From a Japanese cloud outage to Gorton’s parent company: the hidden supply chain risk for U.S. firms

Posted in Commentary with tags on October 9, 2026 by itnerd

A ransomware attack against a SoftBank-owned cloud provider in Japan has affected 495 companies and local governments, and the impact is expanding beyond the original infrastructure outage.

JR East has now disclosed approximately 6.09 million potentially exposed customer records across its group. Nissui, which operates major U.S. seafood businesses including Gorton’s, has confirmed disruptions to its Japanese logistics subsidiary. No direct U.S. disruption has been established.

The next development to watch is which additional customers disclose incidents as investigations continue.

John Watters, Founder & CEO, iCOUNTER | Former President & COO, Mandiant Said This:

“One ransomware attack against a cloud provider in Japan has put 495 companies and local governments at risk, with JR East already reporting approximately 6.09 million potentially exposed customer records. And this story is far from over. As more organizations investigate their exposure, we should expect additional disclosures that reveal just how far a single attack can reach.

This isn’t just a Japan problem. It’s a warning to American businesses about the dependencies hiding inside their supply chains. Nissui, one of the affected organizations, has significant U.S. operations, illustrating how interconnected these ecosystems have become, even though no impact on its American operations has been confirmed.

What concerns me most is that many organizations won’t know they’re exposed until a vendor tells them. By then, critical decisions about data protection, business continuity, and recovery may already be overdue.

Every CISO should be asking three questions right now: Which of our vendors and their suppliers depend on the affected infrastructure? Is our data exposed? And what is our response plan if those services go down?

Traditional third-party risk assessments tell you whether a vendor met security requirements at a point in time. They don’t tell you when that vendor, or a supplier behind it, is actively under attack.

The next breach notification shouldn’t be the first time you discover your organization was at risk. Security teams need to identify threats across their extended ecosystem, determine what matters to their business, and act before a supplier’s incident becomes their own.”

With everything being interdependent on everything else, you’re only as secure as the guy next to you. Thus need to make sure that the guy next to you is secure to your standards and not theirs.

Midnight Mimosa malware in Android firmware with system level privileges

Posted in Commentary with tags on October 8, 2026 by itnerd

Bitdefender found Midnight Mimosa malware preinstalled in the firmware of thousands of inexpensive Android phones being sold across 150+ countries. Researchers  said: “The malware ships preinstalled in the device firmware, and (was) found multiple system packages involved, depending on the device. It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled.

“The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets. This scheme is likely designed mainly to generate revenue,” the reviewers said. 

Western Europe and the Americas are “centers of gravity” for the infected devices.


Ted Miracco, CEO, Approov:

The uncomfortable takeaway from Midnight Mimosa is that you can’t assess an app’s security in isolation from the environment it runs in.

If malware is embedded in firmware before a phone even reaches the customer, trust is undermined before the first login. The user didn’t have to download a malicious APK. The app didn’t necessarily do anything wrong. The underlying device was already compromised.

For organizations protecting mobile APIs, this raises a bigger question: Should a successful login be enough to trust a mobile request?

The answer is no. Authentication verifies user credentials; it does not establish the integrity of the app or device making the request. App attestation and runtime integrity signals provide additional evidence that should inform API access decisions.

Crucially, those decisions should be enforced outside the potentially compromised device, using remotely evaluated integrity checks and backend verification.

When compromise occurs below the application layer, app and device integrity need to become part of the API security decision—not assumptions sitting underneath it.

Roland Lindsey, Lead Solutions Engineer, Finite State:

“This is why there is no substitute for binary analysis on the shipping firmware.  Source trees and build processes are aspirational.  If you aren’t looking at what ships to the customer, you are running blind.”

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

“This is a serious supply chain security issue because these devices are potentially compromised before consumers ever turn them on. When malware is embedded in firmware, traditional security tools may have limited visibility, and consumers have little chance of identifying or removing the threat.

“One of the biggest blind spots is the lack of oversight into third-party firmware, preinstalled applications, and software components supplied by outside vendors. Manufacturers need to take responsibility for the entire software supply chain, not just the components they develop themselves.

“Firmware integrity checks, cryptographic signing, secure boot, and independent security testing should be standard practices before devices ship. Security needs to start at manufacturing, not after a compromised device reaches the consumer.”

This is a serious problem as there are millions of Android phones out there and a lot of them are on the cheaper side. This may make people decide to go more upscale if they want a phone that doesn’t have unwanted guests.

Hacker uses AI-powered attack tools to breach South Korean banks 

Posted in Commentary with tags , on October 8, 2026 by itnerd

A suspected Chinese-speaking hacker used AI-powered penetration testing tools to target South Korean financial institutions in a campaign that resulted in stolen data, according to new CrowdStrike research.

The activity occurred from late September through early October 2026, although the total number of affected organizations remains unconfirmed, at least five lenders affected include Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank

The attacker used ARTEX, an open-source agentic penetration testing tool developed in China, alongside several LLMs. CrowdStrike identified exposed attacker-controlled directories containing Claude Code session histories, ARTEX configuration files and AI memory files. The ARTEX deployment used DeepSeek v4.1-flash as its primary model, while additional sessions involved GLM-5.3 and Grok 4.6.

According to reports examined by CrowdStrike, one affected bank’s loan inquiry service used by financial brokers was breached, while another bank’s employee mobile work-support system was compromised.

The recovered AI conversations also showed the attacker asking Claude where stolen Korean data could be sold and seeking assistance locating Telegram groups involved in data sales.

ㅤRyan McCurdy, VP of Marketing, Liquibase:

“AI is changing the economics of cyberattacks. Tools that once required considerable expertise can now be combined with AI agents that help attackers find weaknesses, test approaches, and operate across multiple targets.

“ That has significant implications for companies running open-source software. Vulnerabilities aren’t new, but the time between discovering one and exploiting it could get much shorter as these capabilities improve.

“Enterprises need to reconsider how they manage that exposure. It’s no longer enough to know that a vulnerability exists or that a patch is available. You need to know where you’re exposed, who owns remediation, and how quickly you can safely deploy a fix.

“Open source isn’t inherently less secure. But as AI accelerates offensive capabilities, relying on community-driven remediation without clear ownership, support commitments, or a tested response process becomes a much harder risk to justify.”

ㅤOpen source anything isn’t going to keep costs down. At least not if you think that you don’t have to follow proper security standards.

Over 8,500 European wind, solar systems publicly exposed

Posted in Commentary with tags on October 8, 2026 by itnerd

Researchers from the Dutch National Cyber Security Centre (NCSC-NL) and cybersecurity company Modat identified 8,547 internet-exposed systems across European wind farms and solar parks, including administrative interfaces and operational control panels that should not be publicly accessible, according to new research.

The researchers examined renewable energy facilities across 40 European countries and identified exposed systems in 35. Of those, 7,942 were associated with solar installations across 34 countries, while 605 were linked to wind farms across 23 countries.

Some exposed interfaces displayed live electricity production data, turbine locations and operational controls labeled Start, Stop and Reset.

Researchers estimated that approximately 181 sites could potentially allow full operational control. Other exposed pages included administrative login screens, with one displaying the default username “root.” Some interfaces could manage multiple turbines or an entire wind farm.

The researchers said the 8,547 figure is likely an undercount because only systems confidently associated with specific facilities were included.

ㅤDamon Small, Board of Directors, Xcape, Inc.:

“Unauthenticated, Internet-exposed interfaces on critical infrastructure threaten regional grid resilience and create operational, legal, and reputational risk across renewable energy portfolios. The discovery of over 8,500 exposed European wind and solar management endpoints, including over 180 permitting full operational intervention, highlights fundamental identity and network perimeter failures. While remote access to operational technology (OT) systems is a clear operational requirement, it must be delivered securely through zero-trust access, network segmentation, and multi-factor authentication rather than exposing control panels directly to the public Internet. To prevent these foolish architectural decisions, organizations must conduct mandatory threat models and architecture reviews before production systems go live, while immediately pulling existing interfaces behind secure gateways and enforcing credential rotation.”

Critical Takeaways

  • Publicly exposing OT control interfaces directly to the Internet turns standard management features into severe grid resilience vulnerabilities.
  • Remote access is a valid operational requirement, but it must be mediated via zero-trust architecture, multi-factor authentication, and secure gateways.
  • Formal architecture reviews and threat modeling must occur prior to live deployment to catch perimeter and identity flaws early.

Threat modeling before deployment costs a fraction of what an incident responder will charge to explain why “root” was still the password.

ㅤ

Steven Swift, Managing Director, Suzu Labs:

“This isn’t an AI problem, even if the authors of the research claim that “AI made things a little faster” We’ve seen decades of organizations putting resources directly onto the public internet with minimal to no protections in place, and then act surprised when its found and exploited.

“There’s already a rich well developed industry of mapping the entire attack surface of literally every single public IP. This isn’t new, and it doesn’t depend on AI. If you put a resource on the internet, existing (non-ai) automation will find it, document it, and put it into a database for easy access by others.

“For this research specifically, there’s a mix of single devices and management interfaces for groups of devices. That said, much of the wind and solar infrastructure is decentralized. So while 8,500 devices being directly exposed to the internet is a lot, if a threat actor wanted to cause harm, they would be limited to a subset of these at a time.

“That’s still a problem. Power is part of critical infrastructure. People want their power to keep working, and not to have an outage because someone decided to hack in. If an attacker wanted to cause harm, rather than simply turning power generation off they could tamper with the working configuration. If the system can be misconfigured to intentionally overload for example, permanent damage could result.

“This is an example where security best practices are completely basic, yet still not being followed. Literally just don’t have equipment directly exposed to the internet. Having remote access to systems is fine, but it needs to be secure. Putting equipment behind a secure VPN for example is only minimally more complex to setup, and orders of magnitude more secure.”

ㅤThreat actors will always target stuff like this because they can pwn it easily. Thus your job is to not be the guy who gets pwned.

ASOS Confirms That They Were Pwned

Posted in Commentary with tags on October 8, 2026 by itnerd

ASOS confirmed Thursday that its investigation found customer names and contact details had been accessed from a cybersecurity breach earlier this week. This differs from most hacks that I see as the threat actors used a trusted communication channel to communicate with the outside world. This takes away any doubt that they got in and ASOS got pwned.

More info here: https://www.reuters.com/business/retail-consumer/uks-asos-says-breach-exposed-some-customer-personal-data-2026-10-08/?utm_source=chatgpt.com

Danny Jenkins, CEO and Co-Founder of ThreatLocker, provided the following comments:

“Organizations must stop treating legitimate employee credentials as a trusted key to the kingdom. If an attacker can trick an employee into giving them valid credentials, the question isn’t whether that employee should have been more careful. It’s why those credentials alone are enough to compromise an entire organization. Zero Trust defenses are designed to add hardware verification to authorization checks. In this case, had a device needed to be verified, stolen credentials may have been useless to the attacker if they weren’t using them from an approved device.”

Jason Brown, Director of Customer Advisory, Counter Fraud Lead, iCOUNTER

“The ASOS breach started with one employee who was tricked into handing over their login by someone impersonating a trusted contact. From there, the attacker reached the third-party platforms ASOS uses to talk to its customers. That’s the part security teams should focus on. Every marketing, messaging and customer data platform a company connects to becomes another route to its customers, and in this case the attacker used ASOS’s own push notification channel to announce the breach directly to shoppers. The same access that sent a ‘HACKED’ message could just as easily have sent a convincing phishing message from a brand customers already trust, which is why anyone who received that notification should be on alert for follow-up scams. The attackers’ claim that they compromised ASOS’s Snowflake instance hasn’t been confirmed, and Snowflake says its platform wasn’t compromised. But the broader point holds. AI marketing tools are often given wide access to customer data so they can personalize campaigns, and that makes them valuable targets. Companies need an inventory of every third-party platform that holds or can reach their customer data, clear limits on what each one can access, and strong authentication on the employee accounts that manage them. Organizations that work with retailers like ASOS should also treat any data those partners hold on them as potentially exposed until they hear otherwise. Threat intelligence that watches for impersonation campaigns against your employees and partners, and for your vendors’ names showing up in breach claims, gives you a chance to act before an attacker uses your own channels against your customers.”

Well at least they knew how they got in. The real question is what are they going to do about it? Better training? Passwordless solutions? It all has to be on the table.

Harness Acquires Augment Code, Advancing the Autonomous SDLC from Idea to Production

Posted in Commentary with tags on October 8, 2026 by itnerd

Harness today announced that it has acquired select Augment Code assets, including Cosmos and the Auggie CLI products, the Code Context Engine, and related technology. The team behind these products will join Harness, accelerating its work to make the entire software development lifecycle increasingly autonomous.

Cosmos will become Harness Cosmos Software Factory Agent, with a clear role: automate engineering work from idea to code. From there, Harness’s existing agents for software delivery, security testing, runtime protection, and cost management take over, carrying the work into production and operations, creating a seamless agent to agent experience.

Connecting Augment’s Code Context Engine with Harness’s Software Delivery Knowledge Graph provides insights across the full SDLC – what’s being built, and what happens to it once it ships. Harness is bringing codebase understanding together with delivery context, so Harness Cosmos can make better-informed changes upfront, and Harness agents can use downstream findings to correct and verify them.

Introducing the Harness Cosmos Software Factory Agent

Harness Cosmos takes engineering work from idea to merge-ready code. When a requirement is written, a ticket is assigned, or a bug is reported, a fleet of Cosmos agents plans the change, writes the code and tests, and opens a pull request. Each agent works in its own isolated VM and pulls in an engineer only where judgment is needed, like approving a design or making the final merge.

Cosmos agents run as a continuous loop through ticket, code, and review. When a reviewer comments or a check fails, an agent fixes the issue on the same pull request. Teams can fork prebuilt Experts like Project Builder, PR Author, Deep Reviewer, and PR Fixer, tune each one to their own codebase, and deploy it organization-wide.

Augment’s Code Context Engine keeps a live map of the codebase, so changes fit the code already there. Model routing matches each task to the right model, and built-in integrations connect to GitHub, Jira, and Slack. Shared memory carries lessons from each review into the next change, and versioning and budget controls let teams run autonomous coding across the entire engineering organization.

What leaves the factory is a reviewed pull request, ready for Harness agents to test, secure, and deploy.

Shared context from code to production

Harness’s Software Delivery Knowledge Graph connects delivery and operational information, including builds, deployments, infrastructure, security, and costs. Augment’s Code Context Engine brings that same specificity to the code itself.

Before a change is written, Harness Cosmos will pull together the delivery context that should shape it: test cases, security requirements, past incidents and their remediations. Once that change exists, Harness’s downstream agents will use codebase context to reason about dependencies, risk, and what validation it needs. If something fails, the agents can loop until resolution.

Extending the Harness Autonomous SDLC Platform

Harness Cosmos joins the Harness platform, automating engineering work from idea to code. No matter how that code is written, the Harness platform already takes it the rest of the way:

The integration vision focuses on connecting Harness Cosmos workflows with the policies, permissions, and approvals that already govern the Harness platform, bringing the same discipline to creating a change that enterprises already expect when releasing one.

Availability

Harness Cosmos is now available. To learn more, read the announcement blog post, visit the website, or get started now.

Airrived Named a Cool Vendor in the 2026 Gartner® Coolest Vendor Innovations in Agentic AI Security

Posted in Commentary with tags on October 8, 2026 by itnerd

Airrived has been named a Cool Vendor in the Gartner Coolest Vendor Innovations in Agentic AI Security report published on October 2, 2026.

Airrived turns business users into AI experts.

Airrived is an enterprise-grade Agentic OS and Sovereign AI Platform that lets business and domain experts build, deploy, and govern autonomous AI — without becoming AI engineers.

Users bring the domain expertise. Airrived brings the reasoning, enterprise context, orchestration, governance, and infrastructure needed to turn that expertise into autonomous systems capable of reasoning, collaborating, deciding, and acting.

Unlike copilots, which mainly assist users, or developer frameworks, which require teams to engineer agents from scratch, Airrived lets enterprises automate complex, multi-step work across cybersecurity, IT, and business operations.

The platform combines deep reasoning, Agentic Mesh, Context Lake, multi-agent orchestration, governance, and end-to-end Agentic Observability — plus pre-built agents and applications that dramatically shorten the path from AI experimentation to production.

Built for the Sovereign AI Enterprise.

Airrived gives enterprises full control over where and how their AI runs. It can be deployed in the cloud, in customer VPCs, on-premises, on private GPU infrastructure, or in fully air-gapped environments — keeping data, models, agents, context, and AI operations under customer control at all times.

That removes a major barrier to enterprise AI adoption: organizations can put autonomous AI directly into the hands of the people who understand the business, without requiring them to master the underlying technology.

With adoption across Fortune 150 enterprises and organizations worldwide, this recognition follows a string of major product advancements from Airrived — including Agentic Observability and Sovereign Agentic AI — as the company continues advancing its vision for governed, autonomous AI across the enterprise.

Gartner subscribers can access the report here: https://www.gartner.com/document-reader/document/8461845?ref=TypeAheadSearch

*Source: Gartner Report, Coolest Vendor Innovations in Agentic AI Security, by AI and Cybersecurity Insights Team, 2, October 2026. Gartner is a trademark of Gartner, Inc. and/or its affiliates.

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

Beyond Another Gadget: Holiday Gifts from Epson that Create, Preserve and Share Memories

Posted in Commentary with tags on October 8, 2026 by itnerd

Society is going through a digital reset. After years of delighting in our devices, the pendulum is swinging back toward the physical. From the resurgence of printed photos, scrapbooking and journaling to growing concerns about screen time in schools and at home, consumers are rediscovering the value of putting something tangible in their hands — making printers more relevant than ever for busy families, memory-keepers, creative hobbyists and work-from-home professionals.

And with select models on sale during Black Friday and throughout December, now is the time to get a head start on the holidays.

The Epson EcoTank ET-2980 Wireless All-in-One Colour Supertank Printer (MSRP: $399.99 CAD)   A practical gift for busy households, the ET-2980 takes the stress out of everyday printing. Featuring wireless mobile printing, families on the go can conveniently print and scan from a smartphone . This model can print thousands of pages in colour without the hassle or cost of frequent ink replacements, making it ideal for everything from school projects and schedules to holiday cards and year-end paperwork.  
EcoTank ET-4950 Wireless All-in-One Colour Supertank Printer (MSRP: $599.99 CAD) A thoughtful gift for the work-from-home warrior, the ET-4950 helps create a more efficient workspace. Its cartridge-free ink system includes enough ink to last up to three years, while productivity-focused features like automatic two-sided printing, copying and scanning make it easy to stay organized and productive year-round.
The EcoTank Photo ET-8550 All-in-One Wide-format Supertank Printer (MSRP: $1099.99) Epson’s best-selling photo printer in Canada, the ET-8550 is the perfect gift for creatives and photography enthusiasts. Designed to produce stunning, lab-quality photos, it can print wide-format borderless images up to 13″ x 19″, making it easy to transform favourite moments into statement pieces for any home.
The Epson Expression Photo XP-8800 (MSRP: $299.99) As Canadians rediscover the joy of printed photographs and personalized keepsakes, the XP-8800 makes a thoughtful and budget-friendly gift for memory-makers and DIY hobbyists alike. Built to bring the best memories off-screen and into the real world, this photo printer can create vibrant 4″ x 6″ photos in as little as 10 seconds, helping transform forgotten digitals into cherished displays.
The Epson Lifestudio Pop Plus Projector (MSRP: $1,049.99) The gift of quality time never goes out of style.With built-in Google TV™ and access to more than 10,000 streaming apps, the Lifestudio Pop Plus Projector makes it easy to bring friends and family together for holiday movie marathons, family game nights and summer backyard screenings. Its sleek, compact design fits seamlessly into the home while turning virtually any room or backyard into a premium entertainment venue, creating memorable moments long after the holiday season ends.
The Epson Lifestudio Flex Plus Projector (MSRP: $1,299.99) Give the gift of a bigger, more immersive entertainment experience with the Lifestudio Flex Plus Projector. From blockbuster movie nights and championship games to gaming sessions with friends, its stunning 4K PRO-UHD® picture, Sound by Bose technology and display of up to 150 inches transform everyday viewing into something extraordinary. Featuring a versatile adjustable stand that projects vivid images on nearly any flat surface, it turns almost any space into a personal theatre, sports bar or gaming arena. 
Epson FastFoto FF-680W Wireless High-speed Photo Scanning System (MSRP: $849.99) As more Canadians look for ways to preserve meaningful memories, the FF-680W offers a unique gift for the family storyteller. It quickly digitizes cherished photographs, helping protect decades of memories from fading, damage and photo overload. Paired with the Epson FastFoto app, users can organize their collections, add voice and text to photos and create slideshows to share family stories with loved ones for years to come.

September 2026 Cyber Threat Landscape: Global Attacks Jump 48% as Phishing and GenAI Data Exposure Rise

Posted in Commentary with tags on October 8, 2026 by itnerd

Key takeaways

  • Organizations experienced 2,803 weekly cyber attacks on average in September, up 16% month over month and 48% year over year.
  • Education remained the most targeted sector, averaging 6,656 weekly attacks per organization, a 59% year-over-year increase.
  • Europe recorded the sharpest regional rise at 61% year over year, while Latin America faced the highest volume at 3,813 weekly attacks per organization.
  • One in every 39 enterprise GenAI prompts posed a high risk of sensitive data leakage, affecting 89% of organizations that regularly use GenAI tools.
  • One in every 91 emails was classified as phishing, up from 1 in 112 in August; 81% of phishing emails contained links.
  • A total of 824 ransomware attacks were reported, 53% more than in September 2025.

September’s data shows cyber pressure rising across multiple fronts. Weekly attack volumes increased sharply, phishing became more prevalent, GenAI use continued to expand alongside sensitive-data exposure, and ransomware remained well above last year’s level. Together, these findings reinforce Check Point’s prevention-first view: organizations need AI-powered security, consistent visibility and shared intelligence across the full attack surface to reduce risk before it becomes business impact.

Global Cyber Attacks Accelerate

Organizations experienced an average of 2,803 cyber attacks per week in September 2026. That represents a 16% increase from August and a 48% increase compared with September 2025. The longer trend is equally significant: weekly attacks per organization rose from 2,055 in May to 2,803 in September, an increase of 36% over five months.

This sustained growth points to more than an isolated monthly spike, making resilience, exposure reduction and prevention increasingly important across networks, cloud, endpoints, email and AI services.

Education Faces the Highest Attack Volume

 Education remained the most targeted industry in September, averaging 6,656 weekly attacks per organization, up 59% year over year. Attacks also rose 24% from August—the second-highest monthly growth across industries— and surpassing the previous steepest monthly increase for this sector seen in September 2024. The increase coincided with the start of the academic year, when students, faculty, parents and other users reconnect to institutional networks.

Telecommunications ranked second with 3,483 weekly attacks per organization, up 29% year over year, followed by Government with 3,443, up 37%. The figures show sustained pressure on sectors with broad user bases, essential services and complex digital environments.

Latin America Leads in Volume as Europe Records the Sharpest Increase

Latin America recorded the highest regional attack volume in September, averaging 3,813 weekly attacks per organization, up 35% year over year. Africa ranked second at 3,701 weekly attacks, followed by APAC at 3,593. Europe experienced the highest rate of growth, with attacks increasing 61% compared with September 2025. North America also rose sharply, up 50% year over year. Although Europe’s overall volume remains lower than that of the leading regions, it recorded the fastest growth of any region, signaling a rapidly intensifying threat environment for organizations there.

GenAI Risk Expands Alongside Enterprise Use

In September, 1 in every 39 enterprise GenAI prompts posed a high risk of sensitive data leakage, affecting 89% of organizations that regularly use GenAI tools. A further 14% of prompts contained potentially sensitive information, making prompt-based data exposure a mainstream governance concern. The average user generated 131 GenAI prompts during the month, a significant increase from August, while each organization used an average of eight tools. Rising prompt volumes and a broader toolset make it increasingly important to understand what information employees share, where it is processed and which controls apply.

Latin America recorded the highest regional rate of high-risk prompts at 1 in 25, or 4%, above the global average of 2.5%. North America followed at 1 in 37 prompts, APAC at 1 in 48 and Europe at 1 in 57. These ratios put the risk into practical terms: the lower the number, the more often employees are entering information that could expose sensitive data.

By industry, Business Services had the highest high-risk exposure rate at 4.9%, or 1 in every 20 prompts, moving up two places from August. Financial Services followed at 4.1%, or 1 in 25 prompts, with Healthcare & Medical at 3.5%, or 1 in 29. These sectors routinely handle client, financial and patient information, which helps explain why everyday use of GenAI tools can carry a greater risk of sensitive data exposure.

Sensitive Data Exposure Spans Core Business Information

Network and IT Infrastructure was the most common sensitive-data category, observed in GenAI prompts at 71% of organizations. Financial Data followed at 70%, Legal and Regulatory data at 68%, Employee and HR data at 62%, and personally identifiable information at 60%. These percentages reflect the share of organizations where each category was observed, not the share of prompts. The leading category includes information such as hardware and network configurations and IP addresses—details that could give attackers valuable insight into an organization’s internal environment if exposed.

Email Phishing Risk Increases

One in every 91 emails, or 1.1%, was classified as phishing in September, up from 1 in 112, or 0.89%, in August. Among phishing emails, 81% contained links and 11% contained attachments, confirming malicious links as the primary delivery method. Others relied on social engineering without either. In practical terms, phishing emails reached inboxes more frequently than in August, and the heavy reliance on links underlines the importance of checking URLs before users click.

North America recorded the highest regional phishing rate, with 1 in 79 emails, or 1.26%, classified as malicious.

By industry, Associations & Nonprofits had the highest rate at 2.17%, or 1 in 46 emails, twice the global average. Construction & Engineering followed at 2.05%, or 1 in 49 emails, and Real Estate, Rentals & Leasing at 1.38%, or 1 in 72. For Associations & Nonprofits, this means employees were exposed to phishing at roughly double the typical frequency.

Ransomware Remains Elevated Year over Year

* Ransomware data is drawn from double-extortion groups’ public “shame sites.” Although these sources have inherent biases, they provide useful insight into the ransomware landscape.

A total of 824 ransomware attacks were reported in September, representing a 53% increase compared with September 2025. Business Services was the most targeted industry, accounting for 31.3% of reported victims. Consumer Goods & Services followed at 15.2%, with Industrial Manufacturing at 11.0%. Because business services providers often hold data or system access on behalf of multiple clients, a single incident can have consequences that extend beyond the organization itself.

North America was the most affected region, accounting for 46% of reported ransomware incidents, followed by Europe at 25% and APAC at 17%. The United States accounted for 41.9% of reported victims, substantially ahead of Germany at 4.0% and Canada at 3.6%. These figures show where publicly claimed victims are concentrated, rather than the level of risk faced by an individual organization in each country.

The Gentlemen Leads the Ransomware Rankings

The Gentlemen was the most prevalent ransomware group in September, responsible for 13% of published attacks. Qilin followed with 9%, while Akira accounted for 5%. On top of the leading three actors, 80 further extortion groups reported ransomware attacks last month.

  • The Gentlemen: A fast-growing Ransomware-as-a-Service operation founded in mid-2025. It operates as both a RaaS provider and an Initial Access Broker and supports Windows, Linux and ESXi environments.
  • Qilin: An established Ransomware-as-a-Service group with victim disclosures dating back to 2022. It provides affiliates with encryption, negotiation and support infrastructure.
  • Akira: A Ransomware-as-a-Service actor first reported in 2023, with payloads targeting Windows, Linux and ESXi systems.

What September Tells Us

September’s figures show cyber risk increasing in both volume and breadth. Attack rates rose across every region, phishing became more frequent and ransomware remained well above last year’s level, while expanding GenAI use continued to expose sensitive information.

Organizations should focus on reducing exposure before it becomes business impact. Check Point’s prevention-first approach brings together AI-powered protection, shared intelligence and consistent governance across hybrid networks, cloud environments, digital workspaces and AI systems. As established and emerging risks converge, a unified security architecture can help teams prevent threats earlier, reduce complexity and secure AI adoption with greater confidence.

New FIRE Report: 475% Increase in Phishing Attacks Using Remote Access Tools

Posted in Commentary with tags on October 8, 2026 by itnerd

Fortra Intelligence and Research Experts (FIRE) have observed a massive 475% increase in phishing attacks leveraging remote management tools in 2026. These campaigns are targeting banking customers with fake support pages that prompt installation of legitimate software like AnyDesk, giving criminals ongoing access to victim devices and accounts. Once installed, threat actors have the ability to monitor activity, steal credentials, deploy additional malware or ransomware, and maintain persistent access long after the initial phishing interaction.

Details here: https://www.fortra.com/blog/increase-credential-phishing-remote-management-tools