UK considers new powers to shut down dangerous AI and block risky tech suppliers

Posted in Commentary with tags on September 3, 2026 by itnerd

UK lawmakers are considering giving the government emergency powers to deactivate powerful AI systems and shut down data centers if the technology poses a national security threat.

The proposed “kill switch,” introduced as an amendment to the Cyber Security and Resilience Bill, is intended as a last-resort mechanism to stop a runaway AI system before it can compromise critical national infrastructure.

At the same time, the UK government has introduced separate amendments to the same cybersecurity bill that would allow ministers to prevent critical infrastructure organizations from using technology suppliers deemed high risk. The new authority is aimed at supply-chain threats, where attackers can compromise a smaller technology provider and use its access to reach more sensitive organizations.

The move follows a recent cyberattack that forced a small UK power generation facility offline for four days.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“A government-mandated remote shutdown capability for data centers is a pre-installed denial-of-service mechanism waiting for the wrong hands. The amendment to the UK’s Cyber Security and Resilience Bill would require operators to build and maintain the exact infrastructure an attacker would need to cause the disruption the legislation claims to prevent. Compromise the authorization channel, and the government has handed the attacker a shutdown switch labeled “safety.”

“Responsibility for containing an AI system sits with the operator running it. If you’re deploying AI on critical infrastructure and cannot kill your own workload when it goes sideways, a minister reaching for a centralized override just confirms nobody expected operators to manage their own systems.

“Cybersecurity minister Baroness Lloyd rejected the proposal, arguing that directing an organization to stop using a specific AI model is more proportionate than shutting down shared infrastructure thousands of services depend on. She’s right.

“The supply-chain provisions in the same bill, letting ministers block critical infrastructure operators from using high-risk technology suppliers, respond to something real. An Iran-linked cyberattack forced a small UK energy generator offline for four days in July. Controlling which vendors touch critical networks addresses the entry point. A kill switch addresses the blast radius after the breach has already happened, and it does so by adding a new attack surface to defend.”

John Strand, Owner, Black Hills Information Security, Inc.:

“I feel like conversations like this in legislatures around the world are incredibly important, and I think many of the provisions being discussed absolutely should be put in place.

“However, I also think the way the conversation is arcing fundamentally misses the point of what AI actually is.

“AI is not something that can be controlled simply by regulating powerful companies like Anthropic, Google, and OpenAI. The technology is already dispersed. With roughly $5,000 worth of hardware, someone can run a highly functional model locally that may be slower than the most powerful commercial models, but can potentially be every bit as destructive.

“If our entire strategy for AI safety is built around restricting what large companies can do with potentially dangerous models, we’re addressing only one part of the problem. Those restrictions may be valuable, but they don’t address what happens when capable models are downloaded, modified, fine-tuned, and operated completely outside those environments.

“There needs to be a much larger conversation about mitigating controls. We need to be thinking about how organizations detect and respond to AI-enabled attacks, how infrastructure is protected when the attacker has access to these capabilities, and what defensive technologies need to change when powerful AI is available to practically anyone willing to invest a few thousand dollars in hardware.

“Regulating the largest AI companies may be part of the answer.

“It cannot be the entire answer.”

I seriously doubt that this is the answer. Thus I hope this gets the time and consideration that this does deserve.

The CISA and FBI advise organizations to drop PR spin during major IT, OT outages 

Posted in Commentary with tags , on September 3, 2026 by itnerd

The CISA and the FBI, alongside cybersecurity agencies from Australia, Canada, New Zealand and the UK, have released new guidance for communicating during major IT and OT outages, warning that poor communication can compound the operational damage caused by an incident.

The agencies specifically advise organizations to avoid PR and marketing language, clearly state what is known and unknown, and provide customers with technical and actionable information rather than vague descriptions such as “service degradation.”

The guidance recommends that organizations establish outage communication plans before an incident, including predefined thresholds for when notifications are required, designated spokespeople, backup communication channels and procedures for reaching customers, regulators and critical infrastructure operators.

During an outage, providers should explain which systems are affected, the scope and operational impact, and the known cause without speculating when an investigation is still underway. The agencies also call for continuous, time-stamped updates throughout an outage, including recovery milestones and actions being taken.

Joshua Marpet, Senior Product Security Consultant, Finite State:

“Agencies advocating clear communication with timely updates, and avoiding PR style language is great! Useless, but great. Companies will use whatever language their crisis communications firm advocates for, because that is how they avoid liability. Firms with the backbone to be open, honest, and transparent are not exactly the majority out there. Unless you have communication strategies mandated, you have an perfect example of Marpet’s law “Unless it’s mandated, or someone is paying for it, ain’t gonna happen”

“The EU CRA is a great example of mandating that type of communication. 24 hours, 72 hours, and 14 days, after an incident, there are specific types of communications with defined pieces of data you MUST give to the public and stakeholders. This is what we need, not best wishes and prayers.”

Denis Calderone, CTO, Suzu Labs:

“Let’s be honest, at a high level, none of this is new. Cross-functional incident teams, designated spokespeople, escalation paths, time-stamped updates, practice transparency. All of that has been in every incident response framework going back to NIST 800-61. Where this guidance actually adds value is in the operational specifics and the timing. It explicitly tells organizations to assume that their own telecommunications and primary communication channels may be disrupted or unreliable during a crisis. That means establishing and testing backup methods like radios, SMS phone trees, and out-of-band channels before you need them. When I run tabletop exercises for clients, one of the first things I do is take their communications down. Email is gone, Teams is gone, your status page is offline. Now coordinate your response and communicate with your customers. Most organizations completely fall apart at that point, and that is exactly the scenario this guidance is built for.

“The timing also matters. This drops alongside CISA’s CI Fortify initiative, which tells critical infrastructure operators to prepare to deliberately disconnect OT systems from third-party networks during a geopolitical crisis. If you’re a water utility or a power plant making a real-time decision about whether to isolate, you need your service providers telling you exactly what is happening and what is not happening. The guidance specifically calls for articulating “what it is and what it is not” to prevent misattribution. After the year we’ve had with attacks against water utilities, ports, power generation, and PLC suppliers, CISA clearly does not want the next big CI outage to trigger days of “was this a nation-state attack?” speculation while downstream operators are making blind isolation decisions.

“What gives this more weight than a typical government advisory is who helped write it. Microsoft, Sophos, Cloudflare, and American Water all contributed. Cloudflare’s November 2025 outage is explicitly cited as an informing event, and for good reason. Their status page went down during the incident, their own response team initially misidentified the root cause partly because of the communication breakdown, and the whole thing spiraled. The organizations that have been through it are helping write the playbook, and that gives the operational details real credibility.”

John Strand, Owner, Black Hills Information Security, Inc.:

“I think everything in this plan is great. There’s just one area I wish they would address more directly. When the decision is made to shut down network access, there need to be very clear lines defining who is authorized to make that decision and what political protections exist for the people making those calls.

“During a breach of this nature, one of the biggest communication problems is often figuring out who’s on first and who’s on second. Who can actually make the call? Who has the authority to shut down access?

“What often happens is that the decision gets escalated again and again and again until it eventually reaches a director, CEO, commissioner, or some other senior official who has enough authority to make the call. Meanwhile, valuable time is being lost.

“Incident response plans need to go deeper than motherhood and apple pie statements about communicating with customers, coordinating between organizations, and keeping everyone informed. That’s all important, but the plan needs to explicitly identify who has the authority to make the really hard decisions during an incident.

“Just as importantly, there needs to be political cover for the people who make those decisions.

“Hindsight is always 20/20. After an incident, everyone gets to sit around and analyze whether shutting something down was absolutely necessary. The person making that decision in the middle of an active breach doesn’t have that luxury.”

Notifications should never be like Apple release notes of “bug fixes and performance improvements”. They should have clear communication in them 100% of the time. Organizations need to work on that now.

Ridge Security asks which AI is actually best at hacking?

Posted in Commentary with tags on September 3, 2026 by itnerd

Everyone wants to know which AI model is smartest. But which one is actually best at hacking?

Ridge Security just published what it says is the first-of-its-kind public benchmark putting eight leading models head-to-head as autonomous pentesters. 96 tests across four vulnerable environments. And the results weren’t what you’d expect from a typical AI leaderboard.

Grok 4.5 led on coverage at 77%. Gemini 3 Flash hit 52% at just $5.42 a run. GPT-OSS-120B was the efficiency winner.

But here’s the more interesting part: the model itself may matter less than what you build around it. Ridge found that an agent’s ability to execute, recover when attacks fail and verify its own findings can make a huge difference.

They also found frontier models sometimes refusing to generate payloads or take exploitation steps even during authorized testing. A pretty interesting problem when you’re asking AI to actually do the hacking.

You can read the press release here: Ridge Security Publishes First-of-Its-Kind Benchmark Comparing Leading AI Models for Autonomous Red Teaming

NVIDIA Acquires Hugging Face

Posted in Commentary with tags on September 3, 2026 by itnerd

NVIDIA is acquiring Hugging Face. Here are the details:

Over the past decade, Clem, Julien, Thomas and the team at Hugging Face have built something remarkable: a vibrant home for the open model developer community.

More than 18 million developers, researchers and creators use Hugging Face to share more than 3 million models, 500,000 datasets and 1 million applications. More than 200,000 companies use the platform to discover, evaluate, customize and deploy AI.

Hugging Face will remain an open platform for the entire AI ecosystem. Developers will choose the models they want, the frameworks they want, the clouds and inference service providers they want and the computing platforms they want. NVIDIA compute will not be required to build on or deploy through Hugging Face.

Hugging Face will continue to support open source and open weight models from across the ecosystem, from every model builder. It will continue to support multi-cloud and multi-accelerator development and deployment, so builders can use the hardware and infrastructure that best fit their work.

Ryan McCurdy, VP, Liquibase:

“NVIDIA’s acquisition of Hugging Face is another sign that the value in AI is moving beyond the models themselves. Models are becoming more available, developers are creating software faster than ever, and AI agents are starting to take action across enterprise systems.

“For enterprises, that creates a new challenge. AI doesn’t just accelerate how quickly change can be created. It increases the volume and speed of changes that can reach critical systems. A bad database change can take an application offline, expose sensitive data, or create an audit and compliance issue.

“That makes the control layer more important. The question isn’t just what AI can create. It’s what AI should be allowed to change, what can reach production, and whether those decisions can be governed and audited. As AI becomes more autonomous, enterprises will need those controls built into the path to production rather than relying on humans to catch problems after the fact.”

AI clearly has value. So based on that I fully expect that this will not be the last purchase that NVIDIA makes.

Hisense Extends Long-Term Partnership as Official Partner of EUFA EURO 2028 

Posted in Commentary with tags on September 3, 2026 by itnerd

Hisense announced at IFA 2026 that it will continue its partnership with UEFA as an Official Partner of UEFA EURO 2028, marking the fourth consecutive UEFA European Championship supported by Hisense.

Hisense’s football journey began with UEFA EURO 2016 and has grown ever since, extending across successive UEFA EUROs and the FIFA World Cups in 2018, 2022 and 2026. For Hisense, the final whistle is not the end of the journey, but the beginning of the next chapter.

At IFA 2026, visitors can explore a dedicated UEFA EURO 2028 activation zone at the Hisense booth, featuring a football challenge with goals tracked and photos automatically generated for sharing. Together with Hisense’s latest innovations, the activation reflects the brand’s vision of “Innovating a Brighter Life” — using technology to make moments that bring people together more engaging and memorable.

Abstract ASTRO Research Blog Offers Way to Detect CrowdStrike Falcon Zero-Day FalconFlank Highlighted by Chaotic Eclipse Researcher

Posted in Commentary with tags on September 3, 2026 by itnerd

As you probably have already seen, a security researcher known as Chaotic Eclipse has published a proof-of-concept exploit called FalconFlank targeting CrowdStrike’s Falcon endpoint platform — the latest in a pattern of public releases against major endpoint security products, following recent disclosures against Kaspersky Endpoint Security and Gen Digital’s Avast Antivirus.

Abstract’s ASTRO research team blogged about it this afternoon and here are some highlights:

  • The exploit turns Falcon’s own defenses against it. FalconFlank reportedly abuses Falcon’s Microsoft Office malicious-macro-removal feature. It’s a remediation function that runs with elevated privileges and escalates from a low-privileged local user to a more powerful context on fully patched Windows 11 25H2 and Windows Server 2025 systems.
  • No CVE, no vendor confirmation yet. As of the blog’s publication, CrowdStrike has not confirmed the flaw’s validity or scope, and there’s no assigned CVE. The technical claims are researcher-provided and currently unverified.
  • A track record worth noting. This researcher has previously released working exploits, largely against Microsoft products including Windows and Defender, with some later observed being abused in the wild…often following public criticism of vendor vulnerability-handling processes.
  • Defenders aren’t stuck waiting on a patch. Abstract ASTRO has published behavioral detection logic, keyed on the underlying mechanism (an anomalous OLE file write, a specific DLL artifact, and a directory-mirroring/coordination pattern) rather than the exact published sample, which means it should hold up even against evasion attempts the researcher has already flagged.

Abstract points out that it’s tricky wth EDR products: the privileges these agents need to protect a host are the same privileges that create new attack surface when abused.

UPDATE: A CrowdStrike spokesperson said:

“We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” 

153 Million Drivers Licenses Hacked And Exposed

Posted in Commentary with tags on September 3, 2026 by itnerd

Bad news. If you are in the US or Canada, you might be among 153 million people who had their drivers license hacked and pop up on the dark web:

A threat actor this week started offering on the dark web digital scans of over 153 million US and Canadian driver’s licenses.

The driver’s licenses emerged on an identity theft service called Nexus. Simultaneously, a threat actor started promoting the service on a Russian cybercrime forum, claiming the possession of the IDs of over 170 million individuals.

On Nexus, visitors could find over 153 million driver’s licenses, more than 10 million identification cards, over 3 million travel documents and international IDs, and roughly 580,000 medical cards.

According to investigative journalist Brian Krebs, a blank search on Nexus appeared to return approximately 153 million results. Only around 1.1 million driver’s licenses were from Canada.

The threat actor behind Nexus alleged that the documents were exfiltrated from an active breach at an identity verification firm that serves multiple Fortune 500 companies, Krebs reports.

Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)

“A license contains the owner’s date of birth, address, physical descriptors, and a government-issued ID number. This is enough data to pass identity verification checks that most financial institutions and government agencies still treat as reliable. The harder problem is that unlike a compromised password, none of those fields can be changed, so every person in this dataset will carry this exposure with them for life. It’s good that this isn’t being taken lightly, but it may be time to raise the standard for ID verification checks.”

Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)

“This looks less like someone stole a database once and more like someone had persistent access to trusted systems or identities. If an attacker gets in as an employee, administrator, contractor or service account, database encryption does not save you because the system treats them as authorized. We do not yet know whether compromised credentials or legacy MFA were the entry point, but that seems likely. 

“For access to hundreds of millions of identity records, organizations should require fingerprint based biometric assured identity on dedicated hardware. And companies need to rethink how much identity data they retain in the first place.”

Donald McFarlane, Advisory Board Member, Xcape, Inc. (https://www.linkedin.com/in/dmcfarlane)

“I am far less interested in how the threat actors gained access than in why all this data was sitting there waiting to be stolen.

“IDScan’s own documentation says their product defaults to “Collect all” and retaining all records, and even touts the resulting PII and demographic data for retail and marketing purposes.  For some customers, IDScan provides retention choices; remarkably, its Basic plan appears to require collecting everything and provides no option to delete it. Checking my ID is one thing.  Building a permanent dossier because I showed it to you once is quite another.

“As Americans increasingly push back on systems like Flock that aggregate data about ordinary people’s movements into permanent surveillance databases, businesses should expect the same scrutiny when they aggregate identity data for purposes far beyond the transaction that justified collecting it. Showing ID because a merchant requires it is not an invitation to monetize your identity.

“Data minimization is a fundamental security control.  If a verification result will suffice, don’t keep the underlying document.  If a derived biometric template will suffice, don’t keep the image.  If you don’t need the data at all, don’t keep it in the first place. Executives who choose to hoard data they do not need should expect to answer for the consequences. Blaming the hackers does not excuse the business decision that created the target.”

John Strand, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“It feels like a broken record whenever we start talking about technology, unregulated industries, and the impact they can have on people.

“When you look at data brokers and the sheer amount of information they collect, purchase, acquire, aggregate, and store over time, it’s absolutely staggering. And this particular breach appears to be staggering in its own right.

“I don’t know what the perfect answer is for dealing with data brokers. But I do think we need to start treating this type of data with protections similar to what we provide for protected health information. Maybe that means bringing some of it under HIPAA-like protections or creating a regulatory framework that treats large collections of personal data with the same seriousness.

“I know regulation isn’t going to be a 100% solution. Nothing is. But there has to be some accountability around how this information is collected, how much of it companies are allowed to retain, and what security controls they’re required to have in place to protect it.

“Right now, we’re allowing companies to accumulate staggering amounts of information about people while the protections around that data simply haven’t kept pace.”

Denis Calderone, Principal/CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)

“We’ve been seeing more of these lately. Texas Parks & Wildlife lost 3 million. AssuranceAmerica exposed nearly 7 million. Now an identity verification provider has reportedly been compromised to the tune of 153 million. The scale keeps multiplying because the data keeps concentrating. Hertz, Target, Caesars, FedEx, over a thousand marijuana dispensaries all outsource identity checks to the same vendor. One breach, and every customer of every client is potentially exposed. 

“What makes this worse is the claim that data has been actively exfiltrating for over a year, and the database reportedly grew by 400,000 and this appears to be a live pipeline. The records aren’t just names and numbers and includes front, back, infrared, and ultraviolet scans of the physical license, which is enough to pass most identity checks that exist today. A compromised password gets reset in five minutes. A compromised driver’s license requires an in-person DMV visit, proof that fraud has already occurred, and a stack of paperwork; this is a lot of friction to the user/citizen. Meanwhile, age verification laws and know-your-customer mandates keep pushing more businesses to collect government-issued IDs through more third-party vendors. A recent analysis documented 88 identity verification breaches since 2011, and 42% of them occurred in just the last two and a half years. 

“Businesses using identity verification vendors need to start asking harder questions about how long scans are retained after verification is complete, whether there’s a contractual data minimization obligation, and whether they have an audit right. Because right now there is no infrastructure analogous to a credit freeze that lets someone flag a compromised driver’s license number. The burden falls entirely on individual victims to place flags manually, state by state, and hope the fraud shows up somewhere they can see it. Every organization collecting and centralizing government-issued identity documents needs to treat those data stores with at least the same security posture they’d apply to payment card data, if not higher. You can get a new credit card number in 24 hours. You can’t get a new face.”

This hack is pretty bad. If I can get a source to have you check to see if you are affected, I will do so. But right now it is safe to assume that you are affected unless otherwise told.

Cyber incidents hit millions of patients, disrupt hospital systems 

Posted in Commentary on September 2, 2026 by itnerd

A series of newly disclosed cyber incidents is affecting healthcare organizations across the U.S., exposing millions of patient records while also disrupting systems used to deliver care.

Aesto Health has confirmed a breach affecting 9.54 million people and at least 30 healthcare provider clients, making it the second-largest confirmed healthcare data breach of 2026 to date. Hackers accessed Aesto’s AWS environment and stole information that included SSNs, financial account information, medical histories, health records, insurance information and claims and billing data.

Separately, Nutex Health, which operates 27 hospitals and outpatient facilities across 12 states, confirmed that attackers stole patient, employee and healthcare provider information along with confidential business and financial data. The attackers are now threatening to publish the stolen information.

Meanwhile, Luminis Health is dealing with an active cyberattack that has made certain systems unavailable across its Maryland healthcare network, affecting access to some patient services.

Damon Small, Board of Directors, Xcape, Inc.:

“Three separate healthcare cybersecurity incidents in three weeks represent an alarming escalation that directly threatens patient care alongside data privacy. The disruption across Aesto Health, Nutex Health, and Luminis Health demonstrates that the operational risk extends far beyond exfiltrated protected health information (PHI) or regulatory fines. When cyber incidents cut off access to electronic health record (EHR) systems, clinical operations grind to a halt, delaying necessary care and risking patient safety. Healthcare providers have historically viewed IT systems as ancillary, underfunding them both operationally and fiscally. These recent events provide a definitive signal that clinical IT infrastructure is just as essential to positive patient outcomes as doctors, nurses, and medical machinery. To protect patient safety and maintain clinical continuity, healthcare executives must elevate IT security to a core operational priority, enforce strict third-party vendor risk controls, restrict network exposure, and maintain offline, immutable backups.

“Critical Takeaways:

  • Clinical IT infrastructure directly affects patient care delivery, making its defense as vital to health outcomes as doctors, nurses, or medical equipment.
  • EHR downtime and business associate breaches create immediate operational paralysis that extends far beyond health record theft.
  • Health system leadership must stop treating IT as an ancillary back-office expense and fund operational technology security accordingly.

“Treating hospital IT like an ancillary expense works right up until the emergency room is forced back to pen and paper.”

John Strand, Owner, Black Hills Information Security, Inc.:

“I am deeply concerned that breaches of this scale and magnitude aren’t even making it into mainstream media anymore.

“If you go back ten years or so, something like this would have been front-page news. But these breaches have happened so frequently, and the story is essentially the same story repeated over and over again with a different organization’s name attached to it, that I think a lot of media outlets simply don’t want to run them anymore. People don’t click on those articles like they used to.

“And I think that’s where the real danger is.

“We’re becoming numb to breaches of this magnitude. Unless you’re one of the people or organizations directly impacted, a massive cybersecurity breach barely registers on the radar for most Americans anymore.

“That normalization should concern us. The breaches haven’t become less serious. We’ve just become accustomed to them.”

Denis Calderone, CTO, Suzu Labs:

“Healthcare as a sector is having a bad year. Luminis Health in Maryland is the most recent, with systems still down and patients calling a phone number instead of logging into MyChart. The Gentlemen ransomware group is threatening to publish stolen data from Nutex Health’s 27 hospitals. Aesto Health had a breach back in December that took five months to confirm, and the number just landed on the HHS breach portal this week at 9.5 million patients across 30 providers. Two days ago it was McKesson and 284 million claimed records. DentaQuest already set the high mark for the year at 15 million. And this is just what’s making headlines right now.

“The legal and regulatory machinery is now moving as fast as the attacks. Nutex disclosed the breach to the SEC on August 24. A class action was filed in Texas three days later. That’s before the company even finished determining what was stolen. The Aesto breach happened in December 2025, wasn’t confirmed until May 2026, and is now the second-largest healthcare breach of the year at 9.5 million individuals. In April, HHS’s Office for Civil Rights settled four separate ransomware investigations for a combined $1.165 million, and the root finding in every single one was the same: failure to conduct an adequate risk analysis. Data breach class action filings went from 604 in 2022 to nearly 1,500 in 2024, and healthcare is feeding that pipeline faster than any other sector. The window between breach disclosure and lawsuit has effectively collapsed.

“The Gentlemen ransomware group went from emergence in mid-2025 to over 675 claimed attacks, with healthcare as their second most targeted sector. Aesto was breached in December, and confirmation didn’t come until May. Meanwhile, the legal bar for what constitutes reasonable cybersecurity in healthcare is already set, and it’s set by freely available government guidance. Plaintiffs’ attorneys are citing HIPAA Security Rule requirements and published CISA recommendations to establish a standard of care in court. The proposed Security Rule update isn’t creating new expectations. It’s codifying what juries are already being told is the baseline. If your organization can’t demonstrate its meeting that bar today, the breach is only the first problem.”

Healthcare is a sector that is targeted by hackers. Which means that if you are in healthcare, you need to defend yourself accordingly

Congress temporarily extends CISA 2015 through December

Posted in Commentary with tags on September 2, 2026 by itnerd

The House has approved a stopgap government funding bill that temporarily extends the Cybersecurity Information Sharing Act of 2015 through December 11, preventing the key cyber law from expiring at the end of September. The Senate previously passed the measure, which now heads to the President for his signature.

Industry groups and federal cyber officials have warned that allowing CISA 2015 protections to lapse could discourage companies from sharing breach and threat information and disrupt real-time intelligence sharing between government and the private sector.

CISA 2015 briefly expired during last year’s government shutdown, and efforts to secure a long-term reauthorization have repeatedly stalled despite calls from the White House and industry for a more permanent solution. The stopgap bill also extends the Technology Modernization Fund and National Cybersecurity Protection System through December 11.

Doc McConnell, Head of Policy and Compliance, Finite State:

“Although it is a positive sign that Congress has extended the Cybersecurity Information Sharing Act of 2015 through December rather than allow it to lapse, short-term renewals are counterproductive to our goals of shared cybersecurity responsibilities and free-flowing threat information.

“The United States has placed a bet that voluntary information-sharing is the best model for collective security. The benefit of pooling threat data means companies can learn from threat activity across the ecosystem and proactively defend themselves, rather than waiting to be targeted individually. CISA 2015 reduces the potential risks to sharing this data by creating liability protections, exemptions from antitrust concerns, and prohibitions on using this data for regulatory enforcement actions.

“Our voluntary approach stands in stark contrast to governments elsewhere, such as the European Union, that have strict mandatory reporting and disclosure requirements. If we want to demonstrate that the voluntary approach can be successful, we need a long-term, predictable structure to build trust. We cannot build that trust if companies expect their risk calculus to change every 90 days.”

Denis Calderone, CTO, Suzu Labs:

“Congress keeps telling us cybersecurity is a national priority and then governing it like it’s an afterthought. This is the second near-lapse of CISA 2015 in a year, and last year’s brief expiration during the shutdown sent legal teams scrambling. Some organizations paused their threat sharing programs entirely until the protections were confirmed back in place. The liability protections in CISA 2015 are what make private sector threat sharing work, and that kind of uncertainty slows down exactly the intelligence sharing that is so needed in the industry. The law has had broad bipartisan support since it was enacted in 2015 and the White House has been pushing for a permanent reauthorization. If you can’t get a long-term deal done on a law that virtually nobody opposes, that tells you everything about where cyber policy actually ranks on the Hill.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Every few months, the industry has to wonder whether the legal framework that makes threat sharing possible will still exist by the end of the quarter. Companies making decisions about what to share and with who are already calculating risk, and this kind of administrative instability changes those calculations before any law actually expires. Extending CISA 2015 to December 11 buys time, but it still doesn’t fix what the recurring uncertainty is doing to the underlying trust that makes information sharing work in the first place.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

“It is disappointing that cybersecurity information sharing has once again proved so intractable in Washington.

“I share Senator Paul’s broader concerns about government overreach, but opening voluntarily-shared threat intelligence to FOIA, or stripping away the narrow good-faith liability protections that enable sharing, seems like solving the wrong problem.

“If Washington cannot provide a durable framework for collective defense, it only serves to make private-sector partnerships that are less dependent on Washington look more attractive.”

John Strand, Owner, Black Hills Information Security, Inc.:

“In the early years of computer security, there was a huge reticence to publicly share information about breaches or vulnerabilities in products. Even penetration testing was something that was largely done in the shadows.

“Laws like this helped pull that information sharing out of the darkness. And that sharing is something the entire security industry now lives and breathes on. Researchers share vulnerabilities. Organizations share information about attacks. Security teams share indicators and techniques. That flow of information makes everybody better at defending their networks.

“So I think it’s incredibly important that they extended it. I’m just a little disappointed that this is another short-term extension that only buys us a few more months.

“This shouldn’t be something we have to keep revisiting every few months. It needs to be permanent. We need to make sure the level of information sharing we’ve developed over the past seven or eight years continues without organizations having to wonder whether the legal protections that helped enable it are suddenly going to disappear.”

The CISA does a lot of good work. Honestly, they need to funded in the long term. Otherwise the US is really going to come under threat from a cybersecurity standpoint.

Dropbox says about 5,000 accounts compromised in epic hack 

Posted in Commentary on September 2, 2026 by itnerd

Online file storage and sharing service Dropbox accounts were compromised in August after hackers exploited a flaw involving Lenovo’s account authentication system, with files accessed in some cases. Dropbox said hackers viewed and downloaded files from roughly 5,000 accounts

Wait? Dropbox is still a thing?

Anyway, commenting on this is Brian Higgins, Security Specialist at Comparitech:

“Dropbox has been successfully infiltrated more than once in the past. It’s notable that they are blaming affected account holders for lackadaisical independent security measures which could be an emerging trend for victim organisations. 

What also draws attention is the focus on share price fluctuations peri and post breach. 

Most companies of commensurate size tend to see a swift bounce-back so it’s worth monitoring the markets for a day or two for any ‘material impact’ on their business. 

Unfortunately for anyone affected Tim Rathschmid’s employers fall in to the ‘too big to be bothered’ club. It’s doubtful there will be any notable fallout from this incident but it stands as a salutary tale for anyone who still doesn’t have 2FA.”

Drop Dropbox. Clearly this isn’t safe and you shouldn’t be exposed as a result.

UPDATE: Dan Moore, Sr. Director CIAM Strategy at cybersecurity company FusionAuth, provided the following comments:

“This Dropbox account takeover highlights a dangerous emerging trend where attackers create fake accounts at a trusted federated identity source. The application then accepted tokens from those controlled accounts and linked them to application user profiles without requiring any verification from the real owner. The June Meta AI chatbot exploit worked in a similar way by allowing attackers to add recovery emails to target Instagram accounts and reset passwords. Modifying an account to add an additional login method should require the user to prove they own it.”