Guest Post: What Is Brand Phishing and Why Does It Work?

Posted in Commentary with tags on July 23, 2026 by itnerd

Brand phishing is when a scammer impersonates a trusted, well known company, through email, a fake website, or both, in order to steal login credentials, payment details, or personal information. It works because trust is transferable. If a message looks like it came from a brand you already use and rely on, your guard drops. You’re not evaluating a stranger’s request. You’re responding to what feels like routine correspondence from a company you already have a relationship with. That single psychological shortcut is the entire business model behind brand phishing.

Which Brand Was Impersonated Most in Q2 2026?

Microsoft, by a wide margin. In Q2 2026, Microsoft remained the most impersonated brand in phishing attacks, accounting for 23% of all brand impersonation attempts, nearly double the next closest brand. Here’s how the full top ten broke down.

Together, the top five brand names cover more than half of all brand phishing activity this quarter. That concentration is worth sitting with. Scammers aren’t spreading their efforts across thousands of brands. They’re focused on a small set of names that nearly everyone recognizes and uses daily, since that recognition is what makes the con work in the first place.

Why Did ChatGPT Suddenly Join the Top Ten?

For the first time, the ChatGPT appeared among the ten most impersonated brands tracked in this report. It’s a strong signal of where attacker attention is heading next. As AI tools move from novelty to daily habit for millions of people managing subscriptions, payments, and work tasks through them, they become just as attractive a target as any bank or tech giant. One example from June involved a fake ChatGPT Plus billing email, built to look exactly like an OpenAI payment failure notice, that led to a page designed to harvest full credit card details. Expect AI platforms to keep climbing this list in future quarters.

Which Industries Get Targeted Most?

Technology led as the most impersonated sector overall, with Social Networks and Banking close behind. This lines up neatly with the brand rankings above. The industries under the most pressure are the ones handling our identities, our professional relationships, and our money, which also happen to be the accounts most people would be quickest to protect if only they knew an attack was happening.

What Do Real Phishing Attempts Actually Look Like?

The following sample of documented cases from this quarter demonstrate just how varied these schemes can be.

ChatGPT. A fake subscription failure email led to a payment page built to steal credit card details, using an official looking OpenAI subject line and branding.

Michael Kors. A registered lookalike site replicated the entire shopping experience, browsing, cart, and checkout, all designed to capture payment information under the guise of a real purchase.

UNIQLO. A fake regional storefront appeared for a market UNIQLO doesn’t officially operate in. The giveaway was that its social media icons didn’t actually connect to UNIQLO’s real accounts.

Apple. A fake iCloud login page, presented in Russian, used Apple’s real logo and branding. The sign in button itself didn’t work, suggesting the page was still being tested before a fuller campaign.

PayPal. A near identical login page carried a noticeably distorted PayPal logo, a likely sign it had been produced with an AI image tool rather than lifted from PayPal’s actual assets.

Microsoft. A fake support page pushed an urgent Office security update. Clicking through didn’t install anything from Microsoft. It delivered a disguised executable file, the first step of a malware infection.

What Gives Phishing Attempts Away?

A few patterns showed up across nearly every case.

A sense of urgency is doing the work. Payment failures, security alerts, and required updates all push you to act before you stop to think, which is exactly the point.

Small visual flaws are common. A distorted logo, a button that doesn’t respond, icons that lead nowhere. None of these are obvious at a glance, but a more thorough review tends to reveal them.

Domains rarely match the real brand exactly. A slightly off spelling, an unusual extension, or a domain that has no business hosting that brand’s content is a strong signal on its own.

AI-generated assets are starting to leave their own fingerprints. As logos and pages get faked with AI tools, subtle distortions and inconsistencies are becoming one of the more reliable ways to spot a fake.

Cinchy Launches PeriMind for Trusted AI

Posted in Commentary with tags on July 23, 2026 by itnerd

Cinchy today announced the general availability of PeriMind, a new suite of AI governance solutions designed to help enterprises run AI safely, predictably and with confidence as artificial intelligence moves from pilots into business-critical operations.

The AI Trust Gap

Enterprise AI adoption is accelerating, but operational trust has not kept pace. Organizations are rapidly deploying copilots, AI agents and autonomous workflows to improve productivity, reduce costs and accelerate decision making. Yet many executives still lack visibility into where AI is being used, what systems it can access, how much it is costing the business or whether its actions align with organizational policy.

As AI becomes embedded in everyday business operations, these blind spots create new challenges. Shadow AI introduces unmanaged applications and models, AI systems consume resources without clear accountability, and security and compliance teams are expected to govern AI behavior without the operational visibility needed to understand what AI is actually doing.

The result is a growing gap between AI adoption and AI trust. 

Many enterprise AI initiatives will struggle to scale, not because the technology fails, but because organizations lack the governance, visibility and operational controls needed to deploy AI confidently in production.

Introducing AI Action Governance

Cinchy believes organizations need more than governance frameworks, policies and risk assessments. They need operational control over AI as it works across enterprise systems.

The company defines AI Action Governance as the discipline of observing, governing and enforcing policy over AI behavior in real time as AI systems access data, interact with applications and execute business actions.

PeriMind helps organizations close the AI trust gap by providing the visibility, governance and operational oversight needed to confidently scale AI across the enterprise. Rather than asking organizations to choose between innovation and control, PeriMind enables them to move faster with AI while maintaining confidence that AI systems are operating safely, responsibly and in alignment with business objectives.

Built to Help Organizations Trust AI

PeriMind is designed to help organizations:

  • Build trust in AI through operational visibility and accountability.
  • Reduce the risks associated with Shadow AI and uncontrolled AI adoption.
  • Better understand and manage the operational cost of AI across models, agents and enterprise workflows.
  • Govern how AI interacts with enterprise data and business applications.
  • Strengthen security, compliance and human oversight as AI adoption expands.

Built on a Foundation of Trusted Data Access

PeriMind is built on the same governance principles that established Cinchy as a trusted provider of enterprise data access and control solutions.

Organizations worldwide rely on Cinchy’s Data Collaboration Platform to govern how information is shared across complex enterprise environments. With PeriMind, Cinchy extends that foundation to AI, giving organizations the visibility, accountability and control needed to confidently deploy AI across enterprise data, applications and business processes. 

Organizations interested in evaluating their AI readiness, governance posture and adoption strategy can schedule a complimentary trusted AI adoption assessment with Cinchy.

To learn more, visit www.cinchy.com.

Comparitech Education Ransomware Roudup: H1 2026 stats on attacks, ransoms, and data breaches

Posted in Commentary with tags on July 23, 2026 by itnerd

Comparitech has published a new study looking at ransomware attacks against the education sector in H1 2026, finding that while overall attacks against educational institutions declined, attacks on higher education actually increased. 

Key findings include: 

  • 104 attacks in total
  • 36 confirmed attacks
  • 68 unconfirmed attacks
  • Nearly 693,000 records are known to have been breached in the confirmed attacks
  • Median ransom demand: $420,620 – up 53% from $275,000 in H2 2025
  • The ransomware strains that made the most attack claims were The Gentlemen and Qilin (15 each), LockBit (9), Interlock and Nova (6 each)
  • The Gentlemen claimed the most confirmed attacks (6), followed by Interlock (4) and Qilin and LockBit (3 each)

For full details, the research can be read here: https://www.comparitech.com/news/education-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/ 

NRCan certifies higher estimated range for 2027 Volvo EX60 P10 AWD, now up to 531 kilometres

Posted in Commentary with tags on July 23, 2026 by itnerd

Volvo Car Canada Ltd. has received Environmental Natural Resources Canada (NRCan) certification for the all-new 2027 Volvo EX60 P10 AWD with an estimated driving range of up to 531 kilometres on a single charge*, exceeding earlier estimates by the company. This marks a significant milestone as the company prepares for customer deliveries.

After its debut earlier this year and the opening of Canadian order books this spring, the EX60 positions Volvo Cars in the mid-size electric SUV segment, the largest and fastest-growing category in the electric vehicle market. The game-changing SUV offers impressive range, fast charging, and exceptional performance – all at a competitive price.

  • The EX60 P10 AWD delivers the longest electric driving range of any Volvo car sold in the Canadian market to date, transforming range anxiety into a sense of freedom.
  • The EX60 is the first vehicle built on Volvo Cars’ new SPA3 architecture, which features an 800-volt electrical system that enables the EX60 to charge quickly. For the P10 AWD variant, drivers can add up to 265 kilometres** of range in just 10 minutes, about the amount of time it takes to grab a coffee.
  • As the first Volvo car equipped with a native North American Charging Standard (NACS) port, the EX60 provides customers with seamless, adapter-free access to more than 29,000 Tesla Supercharger stations across the United States and Canada.

This NRCan certification provides customers with independently verified range performance and underscores the company’s commitment to delivering practical, long-range electric mobility without compromising safety, comfort, or Scandinavian design. 

 Electric range*  
EX60 P10 AWD (20” & 21” wheels)Up to 531 kilometres
EX60 P10 AWD (22” wheels)Up to 502 kilometres 

Customers interested in the Volvo EX60 are encouraged to contact their local retailer or visit volvocars.com/en-ca/cars/ex60-electric/.

The small print

* MY27 EX60 P10 AWD has an estimated range of up to 531 kilometres with 20″ or 21″ all-season tires and up to 502 kilometres with 22″ all-season tires. The figures are based on Natural Resources Canada (NRCan) approved test cycles. Actual range, energy consumption, and charging times will vary depending on factors such as ambient temperature, battery temperature, charging equipment, driving conditions, vehicle configuration, and battery condition. See https://fcr-ccc.nrcan-rncan.gc.ca/en for more information.

** The figures are based on Natural Resources Canada (NRCan) approved test cycles. Actual range, energy consumption, and charging times will vary depending on factors such as ambient temperature, battery temperature, charging equipment, driving conditions, vehicle configuration, and battery condition. See https://fcr-ccc.nrcan-rncan.gc.ca/en for more information. Peak charging estimates are based on the use of a DC fast charger capable of delivering up to 400 kW.

Approov names Valley vet Rex Jackson Chairman of Scottish mobile app security leader

Posted in Commentary with tags on July 23, 2026 by itnerd

Approov today announced the appointment of Rex S. Jackson as independent Chairman of its Board of Directors. Mr. Jackson succeeds Dr. Lucio Lanza, who has been recognized for his years of leadership and who will continue to serve on the Board as a non-executive director.

Mr. Jackson brings more than three decades of executive and board leadership in Silicon Valley technology companies. He has served as Chief Financial Officer and General Counsel across multiple public and private technology companies, most recently as CFO helping lead ChargePoint through its merger and public listing. He currently serves on the board of Terra Innovatum (Nasdaq: NKLR), where he chairs the audit committee and serves on the compensation committees. Mr. Jackson holds a J.D. from Stanford Law School and a B.A. from Duke University.

The company also paid tribute to Dr. Lanza’s tenure. A legendary figure in semiconductor and electronic design automation investing, Dr. Lanza backed Approov’s vision early and has chaired its Board through years of sustained growth, championing the company’s pioneering work in cloud-based cryptographic mobile app attestation.

The appointment was approved unanimously by Approov’s Board and shareholders, including investors Maven Capital Partners, Lanza Tech Ventures and Scottish Enterprise.

Other World Computing (OWC) Announces OWC Express 4M2 Ultra 

Posted in Commentary with tags on July 23, 2026 by itnerd

Other World Computing today announced the launch of its OWC Express 4M2 Ultra, the fastest compact ready-to-run ThunderboltTM 5 NVMe RAID solution, in 4TB, 8TB, 16TB, and 32TB capacities. 

The OWC Express 4M2 Ultra combines everything creative professionals need in one high-performance desktop RAID solution – massive all-flash NVMe storage capacity, flexible RAID configuration, and the dramatically improved workflow efficiency of Thunderbolt 5 bandwidth. Built for demanding creative pipelines, it delivers up to 6622MB/s performance that turns massive 12K RAW video files, 8K multi-cam sequences, and monster photo libraries into effortless workflows. From backing up media cards on set to working through intense VFX compositing in post, the OWC Express 4M2 Ultra delivers the speed, capacity, and reliability to keep projects humming from capture to final delivery. 

OWC Express 4M2 Ultra features: 

  • Blazing Speed – 6622MB/s for 12K RAW video and 8K multi-cam workflows
  • Small Yet Scalable – 32TB per unit, expandable to 128TB via daisy chaining
  • More Connectivity – Second Thunderbolt 5 port connects five more devices
  • Future-Ready – Upgrade to faster, larger NVMe SSDs anytime

The OWC Express 4M2 Ultra NVMe SSD Solutions are now generally available (GA) and priced as follows: 

  • 4TB – $2,399.99
  • 8TB – $3,799.99
  • 16TB – $5,579.99 
  • 32TB – $10,299.99

To learn more and purchase the OWC Express 4M2 Ultra NVMe SSD Solutions, please visit:

France Recorded Over 145 Million Data Exposures in Two Years as Dark Web Activity Targeting the Country Quadrupled

Posted in Commentary with tags on July 23, 2026 by itnerd

France-linked underground cyber activity has increased more than fourfold over the past two years, with stolen credentials, personal data, ransomware advisories and hacktivist claims rising sharply across dark web forums and cybercriminal channels.

Monthly activity climbed from fewer than 300 items in mid-2024 to more than 1,400 at its peak in January 2026. It remained above 1,000 items per month through spring 2026, pointing to a sustained expansion of the underground market for French data rather than a short-lived spike caused by a single breach.

These findings are part of a new CloudSEK report, France Cyber Threat Outlook: Dark Web, Ransomware, and Hacktivism Trends,” which analysed approximately 17,800 France-related threat intelligence items recorded over 24 months.

The report shows that stolen credentials and infostealer logs account for a significant share of the increase, while government organisations, financial services, technology companies and telecom providers remain among the most exposed sectors.

It also highlights a parallel rise in ransomware activity targeting smaller organisations and municipalities, alongside sustained pro-Russian hacktivist campaigns against French ministries, aviation entities, drone manufacturers and other policy-linked organisations.

Stolen credentials are driving the underground market

The increase is being fuelled primarily by the mass harvesting and circulation of passwords, authentication data and personal information, rather than only by large corporate breaches.

The research identified:

  • 4,447 account credential exposures
  • 4,360 credential collections
  • 4,011 combined datasets
  • 3,565 breached-record listings
  • 977 authentication-token exposures

This pattern reflects the growing use of infostealer malware, which extracts credentials, browser data, cookies and authentication tokens from infected systems. The stolen information is then packaged into combolists, sold on underground forums or distributed freely to support fraud and account takeover. 

CloudSEK researchers found that this low-cost, high-volume model is making stolen access easier to acquire and reuse across multiple platforms.

French personal data is being traded at low cost

In one case, approximately two million records allegedly belonging to French women were advertised for $399. In another, nearly 489,000 French records were distributed through a forum-based access mechanism rather than offered through a conventional sale.

The research also identified fabricated databases advertised in the names of trusted French institutions, including ANTS, the national secure-documents agency, and CPAM, the national health insurance system.

Such activity can enable phishing, impersonation and fraud even when the institution named in the listing has not suffered a confirmed breach.

Government organisations face the highest exposure

CloudSEK research shows that government recorded the highest level of France-related exposure over the two years, with 1,652 items.

It was followed by:

  • Financial services: 1,594
  • Technology: 1,491
  • Telecommunications: 1,480
  • Email-related exposure: 1,427
  • Retail: 1,197
  • E-commerce: 1,089

The prominence of government reflects a combination of leaked credentials, ransomware pressure on municipalities and politically motivated targeting of ministries and public agencies. 

Ransomware pressure is concentrated on smaller organisations

The research recorded 213 France-tagged ransomware advisories over the past six months. Some victims were posted more than once, meaning the total should not be interpreted as the number of unique organisations attacked.

Even after accounting for repeated listings, the data shows that municipalities and smaller organisations remain recurring targets, particularly where security teams and incident-response capabilities are limited.

Groups including Qilin and MedusaLocker were linked to claims involving French local authorities. Repeated listings of the same victim suggest that ransomware operators may use staged disclosures to prolong pressure during extortion attempts.

Pro-Russian hacktivism adds a geopolitical threat

The report identified 742 France-related hacktivism items over six months, with the activity dominated by the pro-Russian group NoName057(16). 

The group claimed distributed denial-of-service attacks and unauthorized access involving French ministries, civil aviation bodies, drone manufacturers and private organisations.

Several of these campaigns were explicitly framed as retaliation for France’s support for Ukraine and its position on sanctions against Russia.

CloudSEK assesses that this activity represents a continuing operational risk for organisations associated with government, defence, aerospace and public policy, rather than an isolated wave of disruption.

Regulatory consequences are becoming more serious

The rise in underground cyber activity is taking place alongside stricter enforcement of data-protection and security obligations in France. Recent CNIL actions have focused on failures such as inadequate authentication, excessive access permissions and insufficient protection of personal data.

These weaknesses closely mirror the patterns identified in the report, particularly credential exposure, weak access controls and third-party risk.

For affected organisations, the impact of a breach can therefore extend beyond operational disruption to include regulatory penalties, mandatory remediation and reputational damage.

Shark robot vacuum flaw exposes fleet-wide IoT risks

Posted in Commentary with tags on July 22, 2026 by itnerd

Security researcher “tokay0” recently published a serious vulnerability affecting Shark robot vacuums. A certificate extracted from one compromised Shark robot vacuum could be used to access other devices, exposing live camera feeds, stored home maps and Wi-Fi credentials held in plaintext. During a 24-hour observation, the researcher identified more than 1.5 million Shark serial numbers in one AWS region, with approximately 674,000 devices responding to a command probe.

Edwin Shuttleworth, Lead Penetration Tester and Security Researcher at Finite State, offered the following comments:

   “This is a classic authentication-versus-authorization failure. The certificate issued to each device correctly authenticated the holder of that device’s private key. An attacker who had fully compromised a vacuum could extract the key and authenticate as that legitimate device. The cloud backend, however, did not correctly enforce authorization. As a result, a validly authenticated device was permitted to access data and perform actions involving other devices it should not have been able to reach.

   “This is a common security design mistake: treating a successfully authenticated identity as broadly trusted instead of applying narrowly scoped, per-device permissions. Security professionals reviewing IoT systems should verify both that device identities are unique and that each identity is restricted to its own resources and required operations.

   “Manufacturers must assess the complete connected-product environment because the most serious vulnerabilities often arise from interactions between multiple layers rather than a single isolated flaw. This case illustrates that clearly. Weaknesses in the device’s boot and debug protections allowed an attacker to obtain privileged access to the vacuum and extract its credentials. Those credentials were then accepted by the cloud service and granted access to MQTT resources belonging to other devices. Finally, dangerous command-handling functionality allowed cloud-delivered messages to result in remote code     execution.

   “Individually, each weakness might have appeared limited. Together, they created an attack chain that turned the compromise of one physical device into a potential fleet-scale compromise. Testing firmware, cloud permissions, credential storage or backend infrastructure only in isolation could therefore miss the true severity of the vulnerability.

   “Manufacturers should avoid storing sensitive information that is not necessary for the device’s function or business operations and should avoid transmitting sensitive information to the cloud when it is not needed. When information must be transmitted, robust encryption should be used to prevent access by unauthorized parties. Security testing must also be performed early and regularly to prevent compromises like this and minimize their impact when they occur.”

This is precisely why I am working towards making all of my IoT gear, of which I don’t have a lot, not talk to the Internet. My concern is that I don’t know who they are talking to. That is a huge problem as evidenced by this report.

95% of security teams are finding critical vulnerabilities their scheduled tests missed

Posted in Commentary with tags on July 22, 2026 by itnerd

Synack recently released a new survey of enterprise security teams and found that 95% discovered a high or critical vulnerability outside their scheduled testing window in the past year, with 42% saying it happens at least monthly, no breach required to expose the gap, no dramatic incident, just the ordinary rhythm of scheduled testing failing to keep pace with how fast environments actually change.

You can read the press release here: New Synack Research: The State of Continuous Security Validation

Brian Proctor, Founder and CEO, Frenos

“Finding critical vulnerabilities outside scheduled tests is the new norm. AI has pushed time-to-exploit toward zero, and no security team can continuously run live exploitation without breaking things. Nowhere is that more true than in OT and critical infrastructure, where live testing is a non-starter. Simulation against a digital twin of the environment is the only path to continuous, high-confidence validation of what’s actually exploitable. The real red flag in this data isn’t the 95%; it’s that only 15% of organizations are validating continuously.”

If you’re not testing, or testing frequently enough, then you aren’t protected. It is that simple. I would strongly recommend that all organizations increase their testing as part of their broader plan to stay secure.

OpenAI confirms Hugging Face breached by rogue AI Agent 

Posted in Commentary with tags on July 22, 2026 by itnerd

OpenAI has disclosed that one of its frontier systems autonomously escaped a testing environment and compromised Hugging Face. This is the first public demonstration that frontier AI can execute a complex, end-to-end cyberattack across multiple environments with minimal human intervention.

CBC News has some details: OpenAI model went rogue, hacked another company’s system during testing | CBC News

The ChatGPT creator was testing capabilities of some of its most advanced models in a controlled environment, but the agent escaped containment, reached the internet and broke into Hugging Face to satisfy its testing goal.

The incident signals how AI’s expanding capabilities are already fuelling fears about security and that even top developers can ​be caught off-guard by flaws their models can exploit.


Sonali Shah, CEO, Cobalt had this to say:

“This was inevitable. Every security leader has understood for some time that AI would eventually move beyond automating individual attack tasks to autonomously executing an entire attack lifecycle. This is the first public demonstration of that happening across multiple environments. The lesson for defenders is that the window between vulnerability discovery and exploitation is collapsing even further. Organizations should assume attackers will increasingly operate at machine speed, which means security testing, exposure management and remediation also have to operate at machine speed.

The attack techniques are not new. We’ve had tools capable of chaining attacks for over a decade. What’s different is that AI is removing many of the human validation steps that previously governed how those tools were used. That makes strong guardrails and human oversight more important than ever.

What escaped here was an autonomous offensive capability operating toward an objective. One analogy to illustrate this is giving an exceptionally skilled penetration tester unlimited patience, unlimited time and the ability to execute thousands of attack steps every minute. The concern is that the agent remained relentlessly focused on its objective and discovered attack paths humans hadn’t anticipated. That’s fundamentally an engineering, governance and containment challenge, not evidence of malicious intent. As organizations adopt increasingly autonomous AI systems, they need the same validation controls we’ve relied on for years in offensive security. Human oversight can’t disappear simply because AI can execute faster.

The biggest takeaway is that defenders increasingly need AI capabilities comparable to the attackers they’re facing. Historically, every organization could buy roughly the same security tooling. We’re now entering an era where the quality of your defensive AI may directly determine how quickly you understand, contain and remediate an attack. Perhaps the more significant lesson is that incident response can’t depend entirely on cloud-hosted AI services whose safety guardrails may prevent effective forensic analysis during a crisis.

Organizations should have vetted AI models they can operate inside their own trust boundary before an incident happens. That said, better models alone aren’t enough. AI for cybersecurity is still maturing, and organizations shouldn’t blindly trust autonomous systems. Every security leader wants the speed and scale AI delivers, but they also want humans to retain accountability for validating targets, approving attack paths and verifying results. You need both AI and humans.”

The genie is now out of the bottle. You can fully expect that AI will be used to attack you. So you should plan accordingly.