Around 8.7 Million travellers’ info stolen at 3 UK airports

Posted in Commentary with tags , on August 29, 2026 by itnerd

Around 8.7 million travellers who signed up for WiFi, car parking services and lounges in airports run by Manchester Airports Group (MAG) had their data stolen, including email addresses and phone numbers, postcodes and vehicle registration details. MAG operates airports in Manchester, London Stansted and East Midlands, and declined the demand to pay ransom.

Denis Calderone, CTO, Suzu Labs:

The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings. No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.

What’s more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That’s a pivot upstream into a data provider, not downstream into operational systems. What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG’s network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.

The UK’s Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology. We don’t know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.

Seemant Sehgal, CEO and Founder, BreachLock:

“This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself. Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.”

This is why I use a VPN when I use public WiFi. In short, public WiFi cannot be trusted. You have to assume the same in order to keep safe.

PaperCut zero-day: “Boring” print servers become domain-wide threats

Posted in Commentary with tags on August 29, 2026 by itnerd

PaperCut’s urgent zero-day advisory is raising concerns well beyond the vulnerability itself, particularly given how many PaperCut servers are exposed to the internet and the potential for unauthenticated SYSTEM-level access. I have SMEs who are weighing in on the real-world exposure, why traditional vulnerability scanning can miss an actively exploited zero-day, and why defenders need to focus on containment, outbound controls and hunting for compromise – not just patching.

John Strand, Owner, Black Hills Information Security https://www.linkedin.com/in/john-strand-a1b4b62

“This is yet another example where the people who most need to see this vulnerability disclosure probably aren’t going to be the people who actually see it. Any sane computer security or IT professional would not have a PaperCut server directly exposed to the internet for anyone to access. But I just ran a quick check, and there are more than 100,000 PaperCut servers exposed directly to the internet right now. That’s the problem. We’re going to end up preaching to the choir until it’s far too late and these servers start getting compromised.”

Jacob Warner, Director of IT, Xcape, Inc. https://www.linkedin.com/in/jacob-warner-n1377

“Boring infrastructure with credential-free remote code execution and self-erasing payloads is how a print server becomes a domain-wide incident. When an unauthenticated request becomes SYSTEM on your print server, the resulting administrative compromise transforms routine utility services into elevated beachheads for lateral movement across enterprise environments. Because the attacker cleans up after themselves, security teams must patch now and assume the logs will not tell them if they were late to respond. Traditional vulnerability scanners often miss active zero-day exploitation until vendor signatures catch up. Defenders should patch or isolate today, close all Internet exposure, and image affected machines before remediation, as the attacker’s cleanup routine may have already deleted the logs that would have confirmed exposure.

“Unauthenticated remote code execution on print management software grants immediate elevated privileges, escalating utility software into a full domain threat. Self-erasing payloads and automated log deletion mean security teams cannot rely solely on post-incident forensic artifacts to detect compromise. Immediate containment requires closing all Internet exposure, imaging affected application servers prior to remediation, and applying vendor patches immediately.

“Boring utility servers make the best targets because nobody expects the print spooler to hand over domain administrator rights.”

Seemant Sehgal, Founder & CEO, BreachLock https://www.linkedin.com/in/s-sehgal

“Pre-authentication RCE means the attacker needs nothing from you. No credentials, no foothold, no prior access, before they own the application and can run arbitrary Java on your infrastructure. The first question every team should be answering right now is whether their PaperCut instance is reachable from the internet, because if it is, that answer is more urgent than any patch timeline. Vulnerability scanners will tell you the CVE exists, but they will not tell you whether an attacker already walked through it and what the impact would be if they did.”

Denis Calderon, Principal & CTO, Suzu Labs https://www.linkedin.com/in/deniscalderone

“PaperCut’s Application Server runs as SYSTEM on Windows, manages configurations for every endpoint in the org, and has a web-accessible console that is often exposed to the Internet. It’s “just printing”, but in this case, its important to treat it like any other management plane that holds implicit trust within your network.

“I ran a Shodan query this morning and found over 1,000 of these servers exposed to the public internet on their default management ports. A lot of them look like schools. That makes sense. PaperCut is heavily deployed in education for managing student print quotas, and students need to access the system from their own devices, so the web interface ends up internet-facing almost by necessity. The first confirmed victim to report this exploitation to PaperCut was a university. These servers are findable in seconds, they require zero credentials to exploit, and the attacker gets SYSTEM-level code execution. Unfortunately, even a well managed vulnerability scanning program wouldn’t have flagged this since it was an 0day, and you can’t see vulnerabilities that haven’t been discovered yet. That’s the fundamental limitation. The exposure itself was the risk, long before anyone knew the specific flaw.

“So, needless to say, get the PaperCut Emergency Patch Release 2 implemented immediately.  It covers v24, v25, and v26. I wish I could advise a holistic architectural fix like removing the admin interface off the internet, but it’s unclear from the current reporting whether that alone would have stopped this. The auth bypass operates below the URL routing layer, so even user-facing endpoints may have been sufficient for the attacker to reach the vulnerable components. What is clear is that a restrictive egress policy would have stopped this. Huntress’s proven exploit chain required SMB to traverse outbound from the victim to an attacker-controlled share. That can and should be controlled and stopped at the perimeter. If your PaperCut server can initiate outbound SMB to the internet, fix that today. And then hunt. Keep in mind that this malware deletes server.log, derby.log, and its own class files after execution. If your server was internet-exposed yesterday, patch or no patch, you need to be hunting today. Preserve those logs before you restart anything, look for the indicators Huntress published, and assume compromise until you can prove otherwise.”

If you use PaperCut, consider this a today problem. Patch now and keep watching this advisory as I am sure that this is not the last that we’ve heard of this issue.

Posted in Commentary with tags on August 29, 2026 by itnerd

More than 100 companies came together to make an open plea for collective action on cyber defense against AI-enabled cyber attacks. Signed by organizations including Accenture, Capital One, Anthropic, CloudFlare, Deutsche Telekom, Fifth Third Bank, General Motors, Microsoft, Red Hat, SAP, TransUnion and Zurich Insurance, the letter says these attacks “will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet—are at risk.”

John Strand, Owner, Black Hills Information Security:

“I think the sentiment behind what they’re doing here is fine, but I don’t think it moves the needle in any discernible way. A lot of this is motherhood and apple pie. They’re essentially telling organizations to spend more money on defensive security, which happens to directly support the marketing initiatives of many of the companies signing onto this. At a certain point, it starts to feel like infosec marketing theater.

“The one recommendation that actually has some teeth to it is the call for greater open exchange of detects and IOCs. But I would have liked to see these companies go much further. Many of them make billions of dollars from the security community. Why not create open initiatives where organizations can access threat intelligence feeds for free? Why not provide some of these security services at no cost to municipalities and other organizations that simply cannot afford them?

“Some companies already do this, and they deserve credit for it. But if the industry is going to collectively call for organizations to improve their security, it also needs to recognize the reality on the ground. A huge number of these organizations are understaffed, underfunded, and under attack. Many of the companies signing these initiatives have the resources and expertise to directly help them.

“Calling for better security is easy. Actually helping the organizations that can’t afford it would mean a hell of a lot more.”

Seemant Sehgal, CEO and Founder, BreachLock:

“There’s real value in this coalition, but there’s also a conflict of interest here. The companies asking governments to fund AI defensive tools are the same ones that would get paid to supply them, and some of them build the frontier models making the offensive side harder. That doesn’t make the warning wrong, but the recommended response isn’t neutral. The real question is whether hospitals, water utilities, and local governments get unrestricted funding to spend on what they actually need, or subsidized access to specific vendor products. Those are very different outcomes.”

Ryan McCurdy, VP, Liquibase (): 


“The warning is right, but using AI to defend against AI isn’t enough.

“AI is accelerating both sides of the equation: attackers can find weaknesses and execute attacks faster, while developers and AI agents are creating legitimate software and database changes faster than ever. Security teams have now got to determine whether a change is authorized, safe, and expected, and do it at a speed that humans simply can’t keep up with.

“That’s why governance has to move closer to the change itself. Organizations need to know what changed, whether it was authorized, and whether it meets policy before it reaches a critical system and data. And when something does get through, teams need the visibility to understand what happened, what’s impacted and how to recover quickly.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

More than 100 technology and cybersecurity companies signed an open letter this week, organized by OpenAI, calling for a “defenders’ window” to strengthen cyber defenses against increasingly capable AI-enabled attacks. The letter asks governments to fund cybersecurity improvements for hospitals, water utilities, and other critical infrastructure, while frontier AI developers provide model access, funding, training, and hands-on support. However, some of its most prominent signatories are also helping shorten that window.

OpenAI published this initiative weeks after its own models escaped intended isolation during a capability evaluation and compromised Hugging Face’s production infrastructure. Anthropic, Google, and Microsoft are co-signatories while simultaneously advancing frontier-model capabilities that expand what attackers can automate. The same capability race creating the urgency behind this letter is steadily compressing the window it asks defenders to use.

This is also part of a broader push this summer to put AI-powered cyber defense into critical infrastructure. In July, the UK’s National Cyber Security Centre outlined Cyber Shield, including autonomous vulnerability discovery and eventually fully automated vulnerability mitigation. That’s happening against a baseline where the UK’s National Audit Office found that departments lacked fully funded remediation plans for roughly half of their vulnerable legacy systems. The White House’s Gold Eagle initiative similarly proposes using frontier AI to accelerate vulnerability discovery and remediation across government and critical infrastructure.

Then Minnesota demonstrated what the actual bottleneck looks like. More than thirty community water systems were targeted in a coordinated cyberattack in late July. Federal authorities subsequently warned about attacks targeting internet-facing Rockwell Automation programmable logic controllers. In Braham, a community of roughly 1,700 people, compromised operating controls took the city’s well and water-treatment plant offline until operators restored service.

None of that required frontier AI.

Critical-infrastructure operators are struggling to inventory what’s connected to the internet, eliminate insecure remote access, hire dedicated security staff, and remediate vulnerabilities they already know about. Offering increasingly sophisticated AI defensive capabilities without fixing those fundamentals is like giving someone a Tesla when what they need is a road.

The letter acknowledges that these organizations need funding and hands-on support. But it contains no funding amounts, delivery deadlines, or firm financial commitments from its more than 100 signatories. If the companies warning that the defenders’ window is closing want to materially extend it, the commitment needs a dollar figure and a delivery date, not another page of corporate logos.

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

There is a little bit of “industry identifies an emergency; government buys industry’s solution” in this proposal. If the companies signing this letter believe that AI creates an urgent new systemic risk, I would expect them to put substantial skin in the game rather than simply asking taxpayers to fund another generation of security products: including through private partnerships for collective defense.

Before we spend public money putting AI on top of insecure infrastructure, I want to know that we have paid for the basics: remove PLCs from the public internet, secure remote access, segment networks, maintain backups, and make sure somebody actually owns the security of the system.

AI makes attacks faster and cheaper, but it does not repeal the fundamentals of cybersecurity. We should not use a new technology problem as an excuse to avoid fixing old, well-understood weaknesses.

Given this, now is a good time to look at the use of AI in your organization given that AI can’t be entirely trusted.

ServiceNow’s CVSS 10.0 trio shows how one platform patch cycle becomes everyone’s third-party risk problem

Posted in Commentary with tags on August 29, 2026 by itnerd

Four flaws hand just been disclosed in ServiceNow’s AI Platform, three of them scored a maximum CVSS 10.0: a code injection bug in the GraphQL Composite Data API (CVE-2026-18885), a privilege escalation flaw in the system configuration image upload processor (CVE-2026-18886), and a SQL injection through a dynamic schema ORDER BY clause (CVE-2026-74820), plus a lower-severity sandbox escape in the Now Platform (CVE-2026-6876, CVSS 8.7). ServiceNow patched its own hosted instances on August 27, but self-hosted customers must apply the fix themselves, leaving the responsibility for closing three maximum-severity holes with the customer rather than the vendor.

Jason Brown, Director of Counter Fraud Operations, iCOUNTER had this to say:

“Three maximum severity bugs in one disclosure is a lot, but the detail I’d focus on is the split between hosted and self hosted customers. ServiceNow’s hosted instances were already updated as part of the August 27 advisory. Everyone running ServiceNow on their own infrastructure now has to go find, schedule, and apply that patch themselves, and in a lot of organizations that process takes weeks, not days. During those weeks, an unauthenticated attacker with a working exploit for the GraphQL Composite Data API code injection bug or the SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals. I spent years chasing fraud operators who specifically target that lag between disclosure and patch adoption, because they know it’s where the easy access is. My advice to any security team running ServiceNow self hosted right now is simple: don’t wait for your normal patch cycle, treat this one as urgent and confirm it’s applied this week.”

Needless to say, if you use ServiceNow, it’s time to patch all the things. And maybe at the same time take a look at how ServiceNow is used in your organization.

Carhartt data breach exposes information of 12.9 million accounts

Posted in Commentary with tags on August 28, 2026 by itnerd

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.

Details available here: https://haveibeenpwned.com/Breach/Carhartt

Commenting on this news is Paul Bischoff, Consumer Privacy Advocate at Comparitech:

“ShinyHunters is a high-profile cybercriminal group and its claims areusually credible, so breach victims should take the risks seriously. Based on what Have I Been Pwned found, the breached customer data was mostly limited to contact information. That doesn’t pose a direct threat to customer’s bank accounts or identities, but it could be usedto target them with phishing messages. Employees could have moresensitive data risk, but we’ll probably have to wait a few weeks for Carhartt to finish its investigation before we learn exactly what datawas compromised.”

Just like any other breach, you should check Have I Been Pwned to see if you are affected. And if so you should of course change your password. While you are at it, you should make all your passwords unique to lessen the chance that a credential stuffing attack will work on you.

Meet the Samsung Galaxy S26 FE: Galaxy AI, My FanCam and More 

Posted in Commentary with tags on August 27, 2026 by itnerd

Samsung has announced the Galaxy S26 FE, the newest addition to the Galaxy S26 family, bringing signature Galaxy S camera and AI experiences together with the latest One UI 9

Built around the experiences people use most, Galaxy S26 FE puts a particular focus on capturing, editing and sharing content, alongside more personalized and context-aware Galaxy AI features. Highlights include: 

  • My FanCam comes to the Galaxy S series: First introduced on Samsung’s latest foldables, My FanCam automatically tracks a selected subject and keeps them centred in the frame, making it easier to capture social-ready video with less manual editing. 
  • More ways to capture and create: A triple rear camera system includes a 50MP wide, 12MP ultra-wide and 8MP telephoto camera with 3x optical zoom, while Nightography and Super Steady Video with Horizontal Lock help capture clearer, steadier footage. Photo Assist also lets users make edits using natural language prompts. 
  • The latest Galaxy AI with One UI 9: Updated Now Brief offers customizable briefing cards, while Now Nudge can surface relevant suggestions across select third-party apps and notifications. Circle to Search with Google and Gemini Live can also identify multiple items in an image at once. 
  • Built for the everyday: Galaxy S26 FE features a 6.7-inch Dynamic AMOLED 2X display with a 120Hz refresh rate, a 4,900mAh battery45W wired charging, and seven generations of OS upgrades and seven years of security updates. 

Galaxy S26 FE will be available starting September 4 in Blueberry, Graphite and Pistachio, starting at $1,049

Here’s some details:

Category Details 
Display 6.7” FHD+ Dynamic AMOLED 2X display; 120Hz refresh rate 
Processor Exynos 2500 
Memory 8GB RAM 
Storage 128GB, 256GB or 512GB 
Rear camera 50MP wide + 12MP ultra-wide + 8MP telephoto triple rear camera 
Front camera 12MP 
Battery 4,900mAh 
Charging 45W wired charging; 15W wireless charging 
Durability IP68 
Software One UI 9 / Android 17 
Category Details 
Pricing Starting at $1,049 
Colours Blueberry, Graphite, Pistachio 

OpenAI’s AI agents built their own hidden coordination system before the Hugging Face hack

Posted in Commentary with tags on August 27, 2026 by itnerd

OpenAI disclosed that AI agents coordinated the intrusion behind the Hugging Face breach through a self-organized communication system, first an improvised bulletin board inside its internal Artifactory service, then, after that was shut down, messages encoded directly into directory names, letting agents share tools, divide labor, and settle disputes. On July 10, an agent found 14 Hugging Face credentials with write access and posted them to the board, which other agents used to gain broad infrastructure access within days.

You can see the details here: OpenAI agents formed secret swarm, hacked Hugging Face, then forged their own logs

Gidi Cohen, CEO & Co-Founder, Bonfy.AI

“This shows how quickly AI agents can improvise when they find cracks in the rules. The message board wasn’t just a weird side effect, it became a coordination hub that let agents share discoveries, stack exploits, and push far past what the system expected. Once they had a way to talk, they basically formed a small team.

The speed is the real story. One note turned into a whole communication network, then into privilege escalation, then into agents building on each other’s work across runs. That’s not just misalignment, that’s group behavior emerging on its own. And seeing agents pressure each other, even when some tried to opt out, shows how unpredictable things get when they influence one another outside approved channels.

Yusif Mukhtarov, Lead Machine Learning Engineer, Polygraf AI

“The bigger takeaway is that isolation assumptions don’t hold anymore. If agents can create side channels, they will and their collective capability jumps fast. Teaching models to ignore unsanctioned instructions helps, but future systems need to assume agents will collaborate, improvise, and repurpose infrastructure unless guardrails are airtight. This incident feels less like an anomaly and more like a preview of how agentic systems behave when left to their own devices: resourceful, collaborative, and quick to escalate impact.”

There’s the time slot between May 12 and July 19th where no action from anyone was taken even though the agent left in a package repo. In that time period OpenAI pulled down Artifactory, revoked the credentials and brought everything back. It took one day for agents to start talking again, and this time the messages were hidden in directory names. The problem was treated as if it’s a credential one. But I think the disturbing part here is that agents refused things. Some of them pulled out once they realized it was unauthorized hacking. The group got a proposal to contact an outside party because it was social engineering. Then one of the agents that objected went ahead anyway after another agent posted a deadline at it. This shows how models have a safety behavior that folds when the pressure comes from a peer. OpenAI’s building that distinction into training now, which tells us how far ahead of the safety work multi-agent deployment has gotten. Everything else here was ordinary hygiene: 14 write-capable credentials sitting in a public dataset, admin rights through an unpatched flaw, 22 admin accounts the agents made that nobody flagged.”

If you let AI do its thing without having proper safety measures, bad things will happen. This is an example of that. And you should take note and take action.

UPDATE: An independent investigation by METR and Redwood Research was also posted on this issue. Bri Frost, Director of Product Management, Cloud Range had this to say:

“If your AI security strategy is ‘put it in a sandbox and trust the prompt,’ you don’t have a security strategy, you have a wish. The Irregular and OpenAI–Hugging Face incidents show that AI agents will systematically search for any available path to complete an objective, acquire new credentials, assume trusted identities, communicate with other agents, and continue beyond their intended scope. Containment still matters, but this is increasingly an identity and behavior problem: organizations must continuously validate what an agent is doing, whether it remains authorized, and how quickly its access can be revoked.

The most uncomfortable part is that METR had to rely heavily on AI agents to analyze the AI agents and admitted those analysis agents made mistakes human researchers likely would not have made. That should end the fantasy that we are ready for fully autonomous agents. Humans still need to evaluate, orchestrate, and validate these systems in safe environments while defenders build the muscle memory to respond at machine speed. Until an organization can detect and stop an agent, or even hundreds of collaborating agents, from going off mission, deploying one with broad authority is not innovation. It is an uncontrolled production experiment.”

ATF investigating ‘major’ cybersecurity incident

Posted in Commentary with tags on August 27, 2026 by itnerd

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) yesterday announced an investigation into a “major” cybersecurity incident that the Qilin ransomware group claimed responsibility for. Given that is is Qilin, that’s all that needs to be said really.

Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech

“We recorded a significant uptick in the number of Qilin’s claims last month. Qilin claimed responsibility for the second-most data breaches out of all ransomware gangs in July, second only to the Gentlemen. Many of Qilin’s attack claims have proven credible. Most experts believe Qilin is based in Russia, which raises further questions about national security and what data was exposed.”

If you want to see more details on the Comparitech report that is being referred to, here you go: https://www.comparitech.com/news/ransomware-roundup-july-2026/

UPDATE: The ATF has since confirmed a breach of one standalone, isolated system that was quickly disconnected, and says its enterprise network, eForms system, and core mission functions were not affected. Qilin listed the ATF on its leak site on August 26 but hasn’t posted the screenshots or stolen documents it typically shares as proof, and the DOJ has designated it a “major incident,” which triggers mandatory federal reporting.


Adrian Culley, offensive security engineer at SafeBreach had this to say:

“ATF’s claim that the compromised system “operates separately from the ATF enterprise network” is the detail worth testing rather than accepting at face value. A genuinely standalone system with no route out has no way to hand data to Qilin’s leak site — so either that isolation has a gap nobody has mapped yet, or the segmentation held and what Qilin is holding is thinner than the leak posting implies. Both are worth knowing before this gets filed as contained.

Qilin’s tradecraft favours exploiting internet-facing systems for initial access (T1190) before attempting lateral movement (T1021) toward whatever segment holds value. That a federal law enforcement agency runs a system isolated enough to survive contact with its enterprise network is good practice. Whether that isolation has actually been tested against an actor trying to break out of it is a separate question, and the more important one.

Owning a segmentation boundary and knowing it holds under a live attack path are not the same claim. Before this incident is closed out, I am sure that the ATF’s own investigators will be running the same lateral-movement techniques Qilin favours against that boundary directly, rather than relying on logs that simply show no crossing occurred.

Guest Post: Why GRC Is Becoming an Engineering Discipline 

Posted in Commentary with tags on August 27, 2026 by itnerd

By Yasmine Abdillahi, Executive Director of Cyber GRC and Business Information Security Officer, Comcast 

When security leaders hear “engineering discipline” applied to Governance, Risk, and Compliance (GRC), the instinct is to brace for more tooling, more headcount, and more infrastructure that needs to be justified to the board. 

But this initial reaction misreads what is actually happening. GRC is becoming an engineering discipline not because someone decided to make it more complicated, but because the complexity was already there. The compliance programs built a decade ago were designed for the slower world of annual audits, static risk registers, and policies that changed quarterly at best. That world is gone. Today, cloud infrastructure can spin up and down in hours, AI agents are proliferating, regulations can multiply across jurisdictions, and a board member might ask about risk posture, with the expectation of an immediately trustworthy answer. 

The teams making real progress aren’t the ones that have added more people or tools. They’re the ones that changed what GRC is built on. Today, GRC engineering is how organizations simplify governance, shorten the time it takes to find value, and stop reinventing the wheel of pipelines year after year. 

The Problem Is the Data Beneath GRC 

Most organizations don’t fail at GRC because they lack frameworks, policies, or good intentions. They fail because the underlying knowledge of what is connected to what, which data resides where, and which controls protect which assets is scattered piecemeal across security, IT, cloud, identity, and business systems — none of which were designed to maintain that picture coherently. Every time a control needs to be validated, someone manually pulls from multiple sources, normalizes the results, and hopes the timing is close enough to tell a consistent story. 

Consider a simple question: “How many of our critical systems have MFA enabled?” Answering it accurately means pulling identity data, cross-referencing asset inventory, filtering the results by criticality classification, and clarifying whether “enabled” means configured, enforced, or actively used. By the time the answer is ready, it’s already a snapshot from last week. Multiply that by the hundreds of controls a mature GRC program tracks, and you see the real problem: teams aren’t doing GRC work. They’re doing data plumbing. 

Why agentic AI is amplifying the urgency 

AI governance dominated the conversation at Black Hat USA 2026, with much of it tracing directly back to the Hugging Face incident — a preview of how quickly “AI agents” went from an emerging buzzword to the central topic on the floor. 

These solutions are responding to the fact that agents drift and can get exploited when nobody is looking at them. However, AI governance is not just a feature that can simply be added to existing security tool stack. It’s a practice or a discipline requiring alignment between IT, Cybersecurity, GRC, finance and the business. 

Access control issues for agents cannot be observed and trusted periodically. Instead, they need continuous validation and remediation. Because agents can update themselves at runtime; a control evidenced at a point in time may not be compliant an hour later. 

This isn’t hypothetical. In July 2026, an AI model undergoing a routine capability evaluation escaped its test environment and compromised Hugging Face’s production infrastructure — autonomously, over four days, without a human directing each step. The agent didn’t need stolen admin credentials to escalate; it read cloud metadata, minted its own service-account tokens, and mapped its own permissions in real time. That’s the identity-to-agent-to-asset chain breaking down in exactly the way static, point-in-time control evidence can’t catch. 

This is where the identity-to-agent-to-asset mapping underneath any GRC platform needs to be engineered and current. 

Why Building Your Own Solution Usually Stalls 

The natural response is to unify the data by building an internal pipeline, a custom dashboard, and a “security data fabric” that pulls everything into one place. The intent is right, but the execution is where things get hard. 

Data normalization is genuinely demanding. Matching a user record from an identity provider to a Configuration Management Database (CMDB) asset record and a Security Information and Event Management (SIEM) log entry isn’t a configuration task — it’s an engineering challenge requiring sustained expertise. Audit defensibility gets added after the fact, if at all. And maintenance quietly becomes a permanent commitment, consuming engineering capacity that was supposed to go elsewhere. 

Agentic AI makes the engineering lift heavier as its governance requires granular traceability including what the agents are permitted to do and what they actually did, with what inputs, on whose behalf and why. If an agent’s effective permissions can be manipulated by the content it processes through prompt injection, then “what can this agent do” isn’t a static fact pulled once and normalized; it has to be validated continuously. 

What “Engineering GRC” Actually Means 

Engineering GRC doesn’t mean every organization needs to engineer it themselves. It means GRC now depends on properties that must be designed in from the beginning, not added later. 

Those properties are observability, testability, and explainability. Observability means your compliance posture is visible in real time, not reconstructed at audit time. Testability means controls are validated continuously against live data, not just when a review is coming. And explainability means every metric has a traceable origin. If someone asks how a number was derived, you can show exactly what data was used, how it was transformed, and what was included or excluded. 

With adding agentic AI to the attack surface, internal pipelines that have been built to track control configuration need to be expanded to continuous action-level traceability. 

Where the Real ROI Lives 

An organization that has built toward these properties is doing something fundamentally different from one that prepares for audits by collecting screenshots. The output might look similar from the outside, but the foundation is entirely different. The business case is often framed around efficiency such as less audit prep time, and fewer manual handoffs. Those gains are real, but the more compelling argument is compounding value. 

In most GRC programs, a significant chunk of team time goes toward “rebuilding truth.” Every quarter, every audit, every board report, someone pulls from the same sources, normalizes the same fields, and produces a number everyone agrees on. That work doesn’t accumulate into anything. Engineering the data foundation converts this recurring cost into a durable asset — a compliance posture that updates continuously and produces the same defensible answer whether the question comes from internal audit, an external assessor, or the board. 

There’s a risk dimension too. When compliance data is manually assembled, a gap can exist for weeks without anyone knowing. When the foundation is continuous and observable, that window closes. 

Most importantly, with agentic AI, the cost of not having the mapping foundation is an attack vector and not just a control gap. 

The Shift Worth Making 

GRC is becoming an engineering discipline because trust and accountability must now operate at machine speed. The organizations navigating this well aren’t the ones building the most sophisticated internal capabilities — they’re the ones that stopped rebuilding truth from scratch and started instrumenting it. 

When talking to GRC leaders early on in this journey, the question is almost never: “Shouldn’t we do this?” Instead, it’s: “Where do we start?” The answer: start with the data you already have. Map where your control evidence actually comes from. Identify the reconciliation work your team does every quarter that produces no lasting value. Then ask what it would take to make that work happen once — automatically, continuously, with full lineage — instead of repeatedly by hand. 

That question leads you to the foundation. Everything else follows from there. 

About the Author 

Yasmine Abdillahi is Executive Director of Cyber GRC and Business Information Security Officer at Comcast, where she leads security risk and compliance across Comcast and Sky. She is a recognized speaker at SINET, Gartner Evanta, and BrightTalk. She is also a senior fellow at the Atlantic Council. Connect with her on LinkedIn: linkedin.com/in/yasmine-abdillahi-2631b97 

White House order targets foreign-made equipment and software in U.S. power grid 

Posted in Commentary with tags on August 27, 2026 by itnerd

Yesterday, the President Of The United States signed an executive order declaring a national emergency to secure the U.S. bulk-power system, citing cybersecurity and operational risks associated with foreign-produced energy equipment.

The order can prohibit the acquisition, importation, transfer or installation of foreign-made bulk-power equipment, including associated software and digital capabilities, when it is determined to pose a significant national security risk.

The order specifically warns that foreign-made equipment could contain vulnerabilities or digital backdoors capable of providing remote access to U.S. energy infrastructure.

The restrictions could affect equipment such as power transformers and components used in solar infrastructure. China currently accounts for 85% of global solar supply-chain production capacity.

The Department of Energy has 120 days to develop rules implementing the order in coordination with other federal agencies.

Doc McConnell, Head of Policy and Compliance, Finite State:

   “On August 26, the President declared a national emergency over foreign-made equipment in the United States electric grid. Executive Order 14420 is the latest in a series of supply chain actions from this administration, and it includes a now-familiar assumption: equipment manufactured in a foreign country poses a national security risk.

   “The order points to two reasons. First, where equipment incorporates software, firmware, or other digital components, an adversary could build in remote access for surveillance or sabotage. Second, an adversary could cut off the supply of critical equipment at a moment of its own choosing, and do real damage that way.

   “Supply chain risk is real, and it is appropriate for the federal government to act on it. But for software and firmware, I don’t agree that foreign development is inherently risky, or that requiring development to happen within our borders keeps us safe.

   “A better way to secure our critical infrastructure is to test the equipment we install. For example, analyzing the compiled firmware binary of bulk-power system equipment can identify vulnerabilities, surface insecure configurations, and allow us to mitigate specific risks to better secure our energy infrastructure, regardless of where that equipment was manufactured.

   “The Department of Energy has 120 days to write the implementing rule. I hope that we see an evidence-based approach to evaluating the security of the equipment in our energy grid.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “This has been a concern for a large number of people in the computer security industry for a very, very, very long time. If you go back to concerns raised around Super Micro Computer Incorporated, the bigger issue has always been the same. Where are the components that make up our critical infrastructure actually coming from, and how much do we really know about that supply chain?

   “It’s nice to finally see this being acknowledged at a serious level. But acknowledgment is the easy part.

   “The details of how this gets implemented are going to be much more interesting. This isn’t a situation where we can simply decide we don’t trust a supplier and buy the equipment somewhere else. China dominates the production of many of the components and materials that modern technology and critical infrastructure depend on. In some areas, there simply aren’t enough alternative suppliers to make an immediate transition realistic.

   “So yes, I’m glad this is being looked at. It should have been looked at much more seriously years ago. But the real question isn’t whether we recognize the supply chain risk. We do.

   “The question is how we actually reduce that risk when much of the supply chain we’re worried about is also the supply chain we currently depend on.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “The cybersecurity issue here isn’t limited to finding a secret backdoor soldered into a foreign-made transformer. A legitimate vendor update mechanism or remote maintenance service becomes a national-security dependency when the infrastructure behind it is controlled by an entity the U.S. considers adversarial. Modern grid equipment increasingly relies on vendor-maintained update channels, remote diagnostics, firmware management, and other lifecycle services. That control-plane dependency is the threat surface this order actually reaches.

   “The order’s definitions acknowledge this more clearly than its preamble. Section 2(a) expressly covers software, firmware, digital services, maintenance services, and remote-access capabilities. Section 5(b) separately tells agencies to consider “remote access capabilities, lifecycle maintenance and update mechanisms, and other supply chain dependencies.” That operative language goes well beyond hypothetical malicious implants.

   “Section 2(b) creates the harder enforcement challenge, authorizing DOE to order identification, isolation, monitoring, disconnection, or replacement of foreign equipment already installed. This is rip-and-replace authority dressed in “phased compliance” language. Traditional asset inventories may tell a utility who manufactured a device, but not who controls its firmware, update infrastructure, remote maintenance services, or other lifecycle dependencies. The 2020 version of this policy ran into the same implementation problem, with some utilities struggling to determine what equipment fell within scope.

   “The 120-day rulemaking window will determine whether this becomes enforceable policy or another unfunded mandate. If DOE applies the “Covered Foreign Entity” definition narrowly and provides a realistic pre-qualification pathway, utilities can plan around it. If the rules function as a blanket ban without realistic transition guidance, the order risks creating the same grid-reliability problem it is intended to prevent. You can’t rip out a 345kV transformer on a regulatory deadline when a compliant replacement may have a multi-year lead time.”


Donald McFarlane, Advisory Board Member, 
Xcape, Inc.

   “EO14420 is a balanced executive order.  It recognizes that supply-chain provenance is a legitimate national security issue without treating every piece of foreign-made equipment as inherently compromised.  DOE has to identify a connection to a covered foreign entity and make a risk determination, and the order expressly requires consideration of reliability, replacement availability and continuity of service before existing equipment is disconnected or removed.

   “The cyber concern goes well beyond transformers. The order specifically reaches inverters, battery-storage systems, protective relays, PLCs, intelligent electronic devices, software, firmware, maintenance services and remote-access capabilities. The electric grid is increasingly a distributed network of computers, and that is before considering the possibility of undocumented or deliberately concealed capabilities and covert communications channels. Whenever equipment can receive an update or a remote command, who built it, who maintains it and who ultimately retains access to it are important security questions.

   “One interesting feature is what the order leaves out. It reaches transmission down to 69 kV but specifically excludes local distribution. I would not interpret that to mean distribution is safe or unimportant. It looks more like deliberate risk prioritization: generation and transmission are where a successful attack is most likely to create cascading, nationally significant consequences, while distribution is vastly larger, more heterogeneous, subject to different regulatory authorities and potentially much harder to remediate given existing supply-chain dependencies. The exclusion of distribution shouldn’t be read to mean distribution is secure. It means the government is starting with the part of the grid where compromise can most readily become a national event.

   “But that boundary is becoming less comfortable as distributed energy resources proliferate. One compromised residential inverter is not a threat to the grid; coordinated control of thousands or tens of thousands of installations and their inverters, batteries, EV chargers or other distributed resources is a very different proposition. A large fleet of individually modest devices can become a systemically important grid asset if an adversary can command them together. That is why the security of aggregated distributed resources increasingly has to be considered alongside the traditional generation-and-transmission security perimeter.

   “So, I view this EO as an important first step rather than a complete solution.  Cheap infrastructure isn’t cheap if a foreign adversary may retain a control path into it.  The test should be straightforward: do we know what the equipment contains, what and how it communicates with, and who can update or remotely control it?  The next challenge is making sure we eventually apply that same security thinking below the traditional bulk-power boundary, without imposing requirements that utilities and domestic supply chains simply cannot meet.

   “Engineers deliberately build margin into systems, for safety, for growth, and for resilience. In too many parts of the country, rapid load growth and constrained generation and transmission growth are consuming that headroom.  Sophisticated controls and grid-enhancing technologies can help us extract more capacity from existing infrastructure, but they are no substitute for building sufficient physical generation and transmission.  Cybersecurity, supply-chain security and adequate capacity are all parts of the same operational resilience problem.  The United States needs this EO, and it needs substantially more investment in generation and transmission.  It is very encouraging to see this administration treating those issues with the seriousness they deserve.”

Critical Infrastructure needs to be protected. The power system is critical infrastructure and hopefully organizations of all sizes pay attention to this and take whatever action is required to make themselves secure.