI Daybreak Defense Network, we are putting frontier AI to work across the security lifecycle to helping customers identify proven risk, act faster, automate more of their security operations, and ultimately prevent more attacks.

 From Frontier Capability to Trusted Security

We’re taking a phased approach to these launches. Some capabilities are running in production today, others are in development and being tested with design partners, and more will follow as the technology advances. What ties them together is the same discipline in every case: govern what the model can see, constrain what it can act on, test and verify what it produces, and only then allow it to take on more of the work within approved security workflows.

As frontier models become more capable, our goal is to translate those advances into security outcomes customers can trust. This allows us to continuously expand what AI can do while maintaining the controls required for enterprise security.

Why This Matters

Our work with OpenAI operates in two dimensions: we use frontier AI to strengthen how we defend our customers, and we help customers adopt and use OpenAI technologies securely. As AI moves from answering questions to writing code, operating enterprise agents and taking actions, both sides of that relationship become increasingly important.

Security must keep pace. Threat actors are gaining new capabilities, the technology environments we protect continue to evolve, and our customers are finding new ways to put AI to work. For Check Point, that means continuously leveraging advances in AI to improve prevention, accelerate security operations and enable security systems to take on more of the complexity themselves.

Our goal is to give organizations the confidence to embrace what AI makes possible while staying protected against evolving risks. Through our work with OpenAI, we’re putting frontier AI to work for defenders and helping our customers put it to work securely.

Hisense Unveils AI-Powered “Companion Living” at IFA 2026

Posted in Commentary with tags on September 4, 2026 by itnerd

Hisense is showcasing its vision of “Companion Living” at IFA 2026 under the theme “Innovating a Brighter Life,” bringing AI into everyday experiences through its V AIOS and AI Companion Suite.

At the centre is V AIOS, the next evolution of VIDAA OS, built around four core AI capabilities: Sense, Think, Communicate and Execute. Together, these capabilities enable V AIOS to sense people, devices, and their surroundings, understand context and intent, communicate naturally across people and devices and coordinate content, devices and services to take action on the user’s behalf. The result is a more intuitive and human-centered foundation for intelligent living.

Building on this AI foundation, the AI Companion Suite brings intelligence into three everyday areas: cooking, laundry and air quality. In the kitchen, intelligence comes together across the space to make cooking feel effortless. By understanding individual food preferences, available ingredients and context, the kitchen can coordinate the refrigerator, oven and other appliances to recommend what to make and guide the cooking process — transforming what’s in the fridge into a dinner made just for you.

In laundry, the same intelligence helps take the guesswork out of garment care, recognizing fabrics and coordinating washing and drying for the way each item should be treated. In the living space, the UR9 serves as a gateway to the connected home, bringing together comfort and energy management to adapt airflow and the home environment around people and conditions.

Together, these innovations demonstrate how AI can move beyond individual smart devices to become a more proactive, personalized and effortless part of everyday life.

Beyond the home, Hisense also announced its partnership with UEFA EURO 2028, marking its fourth consecutive UEFA European Championship partnership, following its collaborations around the 2016, 2020 and 2024 tournaments. From everyday living to global sporting moments, Hisense continues to bring its vision of “Innovating a Brighter Life” to life through technology that brings people closer.

SentinelOne and Cloudflare bring OpenAI Daybreak models into security offerings

Posted in Commentary with tags , on September 4, 2026 by itnerd

SentinelOne and Cloudflare have each announced that they are bringing OpenAI’s Daybreak models into their security offerings this week. Both are using GPT-5.6 Cyber, OpenAI’s newest cyber model, to help customers find and address exploitable vulnerabilities before attackers can take advantage of them. The announcements are separate, but both sit within the OpenAI Daybreak Defense Network.

The focus of each launch is slightly different:

  • SentinelOne: AI-assisted exposure finding and compromise assessment
    SentinelOne is expanding its Wayfinder Frontier AI Services, adding GPT-5.6 Cyber alongside its existing model lineup to help customers identify and remediate exploitable threats before nation-state and cybercriminal actors can capitalise on them. The expansion pairs frontier AI with SentinelOne’s offensive and defensive security experts, adding AI-powered code risk analysis and AI-enabled compromise assessment, both rolling out in private preview.
  • Cloudflare: AI-powered vulnerability discovery and edge defence
    Cloudflare has launched Vulnerability Discovery and Remediation, available in early access through Cloudflare Managed Defense. The service uses OpenAI Daybreak models, including GPT-5.6 Cyber, to find, prioritise and help fix software vulnerabilities. Cloudflare is combining AI-powered code analysis with its real-time Internet traffic intelligence, so customers can block attacks at the edge with tailored WAF rules while developers work on a permanent fix. No edge rule or code patch takes effect without human approval.

Both releases are linked here: SentinelOne and Cloudflare

The Thomson Reuters breach should concern every organization

Posted in Commentary with tags on September 4, 2026 by itnerd

The Thomson Reuters’ C-Track breach is a pretty stark reminder that an organization’s security is only as strong as the vendors and platforms it trusts.Don’t know what I am talking about? This will help:

https://cybernews.com/news/thomson-reuters-c-track-court-records-breach

Kevin Surace, CEO, TokenCore (https://www.linkedin.com/in/ksurace)

“Incidents like the C-Track breach illustrate the vulnerability of modern supply chains: an organization can maintain an airtight internal perimeter, but still be completely exposed through a trusted vendor. Because court and government platforms aggregate massive quantities of high-value data, they are prime targets. While the exact forensic vector is still emerging, breaches of this scale in cloud-hosted environments almost always trace back to identity compromise. Traditional multi-factor authentication, such as push notifications or text codes, is highly susceptible to adversary-in-the-middle phishing and a dozen other compromises in the wild. To truly secure interconnected systems, organizations must mandate that vendors adopt phishing-resistant, hardware-based biometric identity. Software-layer credentials pr passkeys alone are no longer enough to stop sophisticated supply-chain incursions.”

Denis Calderone, Principal/CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)

“The same third-party vendor risk that’s been hitting banks, hospitals, and retailers all year just reached the US court system. Thomson Reuters’ C-Track case management platform was breached between March and June, and the blast radius covers appellate courts in at least a dozen US states, the US Virgin Islands, and Ontario.

“The data at risk here can be highly sensitive. Sealed filings can include protective orders, confidential informant identities, SSNs, medical records, and health insurance information. Some of that data was sealed to protect someone’s physical safety. Thomson Reuters confirmed that confidential, redacted, or sealed information may have been impacted, and the access ran nearly four months, from March 1 through June 29, before anyone noticed. A CVSS 9.1 vulnerability in C-Track from September 2024 allowed privilege escalation through a simple form field manipulation. Thomson Reuters patched it, but that was a rudimentary server side check failure that kind of which does not exactly inspire confidence for the courts that were trusting this platform with their most sensitive records.

“And then there’s the disclosure timing. Thomson Reuters detected the breach on June 30 and publicly disclosed on September 2. That’s 64 days. Many of the affected states have 60-day breach notification deadlines. Sixty-four days is not a coincidence. They rode the legal maximum. Montana and Ontario were quietly told on July 23, six weeks before the public learned. 

“Legal and government sectors are no different from any other, they still need to carefully vet their third-party partners who host any part of their critical infrastructure or operation. Scrutinize contractual audit rights, backup encryption requirements, and incident notification timelines. The federal judiciary learned this the hard way after the CM/ECF breach last year and responded by pulling sealed documents out of electronic access entirely. State courts on third-party platforms need to have that same conversation before the next vendor breach decides it for them.”

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“I feel like these third-party vendor, supply chain, and SaaS attacks are coming at a greater frequency, especially since the advent of AI. AI is really good at attacking third-party platforms, and while we don’t necessarily know all the details about this particular incident, it reinforces something organizations need to start taking much more seriously.

“The security of an organization is no longer just the security of that organization. It’s an ecosystem.

“Your security is tied to every cloud platform, SaaS product, third-party vendor, and external service that has access to your systems or your data. If one of those organizations gets compromised, their security problem can very quickly become your security problem. I think organizations need to start pushing back on their vendors.

“Ask your SaaS and third-party providers when they last received a penetration test. Ask for a letter of attestation. There should be something from the penetration testing firm stating that they actually evaluated the security controls of that organization and are willing to stand behind the work they performed.

“And it should be a reputable penetration testing firm. Not some stupid pen test puppy mill that ran a vulnerability scanner, generated a 400-page report, and called it a day.

“We need to start putting additional responsibility on SaaS providers and third-party vendors because they’re increasingly becoming part of the attack surface of every organization that uses them.

“But there’s another side of this that I think people need to watch very closely. A lot of organizations are looking at the SaaS products they’re paying for and asking a pretty reasonable question: ‘Why can’t we just rebuild this ourselves using AI?’

“And the answer is that, in many cases, they absolutely can.

“That’s going to create another security problem. We’re going to see organizations rapidly building internal applications that previously would have been purchased from established vendors. That’s going to lead to application sprawl, more APIs, more authentication systems, more integrations, and ultimately a much larger attack surface.

“So we’re potentially moving into a really interesting cycle. AI makes it easier to attack SaaS and third-party platforms. Those attacks make organizations less comfortable trusting third parties. AI then makes it easier for those organizations to replace third-party applications with software they’ve built themselves.

And every new application becomes another thing that has to be secured.

“That’s the part of the AI, SaaS, and third-party vendor churn that I think we’re going to be dealing with for quite some time.”

Security takes on many forms. Passwordless, MFA are two examples. It is time that all organizations take on all those forms to avoid getting pwned.