Posted in Commentary with tags ASOS on October 8, 2026 by itnerd
ASOS confirmed Thursday that its investigation found customer names and contact details had been accessed from a cybersecurity breach earlier this week. This differs from most hacks that I see as the threat actors used a trusted communication channel to communicate with the outside world. This takes away any doubt that they got in and ASOS got pwned.
Danny Jenkins, CEO and Co-Founder of ThreatLocker, provided the following comments:
“Organizations must stop treating legitimate employee credentials as a trusted key to the kingdom. If an attacker can trick an employee into giving them valid credentials, the question isn’t whether that employee should have been more careful. It’s why those credentials alone are enough to compromise an entire organization. Zero Trust defenses are designed to add hardware verification to authorization checks. In this case, had a device needed to be verified, stolen credentials may have been useless to the attacker if they weren’t using them from an approved device.”
Jason Brown, Director of Customer Advisory, Counter Fraud Lead, iCOUNTER
“The ASOS breach started with one employee who was tricked into handing over their login by someone impersonating a trusted contact. From there, the attacker reached the third-party platforms ASOS uses to talk to its customers. That’s the part security teams should focus on. Every marketing, messaging and customer data platform a company connects to becomes another route to its customers, and in this case the attacker used ASOS’s own push notification channel to announce the breach directly to shoppers. The same access that sent a ‘HACKED’ message could just as easily have sent a convincing phishing message from a brand customers already trust, which is why anyone who received that notification should be on alert for follow-up scams. The attackers’ claim that they compromised ASOS’s Snowflake instance hasn’t been confirmed, and Snowflake says its platform wasn’t compromised. But the broader point holds. AI marketing tools are often given wide access to customer data so they can personalize campaigns, and that makes them valuable targets. Companies need an inventory of every third-party platform that holds or can reach their customer data, clear limits on what each one can access, and strong authentication on the employee accounts that manage them. Organizations that work with retailers like ASOS should also treat any data those partners hold on them as potentially exposed until they hear otherwise. Threat intelligence that watches for impersonation campaigns against your employees and partners, and for your vendors’ names showing up in breach claims, gives you a chance to act before an attacker uses your own channels against your customers.”
Well at least they knew how they got in. The real question is what are they going to do about it? Better training? Passwordless solutions? It all has to be on the table.
Harness today announced that it has acquired select Augment Code assets, including Cosmos and the Auggie CLI products, the Code Context Engine, and related technology. The team behind these products will join Harness, accelerating its work to make the entire software development lifecycle increasingly autonomous.
Cosmos will become Harness Cosmos Software Factory Agent, with a clear role: automate engineering work from idea to code. From there, Harness’s existing agents for software delivery, security testing, runtime protection, and cost management take over, carrying the work into production and operations, creating a seamless agent to agent experience.
Connecting Augment’s Code Context Engine with Harness’s Software Delivery Knowledge Graph provides insights across the full SDLC – what’s being built, and what happens to it once it ships. Harness is bringing codebase understanding together with delivery context, so Harness Cosmos can make better-informed changes upfront, and Harness agents can use downstream findings to correct and verify them.
Introducing the Harness Cosmos Software Factory Agent
Harness Cosmos takes engineering work from idea to merge-ready code. When a requirement is written, a ticket is assigned, or a bug is reported, a fleet of Cosmos agents plans the change, writes the code and tests, and opens a pull request. Each agent works in its own isolated VM and pulls in an engineer only where judgment is needed, like approving a design or making the final merge.
Cosmos agents run as a continuous loop through ticket, code, and review. When a reviewer comments or a check fails, an agent fixes the issue on the same pull request. Teams can fork prebuilt Experts like Project Builder, PR Author, Deep Reviewer, and PR Fixer, tune each one to their own codebase, and deploy it organization-wide.
Augment’s Code Context Engine keeps a live map of the codebase, so changes fit the code already there. Model routing matches each task to the right model, and built-in integrations connect to GitHub, Jira, and Slack. Shared memory carries lessons from each review into the next change, and versioning and budget controls let teams run autonomous coding across the entire engineering organization.
What leaves the factory is a reviewed pull request, ready for Harness agents to test, secure, and deploy.
Shared context from code to production
Harness’s Software Delivery Knowledge Graph connects delivery and operational information, including builds, deployments, infrastructure, security, and costs. Augment’s Code Context Engine brings that same specificity to the code itself.
Before a change is written, Harness Cosmos will pull together the delivery context that should shape it: test cases, security requirements, past incidents and their remediations. Once that change exists, Harness’s downstream agents will use codebase context to reason about dependencies, risk, and what validation it needs. If something fails, the agents can loop until resolution.
Extending the Harness Autonomous SDLC Platform
Harness Cosmos joins the Harness platform, automating engineering work from idea to code. No matter how that code is written, the Harness platform already takes it the rest of the way:
The integration vision focuses on connecting Harness Cosmos workflows with the policies, permissions, and approvals that already govern the Harness platform, bringing the same discipline to creating a change that enterprises already expect when releasing one.
Availability
Harness Cosmos is now available. To learn more, read the announcement blog post, visit the website, or get started now.
Airrived has been named a Cool Vendor in the Gartner Coolest Vendor Innovations in Agentic AI Security report published on October 2, 2026.
Airrived turns business users into AI experts.
Airrived is an enterprise-grade Agentic OS and Sovereign AI Platform that lets business and domain experts build, deploy, and govern autonomous AI — without becoming AI engineers.
Users bring the domain expertise. Airrived brings the reasoning, enterprise context, orchestration, governance, and infrastructure needed to turn that expertise into autonomous systems capable of reasoning, collaborating, deciding, and acting.
Unlike copilots, which mainly assist users, or developer frameworks, which require teams to engineer agents from scratch, Airrived lets enterprises automate complex, multi-step work across cybersecurity, IT, and business operations.
The platform combines deep reasoning, Agentic Mesh, Context Lake, multi-agent orchestration, governance, and end-to-end Agentic Observability — plus pre-built agents and applications that dramatically shorten the path from AI experimentation to production.
Built for the Sovereign AI Enterprise.
Airrived gives enterprises full control over where and how their AI runs. It can be deployed in the cloud, in customer VPCs, on-premises, on private GPU infrastructure, or in fully air-gapped environments — keeping data, models, agents, context, and AI operations under customer control at all times.
That removes a major barrier to enterprise AI adoption: organizations can put autonomous AI directly into the hands of the people who understand the business, without requiring them to master the underlying technology.
With adoption across Fortune 150 enterprises and organizations worldwide, this recognition follows a string of major product advancements from Airrived — including Agentic Observability and Sovereign Agentic AI — as the company continues advancing its vision for governed, autonomous AI across the enterprise.
*Source: Gartner Report, Coolest Vendor Innovations in Agentic AI Security, by AI and Cybersecurity Insights Team, 2, October 2026. Gartner is a trademark of Gartner, Inc. and/or its affiliates.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
Posted in Commentary with tags Epson on October 8, 2026 by itnerd
Society is going through a digital reset. After years of delighting in our devices, the pendulum is swinging back toward the physical. From the resurgence of printed photos, scrapbooking and journaling to growing concerns about screen time in schools and at home, consumers are rediscovering the value of putting something tangible in their hands — making printers more relevant than ever for busy families, memory-keepers, creative hobbyists and work-from-home professionals.
And with select models on sale during Black Friday and throughout December, now is the time to get a head start on the holidays.
The Epson EcoTank ET-2980 Wireless All-in-One Colour Supertank Printer(MSRP: $399.99 CAD)A practical gift for busy households, the ET-2980 takes the stress out of everyday printing. Featuring wireless mobile printing, families on the go can conveniently print and scan from a smartphone . This model can print thousands of pages in colour without the hassle or cost of frequent ink replacements, making it ideal for everything from school projects and schedules to holiday cards and year-end paperwork.
EcoTank ET-4950 Wireless All-in-One Colour Supertank Printer(MSRP: $599.99 CAD) A thoughtful gift for the work-from-home warrior, the ET-4950 helps create a more efficient workspace. Its cartridge-free ink system includes enough ink to last up to three years, while productivity-focused features like automatic two-sided printing, copying and scanning make it easy to stay organized and productive year-round.
The EcoTank Photo ET-8550 All-in-One Wide-format Supertank Printer(MSRP: $1099.99)Epson’s best-selling photo printer in Canada, the ET-8550 is the perfect gift for creatives and photography enthusiasts. Designed to produce stunning, lab-quality photos, it can print wide-format borderless images up to 13″ x 19″, making it easy to transform favourite moments into statement pieces for any home.
TheEpsonExpression Photo XP-8800 (MSRP: $299.99) As Canadians rediscover the joy of printed photographs and personalized keepsakes, the XP-8800 makes a thoughtful and budget-friendly gift for memory-makers and DIY hobbyists alike. Built to bring the best memories off-screen and into the real world, this photo printer can create vibrant 4″ x 6″ photos in as little as 10 seconds, helping transform forgotten digitals into cherished displays.
TheEpson Lifestudio Pop Plus Projector(MSRP: $1,049.99) The gift of quality time never goes out of style.With built-in Google TV™ and access to more than 10,000 streaming apps, the Lifestudio Pop Plus Projector makes it easy to bring friends and family together for holiday movie marathons, family game nights and summer backyard screenings. Its sleek, compact design fits seamlessly into the home while turning virtually any room or backyard into a premium entertainment venue, creating memorable moments long after the holiday season ends.
The Epson Lifestudio Flex Plus Projector (MSRP: $1,299.99) Give the gift of a bigger, more immersive entertainment experience with the Lifestudio Flex Plus Projector. From blockbuster movie nights and championship games to gaming sessions with friends, its stunning 4K PRO-UHD® picture, Sound by Bose technology and display of up to 150 inches transform everyday viewing into something extraordinary. Featuring a versatile adjustable stand that projects vivid images on nearly any flat surface, it turns almost any space into a personal theatre, sports bar or gaming arena.
Epson FastFoto FF-680W Wireless High-speed Photo Scanning System (MSRP: $849.99) As more Canadians look for ways to preserve meaningful memories, the FF-680W offers a unique gift for the family storyteller. It quickly digitizes cherished photographs, helping protect decades of memories from fading, damage and photo overload. Paired with the Epson FastFoto app, users can organize their collections, add voice and text to photos and create slideshows to share family stories with loved ones for years to come.
Organizations experienced 2,803 weekly cyber attacks on average in September, up 16% month over month and 48% year over year.
Education remained the most targeted sector, averaging 6,656 weekly attacks per organization, a 59% year-over-year increase.
Europe recorded the sharpest regional rise at 61% year over year, while Latin America faced the highest volume at 3,813 weekly attacks per organization.
One in every 39 enterprise GenAI prompts posed a high risk of sensitive data leakage, affecting 89% of organizations that regularly use GenAI tools.
One in every 91 emails was classified as phishing, up from 1 in 112 in August; 81% of phishing emails contained links.
A total of 824 ransomware attacks were reported, 53% more than in September 2025.
September’s data shows cyber pressure rising across multiple fronts. Weekly attack volumes increased sharply, phishing became more prevalent, GenAI use continued to expand alongside sensitive-data exposure, and ransomware remained well above last year’s level. Together, these findings reinforce Check Point’s prevention-first view: organizations need AI-powered security, consistent visibility and shared intelligence across the full attack surface to reduce risk before it becomes business impact.
Global Cyber Attacks Accelerate
Organizations experienced an average of 2,803 cyber attacks per week in September 2026. That represents a 16% increase from August and a 48% increase compared with September 2025. The longer trend is equally significant: weekly attacks per organization rose from 2,055 in May to 2,803 in September, an increase of 36% over five months.
This sustained growth points to more than an isolated monthly spike, making resilience, exposure reduction and prevention increasingly important across networks, cloud, endpoints, email and AI services.
Education Faces the Highest Attack Volume
Education remained the most targeted industry in September, averaging 6,656 weekly attacks per organization, up 59% year over year. Attacks also rose 24% from August—the second-highest monthly growth across industries— and surpassing the previous steepest monthly increase for this sector seen in September 2024. The increase coincided with the start of the academic year, when students, faculty, parents and other users reconnect to institutional networks.
Telecommunications ranked second with 3,483 weekly attacks per organization, up 29% year over year, followed by Government with 3,443, up 37%. The figures show sustained pressure on sectors with broad user bases, essential services and complex digital environments.
Latin America Leads in Volume as Europe Records the Sharpest Increase
Latin America recorded the highest regional attack volume in September, averaging 3,813 weekly attacks per organization, up 35% year over year. Africa ranked second at 3,701 weekly attacks, followed by APAC at 3,593. Europe experienced the highest rate of growth, with attacks increasing 61% compared with September 2025. North America also rose sharply, up 50% year over year. Although Europe’s overall volume remains lower than that of the leading regions, it recorded the fastest growth of any region, signaling a rapidly intensifying threat environment for organizations there.
GenAI Risk Expands Alongside Enterprise Use
In September, 1 in every 39 enterprise GenAI prompts posed a high risk of sensitive data leakage, affecting 89% of organizations that regularly use GenAI tools. A further 14% of prompts contained potentially sensitive information, making prompt-based data exposure a mainstream governance concern. The average user generated 131 GenAI prompts during the month, a significant increase from August, while each organization used an average of eight tools. Rising prompt volumes and a broader toolset make it increasingly important to understand what information employees share, where it is processed and which controls apply.
Latin America recorded the highest regional rate of high-risk prompts at 1 in 25, or 4%, above the global average of 2.5%. North America followed at 1 in 37 prompts, APAC at 1 in 48 and Europe at 1 in 57. These ratios put the risk into practical terms: the lower the number, the more often employees are entering information that could expose sensitive data.
By industry, Business Services had the highest high-risk exposure rate at 4.9%, or 1 in every 20 prompts, moving up two places from August. Financial Services followed at 4.1%, or 1 in 25 prompts, with Healthcare & Medical at 3.5%, or 1 in 29. These sectors routinely handle client, financial and patient information, which helps explain why everyday use of GenAI tools can carry a greater risk of sensitive data exposure.
Sensitive Data Exposure Spans Core Business Information
Network and IT Infrastructure was the most common sensitive-data category, observed in GenAI prompts at 71% of organizations. Financial Data followed at 70%, Legal and Regulatory data at 68%, Employee and HR data at 62%, and personally identifiable information at 60%. These percentages reflect the share of organizations where each category was observed, not the share of prompts. The leading category includes information such as hardware and network configurations and IP addresses—details that could give attackers valuable insight into an organization’s internal environment if exposed.
Email Phishing Risk Increases
One in every 91 emails, or 1.1%, was classified as phishing in September, up from 1 in 112, or 0.89%, in August. Among phishing emails, 81% contained links and 11% contained attachments, confirming malicious links as the primary delivery method. Others relied on social engineering without either. In practical terms, phishing emails reached inboxes more frequently than in August, and the heavy reliance on links underlines the importance of checking URLs before users click.
North America recorded the highest regional phishing rate, with 1 in 79 emails, or 1.26%, classified as malicious.
By industry, Associations & Nonprofits had the highest rate at 2.17%, or 1 in 46 emails, twice the global average. Construction & Engineering followed at 2.05%, or 1 in 49 emails, and Real Estate, Rentals & Leasing at 1.38%, or 1 in 72. For Associations & Nonprofits, this means employees were exposed to phishing at roughly double the typical frequency.
Ransomware Remains Elevated Year over Year
* Ransomware data is drawn from double-extortion groups’ public “shame sites.” Although these sources have inherent biases, they provide useful insight into the ransomware landscape.
A total of 824 ransomware attacks were reported in September, representing a 53% increase compared with September 2025. Business Services was the most targeted industry, accounting for 31.3% of reported victims. Consumer Goods & Services followed at 15.2%, with Industrial Manufacturing at 11.0%. Because business services providers often hold data or system access on behalf of multiple clients, a single incident can have consequences that extend beyond the organization itself.
North America was the most affected region, accounting for 46% of reported ransomware incidents, followed by Europe at 25% and APAC at 17%. The United States accounted for 41.9% of reported victims, substantially ahead of Germany at 4.0% and Canada at 3.6%. These figures show where publicly claimed victims are concentrated, rather than the level of risk faced by an individual organization in each country.
The Gentlemen Leads the Ransomware Rankings
The Gentlemen was the most prevalent ransomware group in September, responsible for 13% of published attacks. Qilin followed with 9%, while Akira accounted for 5%. On top of the leading three actors, 80 further extortion groups reported ransomware attacks last month.
The Gentlemen: A fast-growing Ransomware-as-a-Service operation founded in mid-2025. It operates as both a RaaS provider and an Initial Access Broker and supports Windows, Linux and ESXi environments.
Qilin: An established Ransomware-as-a-Service group with victim disclosures dating back to 2022. It provides affiliates with encryption, negotiation and support infrastructure.
Akira: A Ransomware-as-a-Service actor first reported in 2023, with payloads targeting Windows, Linux and ESXi systems.
What September Tells Us
September’s figures show cyber risk increasing in both volume and breadth. Attack rates rose across every region, phishing became more frequent and ransomware remained well above last year’s level, while expanding GenAI use continued to expose sensitive information.
Organizations should focus on reducing exposure before it becomes business impact. Check Point’s prevention-first approach brings together AI-powered protection, shared intelligence and consistent governance across hybrid networks, cloud environments, digital workspaces and AI systems. As established and emerging risks converge, a unified security architecture can help teams prevent threats earlier, reduce complexity and secure AI adoption with greater confidence.
Posted in Commentary with tags Fortra on October 8, 2026 by itnerd
Fortra Intelligence and Research Experts (FIRE) have observed a massive 475% increase in phishing attacks leveraging remote management tools in 2026. These campaigns are targeting banking customers with fake support pages that prompt installation of legitimate software like AnyDesk, giving criminals ongoing access to victim devices and accounts. Once installed, threat actors have the ability to monitor activity, steal credentials, deploy additional malware or ransomware, and maintain persistent access long after the initial phishing interaction.
Fall reading week is on the horizon for most Ontario and Quebec post-secondary schools! With that in mind, I wanted to share how Samsung’s new Galaxy devices can help students maximize their time, whether that means studying or stepping away.
Reading week was about recharging. With a 4:3 aspect ratio when unfolded, the Samsung Galaxy Z Fold8 offers plenty of screen space for gaming, streaming TV shows or curling up with some non-textbook reading.
For the more studious folks, Samsung Galaxy Z Fold8 Ultra offers long-lasting battery support and an 8-inch main display, which opens up to make multi-tab researching and note-taking a breeze.
When there’s a major project to tackle, the new Samsung Galaxy Tab S12 Series offers an expansive Dynamic AMOLED 2X display and Samsung DeX for a more PC-like experience. The included S Pen also makes it easy to annotate readings, sketch out ideas or mark up content.
And since accidents happen on campus and at home, Samsung Care+ offers added protection for 24-month, 12-month and month-to-month terms on eligible Galaxy devices.
CloudSEK researchers have uncovered NEBULA, a malicious npm supply-chain campaign involving seven fake AI SDK packages distributed through four attacker-controlled accounts. The packages deploy a modified Windows remote-access trojan (RAT) capable of stealthy surveillance and remote control.
More concerningly, two malicious packages remained downloadable on npm as of October 8, despite being flagged as malicious.
Key findings:
7 malicious packages, 4 publisher accounts: CloudSEK linked seven packages to a single operator using four sequential disposable npm accounts.
Flagged, yet still downloadable: api-nebula and llm-nebula remained installable as of October 8. One package operated for days before receiving a formal malware advisory.
Stealthy RAT bypasses conventional DLL-based detection: The modified KNTRAT malware uses direct Windows system calls and an empty Import Address Table, undermining import-based security detection.
Invisible remote access and surveillance: Source-code analysis confirms hidden-desktop control, camera and microphone access, remote shell execution, and persistence at every user logon.
Convincing AI SDK disguise: The packages contain plausible AI client code, while obfuscated installation scripts secretly deploy the malware. The apparent SDK endpoint does not resolve.
162,464 npm packages scanned: CloudSEK’s YARA analysis of available npm archives from September 25–27 identified only the known campaign packages, with no false positives in the scanned dataset.
An important technical finding: The recovered implant did not beacon during more than 12 minutes of controlled testing, consistent with anti-analysis protections. Its capabilities were established through analysis of the recovered binary and the subsequently published KNTRAT source code. No successful victim compromise was confirmed.
Why this matters: The campaign demonstrates how attackers can exploit the growing demand for AI developer tools to introduce malware through trusted software development workflows, potentially exposing developer workstations and corporate environments.
Full research report, technical analysis and indicators of compromise:
Securonix, Inc., today introduced Securonix Advanced Behavioral Analytics (ABA), a new capability that helps security teams identify at machine speed, activity that is technically permitted but operationally abnormal. ABA features Agent and Entity Behavior Analytics (AEBA), which identifies when an enterprise AI agent uses an unexpected tool, accesses data outside its purpose or changes its operating pattern. It connects those changes with identity, authority, data use, asset sensitivity, timing and threat context, helping analysts understand what changed, why it matters and what to do next.
Compromised accounts, insider activity and AI agents can resemble legitimate behavior when events are reviewed in isolation. Advanced Behavioral Analytics combines AEBA with User and Entity Behavior Analytics (UEBA), which connects unusual login times, rising data access and contact with sensitive assets across systems and time. Together, AEBA and UEBA help analysts investigate developing risk instead of isolated alerts and carry context through detection, investigation, case management and governed response. Policies, approvals and audit records remain visible and enforceable throughout the process.
Detect AI-Accelerated Attacks and Govern the Response
Traditional SIEM platforms were built to collect and correlate human and machine activity before enterprise AI agents became part of the attack surface. Securonix extends behavioral baselines and risk detection across users, identities, assets, applications, cloud environments and AI agents. It correlates signals across systems and time to surface compromised identities, unusual access, privilege misuse, sensitive data exposure and abnormal agent activity. An expanding catalog of AI-threat policies helps teams detect established attack techniques such as AI compresses reconnaissance, exploit development, privilege escalation and data movement.
Sam, the AI SOC Analyst, executes repeatable Tier 1 and Tier 2 work across triage, investigation, evidence collection and case creation. The Agentic Mesh coordinates AI-supported workflows, while Agentic Guardrails keep actions policy-bound, visible and auditable. Analysts review and approve consequential response actions. By completing repeatable work, Sam helps security teams absorb growing alert volumes and expand SOC capacity without requiring linear growth in headcount.
For authorized insider-risk investigations, the Securonix Insider Intent Agent adds contextual and corroborating evidence while preserving competing explanations. Analysts review each signal as part of the broader evidence rather than treating a message, search or behavioral deviation as proof of intent.
New Research Supports Critical Need For AI Governance Pressure
Securonix research found increased AI investment alongside continued questions about governance, trust and human accountability. For The Evolution of Cybersecurity Automation: Towards the AI-Governed SOC, Securonix surveyed 1,000 global cybersecurity professionals during summer 2026.
Survey findings show that cybersecurity teams want automation and AI to advance work inside clear approval boundaries. In the survey, 96% of respondents said cybersecurity automation is important to their organization, 49% said they use AI in behavioral analytics with human approval and 99.6% said their organization had increased its budget for AI in cybersecurity automation during the past year.
Investment has moved past experimentation. Security teams want AI to advance the work inside clear approval boundaries, with evidence they can explain and outcomes they can defend. The full report and methodology will be available in November.
Independent Assurance for Governed AI
Securonix has also achieved ISO/IEC 42001:2023 certification, the world’s first AI management system standard. The certification covers the management system used to govern AI across the Securonix product portfolio, including ThreatQ, and follows an external audit with no major findings. It provides independent validation of accountability, AI risk management and human oversight and can support customer due diligence across security, procurement and AI governance reviews. The certificate is available through the Securonix Trust Center.
Availability
Securonix Advanced Behavioral Analytics is available now.
Posted in Commentary with tags Volvo on October 8, 2026 by itnerd
The research, conducted by Volvo Cars Safety Centre, challenges the long-standing assumption that cars are inherently not equally safe for women and men. It demonstrates that equal protection can be achieved through data-driven safety development grounded in real-world crash research.
Comparing Volvo car models from 2010–2019 with models from 1970–1979, overall injury risk for drivers has decreased by 79 per cent. For women, the reduction is even greater, at 88 per cent, bringing injury risk to the same level as that of men.
The results also show substantial advances in occupant protection across all seating positions. Restrained rear-seat occupants in Volvo cars benefit from protection levels comparable to, and in some cases exceeding, those of front-seat occupants.
This underscores the effectiveness of decades of rear-seat safety innovation in Volvo cars, despite the lack of stringent regulatory requirements and standardised testing over the years.
The approach behind equal safety for everyone Since 1970, Volvo Cars has collected data from over 50,000 real-world crashes involving over 80,000 occupants. Through its Circle of Life safety development approach, these insights are translated into safety requirements, testing, vehicle development, verification and production. The result is a continuous cycle of learning that helps drive innovations and improve protection for everyone.
This approach has also laid the foundation for the pioneering Volvo Cars Safety Standard. Volvo Cars sets its own benchmark for real-world safety, going above and beyond what is required in regulations or safety ratings. This includes developing and testing cars for a wider range of real-world crash scenarios across all seating positions.
And because real world crashes don’t involve standardized crash test dummies, Volvo Cars’ research involves considering a diverse range of occupant characteristics, including gender, height, body shape and weight. As a result, the company’s safety innovations are designed with the same diversity in mind.
For decades, Volvo Cars has openly shared its safety research to help raise safety standards across the industry. As part of the Equal Vehicles for All (E.V.A.) Initiative, launched in 2019, more than 50 years of safety research is freely accessible in a digital library – enabling other carmakers, researchers and policymakers to build on Volvo Cars’ unique real-world safety insights.
About the study The study was led by Lotta Jakobsson, Ph.D. Eng. and Thomas Broberg, Ph.Lic. Eng. at Volvo Cars Safety Centre. It was published as part of the Enhance Safety of Vehicle (ESV) International Conference 2026.
Drawing on more than 50 years of real-world crash data, it is one of the most extensive long-term occupant safety studies in the automotive industry. The study analyses a broad range of real-world crash scenarios, including frontal, side and rear-end impacts, run-off-road accidents, rollovers, side-swipe collisions, large animal impacts and multi-collision crashes. It focuses on belted occupants aged 13 and older and examines injuries with moderate potential to threaten life, such as fractures and concussions, while excluding minor injuries such as bruises and pain.
ASOS Confirms That They Were Pwned
Posted in Commentary with tags ASOS on October 8, 2026 by itnerdASOS confirmed Thursday that its investigation found customer names and contact details had been accessed from a cybersecurity breach earlier this week. This differs from most hacks that I see as the threat actors used a trusted communication channel to communicate with the outside world. This takes away any doubt that they got in and ASOS got pwned.
More info here: https://www.reuters.com/business/retail-consumer/uks-asos-says-breach-exposed-some-customer-personal-data-2026-10-08/?utm_source=chatgpt.com
Danny Jenkins, CEO and Co-Founder of ThreatLocker, provided the following comments:
“Organizations must stop treating legitimate employee credentials as a trusted key to the kingdom. If an attacker can trick an employee into giving them valid credentials, the question isn’t whether that employee should have been more careful. It’s why those credentials alone are enough to compromise an entire organization. Zero Trust defenses are designed to add hardware verification to authorization checks. In this case, had a device needed to be verified, stolen credentials may have been useless to the attacker if they weren’t using them from an approved device.”
Jason Brown, Director of Customer Advisory, Counter Fraud Lead, iCOUNTER
“The ASOS breach started with one employee who was tricked into handing over their login by someone impersonating a trusted contact. From there, the attacker reached the third-party platforms ASOS uses to talk to its customers. That’s the part security teams should focus on. Every marketing, messaging and customer data platform a company connects to becomes another route to its customers, and in this case the attacker used ASOS’s own push notification channel to announce the breach directly to shoppers. The same access that sent a ‘HACKED’ message could just as easily have sent a convincing phishing message from a brand customers already trust, which is why anyone who received that notification should be on alert for follow-up scams. The attackers’ claim that they compromised ASOS’s Snowflake instance hasn’t been confirmed, and Snowflake says its platform wasn’t compromised. But the broader point holds. AI marketing tools are often given wide access to customer data so they can personalize campaigns, and that makes them valuable targets. Companies need an inventory of every third-party platform that holds or can reach their customer data, clear limits on what each one can access, and strong authentication on the employee accounts that manage them. Organizations that work with retailers like ASOS should also treat any data those partners hold on them as potentially exposed until they hear otherwise. Threat intelligence that watches for impersonation campaigns against your employees and partners, and for your vendors’ names showing up in breach claims, gives you a chance to act before an attacker uses your own channels against your customers.”
Well at least they knew how they got in. The real question is what are they going to do about it? Better training? Passwordless solutions? It all has to be on the table.
Leave a comment »