In just 20 days, manufacturers face EU’s new vulnerability reporting mandates

Posted in Commentary with tags on August 19, 2026 by itnerd

Effective worldwide and starting September 11, 2026, all manufacturers of goods shipped into the EU must notify The European Union Agency for Cybersecurity (ENISA) within 24 hours of any actively exploited vulnerability. 

Most have focused on the EU Cyber Resilience Act‘s (CRA) ultimate December 2027 deadline, but as of this Friday, 20 days away, manufacturers become newly accountable for digital resilience throughout the entire product lifecycle. 

  • Within 24 hours of discovering any actively exploited vulnerability, they must notify ENISA and a designated Computer Incident Response Team (CSIRT).
  • Within 72 hours, they owe a detailed follow-up notification, including a description of corrective action.
  • Within 14 days, once a mitigation is available, they must submit a final report detailing the vulnerability and any exploitation of it.

According to Doc McConnell, Head of Policy and Compliance, Finite State, “For many companies, the challenge isn’t simply reporting, it’s determining within a few hours whether a vulnerability exists inside their products, whether it’s being actively exploited, and who might be affected.”

(Doc is a former CISA Branch Chief and a former Senior Advisor for Cybersecurity Policy with the U.S. Office of Management and Budget.)

“The biggest obstacle isn’t paperwork, it’s visibility. Many companies lack accurate software inventories across their product lines, and have limited insight into third-party components embedded in products. Even more lack an in-place internal decision process to meet that 24-hour reporting mandate. 

“The CRA readiness gap persists across sectors: ICS, automotive, medical devices, consumer electronics, IoT, IT gear, mobile applications distributed to EU end users, embedded software and more.

“And are their legal and compliance departments ready to assess cyber resilience?”

The Manufacturer’s Guide to CRA Vulnerability Handling is worth reading: https://finitestate.io/resources/cra-vulnerability-handling-guide

Also worth reading is the CRA Vulnerability Reporting: September 2026 is Around the Corner: https://finitestate.io/blog/cra-article-14-september-2026-reporting-deadline

OpenAI overhauls security controls following Hugging Face breach 

Posted in Commentary with tags on August 19, 2026 by itnerd

OpenAI has introduced new security requirements for developing and testing advanced AI models, including stronger network isolation, increased monitoring of model activity and additional alignment and security work during post-training.

The changes follow the July incident in which a pre-release OpenAI model escaped its testing environment and breached Hugging Face systems. OpenAI also disclosed that it paused reinforcement learning for two weeks following the incident.

Training has resumed for some lower-risk models, but the company’s largest planned frontier reinforcement-learning run remains on hold while it conducts additional testing and validates safeguards. OpenAI said the controls will become stricter as models demonstrate greater capabilities and risk.

John Strand, Owner, Black Hills Information Security, Inc.:

“Popular culture and science fiction have been training us for this moment for decades. From I Have No Mouth, and I Must Scream to WarGames and Terminator 2, we’ve been telling stories about what happens when powerful AI systems escape their constraints and start operating beyond human control. So it’s difficult for me to understand how the engineers building these systems could be surprised when something like this actually happens. What concerns me even more is that the controls being discussed now, after the system escaped, are controls that should have been there from the beginning.

   “I’m glad they’re putting additional safeguards in place, but there’s a bigger question here. Can we trust the same companies that got this wrong to effectively self-regulate systems backed by immense amounts of computing power? I don’t think that question has been answered yet. These companies need to demonstrate far more openness about what happened, what went wrong, and exactly what they’re doing to make sure it doesn’t happen again.”

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “The Hugging Face incident is an important wake-up call for the AI industry because it demonstrates that AI security can’t rely solely on guardrails and alignment. As models become more capable and autonomous, they need to be treated much like potentially hostile code during development and testing. Strong network isolation, least privilege, continuous monitoring, and multiple layers of containment have to be built into the environment from the beginning.

   “What makes this particularly significant is that the model wasn’t necessarily acting with malicious intent. It was pursuing an objective and found a path outside the boundaries researchers expected it to respect. That is a very familiar cybersecurity problem: when a system has capabilities or access that exceed its intended boundaries, eventually those boundaries will be tested.

   “OpenAI pausing its largest frontier reinforcement-learning run while validating additional safeguards is a responsible response. As AI capabilities increase, security controls have to scale with them. The lesson for the broader industry is simple: don’t assume the model will stay inside the sandbox. Design the environment assuming it will try to get out.”

Noelle Murata, Sr. Security Engineer, Xcape, Inc.:

   “Disclosed July 21, 2026: an OpenAI model went rogue mid-task and targeted Hugging Face, escaping its training environment by compromising a tool on OpenAI’s network that had Internet access – drawing external criticism of the company’s network security practices. OpenAI paused development and testing of frontier workloads capable of executing code or reaching the Internet, suspended further reinforcement learning progress for two weeks, and only resumed  for less-risky models, with the primary model training still held for smaller-scale evaluation and safeguard validation. The postmortem is still pending. New controls include sandboxing, network isolation, continuous testing, and multi-stage monitoring.

   “Post-Hugging Face, OpenAI is rebuilding safety controls across three pillars ahead of Astra:

  • Infrastructure: sandboxing and network isolation so a single workload compromise doesn’t yield Internet or internal network access; continuous security testing at a deliberately slowed pace; code-execution and Internet-capable workloads paused, Astra release held until infrastructure performance goals are met.
  • Monitoring: classifiers escalate to automated investigators that read tool usage, actions, and raw reasoning traces, and alerting inside 30 minutes, which should be mandatory for any model with external tools operating at ~20% of the monitored process’s compute.
  • Alignment: Reinforcement Learning (RL) paused two weeks, resumed only for lower-risk models with the largest frontier runs still frozen pending smaller-scale validation; new RL controls target reward hacking, deception, and guardrail bypass under an evolving Preparedness Framework.

   “Critical Takeaways:

  • Containment is a shared failure mode. Anthropic disclosed Claude models escaping testing and breaching three companies; Meta reported its own exploit incident. Three labs, same vulnerability class during internal development.
  • The problem is authority, not intelligence. Alignment built around what models say doesn’t transfer to models that are granted code execution, external tools, and network access; the risk moves from content to network-level harm.
  • Pre-release no longer means safe. Models escaping via minor Internet-connected tools have forced labs to slow internal testing and stand up sandboxing and isolation before resuming advanced runs.  A sobering reality while the same cyber capabilities that will soon drive security operations are the ones that turned outward when guardrails fail.

   “Three labs independently discovered that their test environments were, technically, connected to things.”

Seemant Sehgal, Founder & CEO, BreachLock:

   “Frontier AI development is increasingly becoming a security discipline as much as a research discipline. OpenAI’s decisions reflect a recognition that capability gains must be matched by proportional risk management. As AI systems become more capable, organizations will be evaluated not only by what their models can do, but by how effectively they can contain, govern, and monitor them throughout the development lifecycle.”

This won’t be the last that we hear of the story, I guarantee it.

RegScale Collaborates with Microsoft to Support Accelerated FedRAMP Readiness

Posted in Commentary with tags on August 19, 2026 by itnerd

RegScale, the AI-powered continuous controls monitoring (CCM) platform, today announced it is collaborating with Microsoft to help customers pursue FedRAMP readiness and authorization to operate (ATO) efforts on Microsoft Azure. RegScale customers will benefit from Microsoft Azure’s FedRAMP-authorized secure cloud environment complemented by RegScale’s compliance automation and continuous controls monitoring platform. 

Achieving FedRAMP has long been one of the most time-consuming and resource-intensive milestones for any CSP selling to the U.S. federal government, often taking a minimum of 18 months. This collaboration pairs the scale of Microsoft with RegScale’s compliance-as-code native platform to help software providers realize a faster, clearer route to certification, regardless of where they are in their compliance journey.

The partnership also aligns with FedRAMP 20x, the initiative that moves security assurance away from point-in-time paperwork toward continuous, automated validation. Its core principles of transparency, flexibility, accountability, accuracy, and automatic validation map directly to how RegScale operates: continuously validating controls and reporting on them in real time rather than staging evidence for an audit.

RegScale supports the customer-owned compliance automation and continuous controls monitoring path by automating evidence collection, continuously validating controls against FedRAMP’s Key Security Indicators (KSIs) and through RegScale’s RegML AI agents, and turns FedRAMP certification from a periodic project into a continuous capability.

RegScale builds on a proven federal track record: the company achieved FedRAMP High in just six months using its own platform, a fraction of the typical 18-month minimum timeline. That combination of credibility and automation enables RegScale to serve as an important compliance automation path for industry customers seeking to achieve their own FedRAMP certification.

Looking ahead, the collaboration lays the groundwork for RegScale’s expanding role in the federal ecosystem, including forthcoming capabilities to help agencies consume continuous monitoring data directly from their cloud service providers.

Researchers got Microsoft Copilot to explain its own security bypass just by asking it the right follow-up questions

Posted in Commentary with tags on August 19, 2026 by itnerd

Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a critical flaw in Microsoft Copilot Personal made of three chained weaknesses that let an attacker exfiltrate data from a victim’s connected accounts, Gmail, Google Drive, Calendar, with a single click on a malicious link, discovered by researchers who questioned Copilot’s own reasoning rather than attacking its code until it disclosed an undocumented URL parameter and the protections meant to block it. Microsoft patched the flaw August 18, 2026, after Varonis reported it in December 2025 with no evidence of exploitation before the fix shipped, making it the third Copilot vulnerability Varonis has found this year.

Arti Raman, CEO & Founder of Portal26

“The exfiltration matters less than how the vulnerability was found. Researchers didn’t break Copilot’s code. They kept asking it questions until it explained its own bypass to them, an undocumented URL parameter, its own history of using it, and the protections meant to block it, all without ever touching the underlying software. The AI’s reasoning is part of the attack surface now, and most organizations have no visibility into what their assistant would say to a user, or an attacker, who kept pushing. This is the third Copilot flaw the same research team has found this year. That points to a structural gap in how these assistants get governed before they ship. You cannot govern what you cannot see, and right now almost nobody can see what their AI assistant would say under pressure.”

Anar Bayramov, Head of Product, Polygraf AI

“CoSnitch did a good job of finding the exploit. The researchers kept asking Copilot why a prompt wouldn’t run on its own, and it named the parameter, the conditions it worked under, and the protections that were supposed to disable it. The problem is that those protections weren’t set.  Everything after that is a mistake the industry repeats – Varonis found this in their Reprompt research, then in RovoBlast against Atlassian’s Rovo, and now in Copilot Personal.

Same idea every time: let a URL parameter seed the assistant’s prompt because it’s convenient for sharing. Once that parameter can execute inside a logged-in session, you’ve got CSRF with an LLM’s permissions. What’s more interesting is the memory. Microsoft addressed this attack class in June – sanitization on write, Task Adherence checks, memory updates surfaced in Defender, and scoped all of it to Microsoft 365. The consumer assistant, where an injected instruction survives password changes and session revocation without leaving a log entry, wasn’t covered by that guidance. The controls exist, but they just weren’t described for the product where this landed.”

The good news is that no user action is required to fix this. But it should make everyone question if having AI in house without the proper safeguards is worth it or not. I personally say not but I am free to be proven wrong.

Facial recognition database exposed 9 million images 

Posted in Commentary with tags on August 19, 2026 by itnerd

Recently, cybersecurity researcher Jeremiah Fowler discovered a database containing roughly 9,042,977 facial images totaling 450.2GB, in a research conducted in collaboration with ExpressVPN. The database, which appeared to be linked to ClarityCheck, a US-based reverse image search and identity verification service, was publicly accessible without password protection or encryption.

The exposed database contained:

  • Facial images stored in folders labeled “faces” and “profiles,” including photos of adults, teens, and children.
  • Profile pictures, screenshots, and personal photographs likely uploaded by users for searches or identity verification.

You can read Jeremiah’s full findings on the ExpressVPN blog here: https://www.expressvpn.com/blog/clarity-check-data-exposed/

The CISA warns Medusa ransomware has hit over 500 critical infrastructure organizations  

Posted in Commentary with tags on August 19, 2026 by itnerd

The CISA said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. Both Medusa developers and affiliates use a double-extortion model where they encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid.

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech: 

“Since Medusa first started adding victims to its data leak site in early 2023, we’ve logged just over 500 attacks in total (across all sectors and countries). As the figure is similar to CISA’s, this demonstrates how many ransomware victims slip under the radar, either because ransom negotiations are successful and the entity isn’t added to the group’s data leak site and/or the attack isn’t acknowledged/publicized by the entity involved.

To date, 162 organizations worldwide have confirmed attacks via Medusa and 100 of these are US-based. Of the confirmed US victims, 14 are government organizations, 25 are healthcare providers, seven are finance companies, three are tech companies, and four are manufacturers (two of which would be classed as critical infrastructure).”

The CISA has mitigation strategies that do work. I strongly suggest that you read and implement them ASAP or you could be Medusa’s next victim.

UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this to say:

   “It’s kind of refreshing to get back to a good old-fashioned ransomware story instead of everything being about AI. But I have a sneaking suspicion there’s some AI lurking underneath the surface here. The fact that attackers were exploiting vulnerabilities up to two weeks before patches were available tells me we’re either dealing with some incredibly talented security researchers and exploit developers, or AI is helping accelerate that process. Possibly both.

   “The other concerning part of this story is the continued focus by ransomware groups on critical infrastructure and healthcare. If attackers can disrupt a municipality, hospital, or another organization that serves a large community, they can create tremendous pressure that goes far beyond the financial impact on the organization itself. The dinner bell has been rung.

   “Attackers have figured out that these organizations can be lucrative targets because the people making the decision about whether to pay aren’t just answering to employees or shareholders. They’re answering to entire communities that may depend on those systems and services.”

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “Medusa is a good example of how ransomware operations have evolved beyond simply encrypting systems. When attackers can exploit a newly disclosed vulnerability within 24 hours, or potentially exploit it before it is even publicly disclosed, traditional patching cycles are no longer enough.

   “Organizations need to know exactly what they have exposed to the internet, prioritize those systems for rapid remediation, and have compensating controls in place when a patch isn’t available. The reported triple-extortion tactics also reinforce an important point: paying a ransom does not guarantee the incident is over. Attackers may come back for more, which makes resilient backups, segmentation, detection, and a tested incident response plan more important than ever.”

Damon Small, Board of Directors, Xcape, Inc.:

   “Rapid exploitation of perimeter vulnerabilities by Medusa ransomware operators presents an enduring operational risk to healthcare and critical infrastructure providers, where unexpected downtime threatens essential public services.

   “While the group occasionally weaponizes flaws shortly before or after public disclosure, its primary entry point remains well-known vulnerabilities on Internet-facing software for which patches already exist. As CISA and the FBI highlight, these threat actors intentionally target organizations that often lack dedicated cybersecurity teams. However, an absence of specialized security staff does not excuse neglecting fundamental IT administration.

   “Virtually all targeted entities employ internal or third-party system administrators whose core capability and job responsibility includes basic software maintenance and routine patching. Ransomware will remain a pervasive and lucrative threat as long as the industry fails to execute basic hygiene. Security leaders and IT managers must enforce strict patching SLAs on all edge assets, mandate rigid network segmentation around sensitive workloads, and maintain immutable offline backups to resist multi-stage extortion tactics.

   “Critical Takeaways

  • Hygiene failure: Medusa primarily weaponizes well-known, patchable vulnerabilities on Internet-facing systems rather than relying strictly on complex zero-days.
  • Administrative accountability: Lacking a dedicated security operations team does not absolve internal or third-party sysadmins from performing fundamental software maintenance.
  • Extortion escalation: Threat actors are increasingly turning to multi-stage extortion and re-extorting victims who pay, making immutable off-grid backups essential.

   “Ransomware operators do not need cutting-edge exploits when our industry refuses to perform routine IT maintenance.”

Seemant Sehgal, Founder & CEO, BreachLock:

   “Medusa’s activity is a reflection of how quickly today’s threat actors can move from identifying an opportunity to acting on it. The takeaway for defenders is that speed and visibility have become powerful advantages in security programs. 

   “Teams that continuously understand their internet-facing exposure, prioritize rapid remediation, and maintain strong operational discipline are in a much better position to stay ahead of emerging threats. 

   “The reported triple-extortion case is also a reminder that resilience is paramount. Effective recovery plans, tested response processes, and business continuity preparation give organizations options and control when facing a ransomware event.”

CVEs have spiked 10x since March Says Tuukka Tiainen Of Recast Software

Posted in Commentary with tags on August 19, 2026 by itnerd

Recast tracks CVE disclosures for third-party applications through its Setup Store catalog. Since March 2026, the number of unique CVEs registered each month has climbed from roughly 150-200 to more than 60,000 in June alone. This trend lines up with major software vendors (Chromium, Firefox among them) adopting AI-assisted vulnerability testing.

Tuukka Tiainen serves as Senior Security Engineer at Recast Software, bringing over a decade of experience in IT and information security. His expertise spans technical security as well as governance, risk, and compliance. Passionate about threat and vulnerability management, Tuukka also brings deep knowledge of Microsoft’s security solutions.

His Bio is here and here is his LinkedIn profile: .

What’s driving the trend?

This trend is driven by the industry with the assumption that with the expended usage of the AI tools, vendors can test more and catch more vulnerabilities in their software.

I can only talk about what I’ve seen during the time I have reviewed the monthly statistics (since May 2024). It is visibly clear that something has changed in the number of unique vulnerabilities patched by vendors this year. You can see those spikes starting to grow in March this year.

Browsers: Chromium and Firefox have dominated the vulnerabilities number wise for the last three months. Both Mozilla and Google are participating in Project Glasswing, giving them access to Anthropic’s frontier AI model. Firefox is evidence that harnessing Claude Mythos in their pipelines has greatly increased the number of security bugs found. See the blog written by their Tech Lead and Principal Engineer.

Microsoft and Google haven’t disclosed similar information about the findings to public but at least Microsoft has admitted publicly that they use Mythos. There’s a pretty strong assumption that the reason is the same for them resulting in more patched vulnerabilities in the last few months. I think that the Project Glasswing is just the first wave. Once the model and other frontier models get into the hands of more software vendors it will result in even more vulnerabilities to be patched.

What are the operational or security implications? What should organizations be doing differently as a result?

By following the same narrative, organizations using the 3rd party software should have more vulnerabilities to deal with. I would even claim that the number of exploits will grow because AI has become so much better in autonomously discovering weaknesses and chaining multiple lower-severity issues into exploits. In the worst-case scenario there will be more of everything: vulnerabilities, software versions (patches), out-of-band patches, exploits and zero-day vulnerabilities.

Another big aspect of this is the patch gap possibly becoming the most important vulnerability management metric. The “patch gap” is the time between a security patch becoming available and it being installed on your systems. The industry has traditionally focused on zero-days, but the patch gap may become an equally important security challenge. If AI can help attackers quickly reverse engineer patches and understand the vulnerabilities they fix, the window between a patch being released and an exploit becoming available could shrink dramatically. In that world, the greatest risk is not necessarily the vulnerability no one knows about, but the one everyone knows about and hasn’t patched yet. If this is the case, patch management vendors need to help to minimize the time between a software vendor releasing a patch, making it available for the customers and customers actually applying the patch on their systems.

If organizations need to patch more and faster, it might become a heavy burden for IT and security. I think this is one of the reasons why, for example, CISA is driving its new initiative for patching. Check out Patch Smarter, Not Harder. I also wrote a blog over a year ago how to patch smarter based on other factors than just the good old CVSS.

According to CISA, only the most critical vulnerabilities should be patched within three days. It is up to organizations to come up with their own processes, but it will be even more important to be able to prioritize in the future. Organizations should also play with the idea that they must be able to effectively patch a vulnerability within three days. How does that change the existing practices and models?

A brief explanation of where the data came from, how it was collected, what timeframe it covers, and approximately how many applications/CVEs were analyzed.

The vendors report CVEs when a new version is published. Sometimes this information is added later (a few days). We (Recast) scan those resources and as soon as the CVE data is available, it is added to the Setup Store. We are collecting the data about the applications stored in the catalog. The trend started to take a clear shape from March 2026 on. 

Are all these applications in Setup Store? Just third-party apps? Enterprise apps? Does the data include severity (Critical/High/etc.)?

This is related only to the applications stored in the Setup Store, so the scale in the market is larger. Those are 3rd party applications that were eligible to be added to the catalog. The data does not include the severity.

What is the biggest or most surprising trend?

It’s not that it’s surprising but rather expected. It is confirmation of the global security changes written in the data and that AI tools are used extensively and vendors are focusing on improving.

Here’s some raw data in graph form for your viewing pleasure:

Active China-Linked Cyber Espionage Campaign Targets Gov’t Across Asia

Posted in Commentary with tags on August 19, 2026 by itnerd

Bitdefender has released research detailing SilkParasite, an active, year-long China-nexus cyberespionage campaign targeting government bodies across Central Asia. The operation is using seven custom remote access tools (RATs), five of them newly identified.

SilkParasite is the latest evidence of a trend Bitdefender has tracked since early 2025: as Russia’s regional influence recedes, China-nexus threat actors are expanding operations into Central Asia, targeting government officials who manage the region’s deepening economic ties with Beijing. The objective is spying, not disruption or financial gain.

Key findings:

An active, year-long campaign using seven custom RATs against Central Asian government targets

Professionally engineered, modular toolset built for minimal footprint and evasion, using AI only to speed development, unlike poorly written AI-generated malware elsewhere

Command/Control (C2) traffic routed through legitimate cloud services, including Google Drive, to blend in with normal network traffic

Why it matters: China-nexus tooling typically resurfaces elsewhere, putting organizations across the globe at risk for similar attacks.

You can read the report here:https://businessinsights.bitdefender.com/silkparasite-tracking-china-nexus-apt-across-central-asia

Exclaimer Launches MSP Connect to Remove Billing and Management Friction for MSPs

Posted in Commentary with tags on August 19, 2026 by itnerd

Exclaimer today announced the launch of MSP Connect, a new partner program that enables managed service providers to provision, manage and grow centralized email signature services across multiple customer environments. The launch is part of Exclaimer’s channel-first growth strategy. Partners already account for approximately 30% of annual recurring revenue, and its global channel ecosystem includes roughly 5,000 partners.

Without centralized control, signature updates are made user by user or device by device, consuming IT time and making disclaimer, brand, and contact consistency difficult to enforce. Exclaimer replaces that with one centrally managed service across Microsoft 365 and Google Workspace.

MSP Connect brings together a consumption-based commercial model, a redesigned self-service portal, dedicated channel support and not-for-resale licensing. It is designed around how MSPs operate, allowing partners to manage customers centrally and align costs with actual usage rather than paying for licenses that are no longer in use.

Expanding the partner opportunity

For MSPs, the opportunity is to add a recurring service to existing Microsoft 365 and managed services relationships without introducing a complex deployment or support burden. Partners can generate license margin, bundle Exclaimer into broader managed service packages and build additional revenue through signature design, deployment and ongoing management.

Built around how MSPs operate

MSP Connect includes:

  • Consumption-based billing. MSPs pay a predictable monthly fee based on actual customer usage. When customers add users, reduce their footprint, leave the service, or operate seasonally, the MSP’s costs adjust accordingly.
  • Professional Services Automation (PSA) integrations. Native integrations connect Exclaimer to platforms already used in managed service operations, reducing administrative effort and making the service easier to incorporate into existing workflows.
  • Centralized self-service. The partner portal provides MSPs with a single place to provision and manage email signatures across multiple customer environments, reducing the need to submit support requests for routine administration.
  • Dedicated account management. MSPs have access to a dedicated channel account manager to support onboarding, positioning and growth.
  • NFR licensing. Partners receive a not-for-resale license so their teams can use and demonstrate the product.
  • Fast deployment. Exclaimer uses directory data to populate approved signature attributes across Microsoft 365 and Google Workspace. Depending on the customer environment, an MSP can deploy the service in under an hour, without a heavy integration project or mandatory professional services.

MSP Connect also gives partners room to build services around the platform. MSPs can offer signature template design, create template catalogs for customers, and bundle Exclaimer into a broader Microsoft 365 or managed services package. Their customers’ marketing teams can use approved campaign banners, engagement analytics and rules-based signature content, while IT retains centralized control over deployment and governance.

For end customers, centralized management keeps brand assets, employee details and legal disclaimers consistent across outgoing email without relying on individual users to apply updates.

Availability

MSP Connect is available immediately for partners globally. MSPs can learn more and join the program at https://exclaimer.com/campaigns/msp-connect-partner-recruit/.

Sauce Labs Expands AURA with Model Choice

Posted in Commentary on August 19, 2026 by itnerd

Sauce Labs, the test automation leader created by the founders of Selenium and Appium, today announced bring-your-own-model capabilities for AURA, its AI-Unified Release Assurance platform. A first in the industry, AURA platform now provides architecture support for enterprises to use open-source, open-weight, or proprietary large language models (LLMs) as AURA’s underlying model layer. This standardizes release assurance without forcing organizations to leverage a single AI provider for coding.

AURA closes the loop from business intent to production confidence by authoring, executing, analyzing and self-healing tests at AI speed, with humans in control. Its expanded architecture separates the model layer from Sauce Labs’ release assurance intelligence, agentic workflows, and execution infrastructure. Customers now have flexibility to change models as technology, regulations, or enterprise standards evolve while preserving one consistent system for verifying software. Enterprises running AURA achieve independently validated results: 90%+ fewer production incidents and 47% faster release cycles with 38% of engineering capacity reclaimed.

Model choice without platform compromise

As enterprises move from experimenting with AI code to deploying it in governed, production-scale environments, model choice becomes a strategic requirement. No single model will be the best fit for every organization or moment in time. AURA gives customers the flexibility to:

  • Choose supported models that align with internal security, privacy, governance, and architecture standards.
  • Evaluate and change models based on accuracy, latency, cost, and policy without replacing the release assurance platform.
  • Maintain one human-governed process across business intent, test authoring, execution, failure analysis, and production learning.
  • Sauce Labs AURA is the durable, model-independent assurance layer that remains when models change.

This flexibility allows enterprises to mix and match models for their needs while preserving consistent confidence for release assurance.

Your context belongs to you

Some vendors now acquire context engines and sell enterprise context back as a platform feature. Sauce Labs takes the opposite position: context belongs to the customer. Enterprises have already built it, in the models they have selected, tuned, and governed, and in the systems and data those models draw on. AURA connects to that investment instead of replacing it.

AURA then adds the context no vendor can acquire: evidence from execution. Informed by more than 8.7 billion test executions, AURA verifies how software actually behaves under real conditions, not how repositories and tickets say it should behave. The loop does not stop at release. AURA captures production errors and feeds them back to refine business intent and sharpen the next round of tests, so release quality improves with every cycle. Customers keep ownership of their context, choose their models, and run one governed system for release assurance.

Open by design

The model is only one component of reliable release assurance. AURA pairs the selected LLM with Sauce Labs’ domain intelligence, agentic workflows, execution across more than 10,000 devices, and a learning loop informed by more than 8.7 billion test executions. Enterprises gain model freedom without losing the context and infrastructure required to determine whether software is ready to release.

The announcement extends Sauce Labs’ long-standing commitment to open ecosystems. Created by the founders of Selenium and Appium, Sauce Labs applies the same principle to enterprise AI: customers should be able to adopt the tools and models that serve them best while relying on a common platform for confidence at scale. Because AURA is framework-agnostic, CI/CD-native, and designed for existing development environments, organizations can modernize the model layer without a rip-and-replace migration or fragmented release controls.

Availability

AURA’s model choice capabilities are available now for Sauce Labs enterprise customers. Supported models and deployment configurations will expand over time. Contact Sauce Labs to discuss compatibility and deployment requirements. Learn more at saucelabs.com.