The CISA orders federal agencies to patch actively exploited Oracle flaw by August 27

Posted in Commentary with tags on August 25, 2026 by itnerd

The CISA has added a maximum-severity Oracle vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

The flaw carries a CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS.

The vulnerability can be exploited remotely over HTTP without authentication or valid credentials, potentially allowing attackers to access, modify or delete critical data.

Oracle originally disclosed and patched CVE-2026-21962 on January 20, 2026, as part of its January Critical Patch Update. In March, researchers reported exploitation attempts after exploit code became publicly available.

CISA has ordered federal agencies to address the vulnerability by August 27.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs Had This To Say:

   “CVE-2026-21962 had a patch on January 20, and CloudSEK recorded exploitation attempts against its honeypot on January 22, followed by broader automated scanning. CISA added it to the KEV catalog on August 24, 216 days after the patch. Federal agencies now have three days to remediate something attackers have had seven months to exploit.

   “In January, agencies could have applied the Critical Patch Update inside a normal maintenance window and moved on. Seven months of delay while exploitation attempts and automated scanning were already being observed from rented VPS infrastructure changed the math. BOD 26-04 requires forensic triage at this severity tier, so agencies now have to assess whether compromise occurred during that seven-month exposure period alongside applying the patch.

   “BOD 26-04’s 16-tier remediation matrix is well-designed for the problem it solves. For a vulnerability in the KEV, automatable, and yielding total control of a public-facing asset, the clock is three days with forensic triage. In this case, CISA’s August 24 KEV addition produced an August 27 federal remediation deadline, while CISA’s obligation is to update the catalog “as quickly as possible,” with no numerical SLA. EPSS ranked this in the top 1.4%, Shodan shows roughly 79,000 exposed Oracle HTTP Server instances, and CISA’s own SSVC record dates active exploitation to January 21 while classifying the vulnerability as automatable with total technical impact.

   “Three days to remediate is the right call. Seven months to trigger it turned a maintenance window into a forensic investigation.”

This of course means update all the things ASAP. But we’re getting to a point where patching anything is a losing battle. Thus we need to think of something new when this avenue exhausts itself.

UPDATE: Also Commenting on this is Dan Moore, Sr. Director, CIAM Strategy & Identity Standards at FusionAuth

“The thousands of organizations relying on Oracle WebLogic to provide secure access to their applications are at risk of data loss, manipulation, and exfiltration. The unauthenticated access allows an attacker to make application calls to read data, as well as insert their own unauthorized changes. This issue affects any server accessible to an attacker, which is extremely problematic for many internet exposed applications.”

Uber gets hit with €825 million GDPR fine

Posted in Commentary with tags , on August 25, 2026 by itnerd

The Dutch Data Protection Authority fined Uber €825 million ($964 million), the second-largest GDPR fine ever issued, for violating GDPR’s ban on fully automated decision-making. Between 2018 and 2022, Uber used automated software to suspend driver accounts, sometimes permanently, without human review to catch errors, and failed to tell drivers the decisions were automated

Because losing access to Uber can immediately prevent drivers from earning money through the platform, regulators deemed that the case should fall under Article 22 of the EU GDPR, which restricts automated-only decision-making when it comes to having significant effects on individuals.

Ultimately, it means this is now the second-largest GDPR fine ever to have been issued, falling short of Meta’s 2023 €1.2 billion fine.

Arti Raman, CEO, Portal26

“The uncomfortable truth in this case is that most companies couldn’t tell you, today, everywhere AI is making consequential decisions across their organization. Uber’s violation ran for four years before regulators caught it. That’s not just a governance failure, it’s a visibility failure: you can’t govern what you can’t see. Before you can prove a human was in the loop, or that a decision followed policy, you need to know which systems are touching hiring, credit, insurance, or someone’s livelihood in the first place. Most enterprises running AI today don’t have that map.”

Companies who operate in the EU should take note because the EU isn’t playing around. Thus these organizations need to shape up their business practices or they may be next on the hit list.

New guidance aims to verify whether hardware is actually quantum-ready

Posted in Commentary with tags on August 25, 2026 by itnerd

Non-profit Trusted Computing Group (TCG) has released new guidance to help organizations determine whether Trusted Platform Modules (TPMs) genuinely meet post-quantum cryptography requirements.

TCG warned that not all TPMs currently marketed as quantum-ready provide complete quantum-safe capabilities.

The guidance provides a way to verify hardware against TCG’s PTP 1.07 standard, developed earlier this year with input from nearly 90 contributors across government, academia and companies including Intel, Google, Microsoft, NVIDIA, Lenovo and HPE.

It establishes two classifications: “PQC-ready” for TPMs that already meet the standard and “PQC-upgradable” for hardware designed to support the requirements through future upgrades. 

Denis Calderone, CTO, Suzu Labs Had This To Say:

   “TCG just published what amounts to a nutrition label for quantum-ready hardware claims, and its much needed. Vendors have been marketing TPMs as quantum-safe that don’t actually implement the full PQC specification. TCG’s own language warns buyers to avoid TPMs that advertise “compliance” yet fail to provide full, end-to-end security capabilities. Their new verification guidance gives buyers a way to test those claims against PTP 1.07, the standard that nearly 90 contributors from Intel, Google, Microsoft, NVIDIA, and others developed earlier this year. That’s a welcome move, because the “quantum washing” problem in hardware is getting worse, not better.

   “The backdrop here is real urgency. Nation-state adversaries are already running “harvest now, decrypt later” operations, intercepting and storing encrypted traffic today with the expectation that quantum computers will crack it open within the next decade. NIST finalized the first PQC algorithm standards in 2024, the Trump administration set hard federal migration deadlines of 2030 for encryption and 2031 for digital signatures, and NIST’s own deprecation roadmap phases out RSA and elliptic curve entirely by 2035. TPMs sit at the root of trust for the entire platform. If the chip that holds your keys and validates your firmware can’t do quantum-resistant crypto, everything built on top of it inherits that vulnerability.

   “What’s worth understanding is what this guidance is and what it is not. PTP 1.07 gives buyers a written baseline to verify vendor claims against. That’s genuinely useful. But there is no independent lab certification behind it yet. As of right now, no TPM has achieved FIPS 140-3 validation with PQC algorithms. The first FIPS 140-3 Level 3 validated module to include PQC just arrived in August 2026, and that was an HSM from Thales, not a TPM. The leading TPM vendor in this space has FIPS 140-3 submission targeted for September 2026. TCG has announced plans to build a formal certification program for PQC-ready TPMs, but their own language says “once completed,” meaning it does not exist today. So right now, this verification guidance is a self-assessment tool, not a third-party certification. It puts power in the hands of educated buyers who know what questions to ask, but it requires you to know what you’re looking at.

   “If you’re in procurement right now, particularly for federal or defense contract work, ask for the PTP 1.07 compliance evidence. If the vendor can’t produce it, you have your answer. And pay close attention to TCG’s distinction between “PQC-ready” and “PQC-upgradable.” Ready is a testable fact. Upgradable is a vendor roadmap promise about the future. Those are two very different things when you’re signing a purchase order.”

Organizations need to make their purchasing decisions accordingly and get hardware that doesn’t meet this guidance out of the hands of the users ASAP. It’s one important step to making their organization quantum ready.

Other World Computing Helps Mac Users Unlock the Full Potential of Newly Announced Apple Mac mini and Apple Mac Studio

Posted in Commentary with tags on August 25, 2026 by itnerd

Other World Computing today announced its unmatched roster of storage, connectivity, and expansion solutions for the newly announced Apple Mac mini, featuring M6 and M5 Pro and Apple Mac Studio with M5 Max and M5 Ultra

OWC products that support the new Mac Studio M5 Max, M5 Ultra, and Mac mini M5 Pro include: 

  • OWC Thunderbolt 5 Dock – high-performance 11-port connectivity hub that expands a single Thunderbolt port into multi-display 8K support, ultra-fast data transfer, 2.5GbE networking, and up to 140W of power delivery for Macs, PCs, iPads, and other USB-C devices
  • OWC Thunderbolt 5 Hub – expands a single Thunderbolt connection into three Thunderbolt 5 ports and one USB-A port, delivering up to 80Gb/s bi-directional performance, support for up to three 8K displays, and up to 140W of power delivery in a compact, fanless design
  • OWC Thunderbolt 5 Dual 10G Network Dock – with three fully independent high-speed Ethernet ports and four Thunderbolt 5 and four USB ports, the Thunderbolt 5 dual 10GbE Network Dock is the first all-in-one solution that simplifies complex multi-network workflows and unlocks high-bandwidth network storage connectivity while offering everyday docking convenience
  • OWC StudioStack – This low-profile, aircraft-grade aluminum hybrid storage solution on the planet lets you combine SSD and HDD storage in a single unit up to 32TB at up to 6302MB/s. Plus adds three additional Thunderbolt 5 (USB-C) ports and USB-A ports for new and legacy devices
  • OWC ThunderBlade X12 – Thunderbolt 5-powered portable production RAID SSD delivering up to 6600MB/s speeds and massive capacity in a compact, RAID 5 capable design built for high-end film, multi-cam 8K/12K workflows, and on-set shuttle reliability
  • OWC Express 4M2 Ultra – Thunderbolt 5 (80Gb/s) NVMe RAID storage solution, pre-configured with SoftRAID in 4TB, 8TB, 16TB, and 32TB capacities. Also available as a bare enclosure for building your own configuration
  • OWC Envoy Ultra – rugged, IP67-rated Thunderbolt 5 portable SSD delivering real-world speeds over 6000MB/s in a bus-powered, built-in cable design that makes storage more flexible and goes where you need it, including other Macs and PCs
  • OWC Express 1M2 80G – supremely fast USB4 80Gb/s NVMe portable SSD; available as a DIY enclosure to optimize the NVMe drive you already own or a ready-to-run solution; delivering over 6000MB/s real-world performance with broad Thunderbolt and USB-C compatibility in a rugged, passively cooled design
  • OWC Mercury Helios 5S – a powerfully simple way to use PCIe cards with Thunderbolt 5/4/3 and USB4 notebooks and small form factor computers like the Mac Studio + add more Thunderbolt 5 ports
  • OWC Thunderbolt 5 Cables (fully certified up to 2-Meter Thunderbolt 5 (USB-C) Cable) – fastest, most compatible cable for connecting today’s, tomorrow’s, and yesterday’s Thunderbolt and USB-C Devices

OWC products that support the new Mac mini M6 include: 

  • OWC Thunderbolt 5 Dock – high-performance 11-port connectivity hub that expands a single Thunderbolt port into multi-display 8K support, ultra-fast data transfer, 2.5GbE networking, and up to 140W of power delivery for Macs, PCs, iPads, and other USB-C devices
  • OWC Thunderbolt 5 Hub – expands a single Thunderbolt connection into three Thunderbolt 5 ports and one USB-A port, delivering up to 80Gb/s bi-directional performance, support for up to three 8K displays, and up to 140W of power delivery in a compact, fanless design
  • OWC Thunderbolt Go Dock – first full-featured Thunderbolt dock with a built-in power supply. Go anywhere + connect more than bus-powered docks
  • OWC Express 1M2 – ultra-fast, compatible, and reliable portable USB4 NVMe SSD – build your own or choose ready-to-run solutions
  • OWC Express 4M2 – (DIY to use existing NVMe SSDs) – four-slot USB4 (40Gb/s) external storage enclosure designed to utilize your existing or new NVMe M.2 SSDs
  • Thunderbolt 4 (USB-C) Cables – Thunderbolt 4 certified cable for universal use with Thunderbolt 4, Thunderbolt 3, and USB-C equipped Macs, PCs, and mobile devices

Safe Software Opens Registration for the Peak of Data and AI 2027 With More Accessible Access Packages

Posted in Commentary with tags on August 25, 2026 by itnerd

Safe Software has announced that registration is open for the Peak of Data and AI 2027, its global conference for data and AI professionals, taking place March 9 to 11, 2027 at the QEII Centre in London, UK.

The news builds on Safe’s announcement in March 2026 that London would host the biennial conference, which has previously been held in Vancouver, Canada, Bonn, Germany and Seattle, Washington, and draws attendees from North America, Europe, Asia-Pacific, and beyond.

Alongside opening registration, Safe has introduced a revised set of access packages designed to bring a broader range of professionals to the event:

  • Free passes for public sector and government professionals, from any country
  • One-day passes, for attendees who are unable to join for all three days
  • Lower pricing across every pass type, including the pre-conference training add-on

All attendees will also have access to a free AI training session on the first evening of the conference, regardless of which pass type they hold.

The three-day program will feature more than 100 breakout sessions led by FME users, keynote plenary sessions, product announcements, and FME Basecamp, the conference’s hub for hands-on technical support and networking. A Partner Summit for certified partners precedes the main event on March 8, 2027. The Call for Presentations is open until September 29, 2026.

Safe is currently finalizing 2027 sponsorship packages with its partner community. Organizations interested in sponsoring the event can contact events@safe.com.

Super Early Bird pricing is available until September 29, 2026. To register, visit peakofdataandai.com.

Sage Intacct expands AI-powered financial controls and industry capabilities for greater confidence

Posted in Commentary with tags on August 25, 2026 by itnerd

Sage today announced the latest update to Sage Intacct, introducing new AI-powered financial controls, connected reporting capabilities and industry-specific innovations that help finance teams work more efficiently while maintaining greater confidence and control.

Recent Sage research found that more than half (52%) of SMBs rank cyber security and data protection among their leading business priorities for the next 12 months, yet 81% are unprepared or only in the early stages of readiness for AI-related threats. As AI becomes more embedded across business operations, the findings highlight the growing importance of strengthening safeguards while enabling organizations to take advantage of its potential.

Building on Sage’s continued investment in AI-powered financial management, the latest Sage Intacct release uses AI to strengthen financial controls and help finance teams identify potential issues earlier. New Anomaly Detection for AP Automation surfaces unusual invoice activity earlier in the payment process, reducing the burden of manual review while giving teams greater oversight and control.

Expanding Sage Intacct for industry-specific finance

Sage Intacct continues to deepen its industry-specific capabilities, addressing the distinct financial and operational requirements of organizations across construction, lending and hospitality. The latest release introduces new functionality spanning complex construction billing and retainage, loan lifecycle management and connected hospitality operations.

These investments are part of Sage’s continued focus on delivering financial management capabilities tailored to the industries customers operate in. Combined with enhancements to reporting, billing and customer payments, they enable finance teams to manage greater operational complexity while maintaining visibility, control and confidence as their organizations grow.

What’s new in Sage Intacct August 2026:

  • Anomaly Detection for AP Automation –Helps finance teams identify potential invoice anomalies earlier while maintaining confidence and control, by using AI to detect invoices received from unrecognised vendor email addresses, Administrators can review and block suspicious senders before payment, helping focus attention on transactions that require further investigation.

Generally available globally for Sage Intacct AP Automation customers

  • Enhanced Billing Groups in Order Entry –Supports organizations in managing complex billing processes with greater flexibility and control. With on-demand invoice generation, expanded billing workflows, and draft invoice reviews, finance teams now have improved billing accuracy while maintaining auditability and reducing operational friction.

Generally available globally

  • Customer Payments Portal –Gives organizations greater flexibility over how customers pay, with a self-service experience that supports multiple payment providers and payment methods within Sage Intacct. Payment links, scheduled payments and saved payment details help simplify the payment experience, accelerate collections and reduce administration.

Available through an Early Adopter program globally

  • Construction Billing and Retainage Enhancements – Helps construction finance teams simplify complex project billing and strengthen financial oversight. New capabilities automate retainage calculations and provide greater flexibility across contract billing workflows, reducing manual effort while improving accuracy and consistency.

Construction Retainage Enhancements are generally available, and Construction Billing available through an Early Adopter program in US, UK, AUS and Canada

  • Sage Intacct Lending Management –Enables lending organizations to manage the full loan lifecycle within a single financial management platform, by supporting loan origination through to payoff while automating interest calculations and borrower statements. This improves operational efficiency, accuracy and financial visibility without relying on separate systems.

Generally available in the US

  • Smart Reporting for Excel – Lets finance teams work with Sage Intacct reporting structures directly in Excel, without recreating reports or relying on manual exports. Connected financial data can be refreshed as needed, while Sage Intacct permissions and access controls are maintained, giving teams the flexibility of Excel with greater confidence in the data they are using.

Available through an Early Adopter program in the US and UK

  • Connected to Craftable – Automatically synchronizes purchasing, sales and inventory data with Sage Intacct, reducing manual entry and helping hospitality organizations accelerate month-end close across restaurants, bars, hotels and hospitality groups.

Generally available in the US

Methodology:

Source: Sage report, with research and analysis by IDC, SMBs in the age of AI: Navigating cyber complexity and building resilience, 18 May 2025. 

IDC conducted a custom survey of 2,210 SMBs across eight geographies: Canada (300), France (330), Germany (330), Portugal (100), South Africa (150), Spain (200), United Kingdom (300), and United States (500).

New Global Study Finds AI Success Three Times More Likely at Fully Integrated Organizations

Posted in Commentary with tags on August 25, 2026 by itnerd

Certinia, today released its 2026 Global Service Dynamics Report, based on an independent survey of 1,000 professional services and IT/technology leaders around the world. One of the report’s top conclusions is that the clearest predictor of performance in the sector this year isn’t how much a company has invested in AI or talent, but whether that business runs on a single, connected system across the organization.

Organizations reporting the strongest AI results, highest profit margins, and account expansion are consistently more likely to report full operational alignment across sales, delivery, finance, and customer success than those struggling on the same measures. Companies with successful AI outcomes are more than three times as likely to be fully integrated as those with mixed results (28% vs. 8%). Firms achieving peak profitability, with margins above 40%, are also three times more likely to have fully integrated operations compared with barely profitable competitors. And among organizations achieving net revenue expansion above 100%, 68% are aligned or fully integrated, well above the 22% sector-wide rate of full integration.

The report’s additional findings reveal further gaps in perception, hidden operational risk, and early shifts in how services businesses price and staff their work.

The Perception Gap

Executives and delivery teams are living in different realities: Executives consistently rate their own organizations’ performance more favorably than the people actually delivering the work. Leaders rate their forecasting confidence 24 points higher than practitioners do, their AI success 16 points higher, and their ability to grow without adding headcount 10 points higher.

Retention goals aren’t reaching the front lines: 62% of executive leadership teams have defined net revenue retention goals, compared with just 45% of services/delivery teams, despite these teams often being closest to the customer experience that drives retention.

Operational Blind Spots

Confidence collapses in the “messy middle”: Just 38% of partially aligned organizations report high confidence in their resource, demand, and revenue forecasts. This compares to 75% among fully siloed companies and 78% among fully integrated ones — evidence that half-finished tech connections carry the costs of interdependence without the benefits of a shared system.

Account expansion is a massive missed opportunity: Just 6% of organizations globally are achieving net revenue expansion above 100%. This untapped growth opportunity is highly regional; expansion rates above 100% are more than four times as common in North America (9%) as in Asia-Pacific (2%).

AI performance is unevenly distributed: Among organizations that have deployed AI, the share reporting moderate or significant success ranges wildly by sector — from just 43% among accounting, tax, and audit firms to 74% among IT service providers.

Shifting Business Models

Pricing is moving decisively toward outcomes: 75% of organizations expect to increase outcome-based pricing over the next 12 months, even as nearly one-third already report difficulty managing hybrid or complex billing models.

Hiring priorities are shifting toward AI expertise: 82% of leaders name AI and data specialists their top hiring priority for the year, even as 82% of organizations expect to grow revenue without a proportional increase in billable headcount.

The 2026 Global Service Dynamics (GSD) Report was conducted by Sapio Research on behalf of Certinia, surveying 1,000 professional services and IT/technology decision-makers across the US, Canada, UK, Australia/New Zealand, and Singapore in June 2026. The full report, including chapter-by-chapter analysis of operational alignment, AI maturity, pricing models, talent, and financial performance, is available for download at certinia.com/services-report.

Ericsson Puts Trois-Rivières Transit in the Technology Fast Lane

Posted in Commentary with tags on August 25, 2026 by itnerd

Trois-Rivières Transit (STTR), in a transformative project enabled by Ericsson enterprise technology, has successfully modernized its entire 65-bus fleet. The project replaced a complex web of proprietary hardware with a single, unified in-vehicle network platform. This new approach consolidates all critical onboard systems, including computer-aided dispatch/automatic vehicle location (CAD/AVL) from Systrans, passenger information displays, fare collection, and safety systems, into one ruggedized mobile router. The achievement sets a new standard for operational efficiency and reliability in public transit.

The project was driven by the need to replace an aging, unreliable technology infrastructure that was difficult to manage and dependent on costly, interlocked vendor systems. The new solution leverages Ericsson’s enterprise wireless solutions—backed by its intelligent cloud management platform, NetCloud Manager—which are designed to help organizations innovate and operate without constraints by providing flexible and secure 5G connectivity. With Quebec’s telecommunication providers decommissioning 3G networks, STTR’s legacy CAD/AVL system faced a shutdown, creating an urgent need for a fundamental change. The previous architecture resulted in untrustworthy data for operations supervisors and an inconsistent rider experience.

Working with engineering consultants, CIMA+ and CAD/AVL software provider Systrans, STTR pioneered an innovative approach centred on Ericsson’s technology. The technical foundation of the solution is the Ericsson Cradlepoint R1900 Series 5G mobile router, which serves not only as a connectivity gateway but also as a powerful edge computing platform. Systrans containerized its Navineo CAD/AVL application to run directly within a Docker container on the router, completely eliminating the need for a separate, proprietary onboard computer. This open-architecture model, inspired by ITxPT principles, allows STTR to own and control its onboard technology ecosystem.

This achievement unlocks a future where technology updates and new features can be deployed through software rather than costly hardware replacements. Fleet-wide software updates that previously required physically visiting each bus with a USB stick can now be completed remotely in a single day using Ericsson’s NetCloud Manager. With reliable, real-time data, STTR can now offer accurate arrival information to riders and utilize a Transit Signal Priority (TSP) system to keep buses on schedule, significantly improving service quality.

How it works 

Working with engineering consultants CIMA+ and CAD/AVL software provider Systrans, STTR developed an approach that turns conventional transit technology on its head. Rather than buying another proprietary onboard computer, the team separated hardware from software with an open, capable platform, letting its Navineo CAD/AVL software to run directly on the router, eliminating the need for a separate onboard computer.

Ericsson Cradlepoint R1900 Series 5G mobile routers were deployed across 65 buses in approximately three weeks, replacing STTR’s disparate networking solutions with a single router that acts as the central hub for everything: the passenger displays inside and outside the vehicle, the fare collection system, security cameras, the driver’s tablet, automated stop announcements, and ridership counters. A single 7-in-1 antenna handles GPS, Wi-Fi, and cellular connectivity. The driver’s emergency panic button connects directly to the router, so an alert reaches the operations centre the moment it is triggered. No separate device needed. Operational and location data from each bus feeds into cloud-based systems that power both the real-time tracking that operations staff rely on and a Transit Signal Priority (TSP) system at intersections. When a bus is running behind schedule and carrying a full load of passengers, the system can extend a green light to help it catch up. Across approximately 100 intersections, that intelligence adds up to meaningfully faster, more reliable service for riders

Arcitecta Launches Active Data Management Solution for Universities Facing Microsoft 365 Education Storage Policy Changes

Posted in Commentary with tags on August 25, 2026 by itnerd

Arcitecta today announced Mediaflux® Connect 365, a solution that brings active data management to Microsoft® OneDrive, SharePoint and Teams, to help universities and research institutions optimize long-term data management while keeping data instantly accessible, searchable and governed.

Microsoft is transitioning Microsoft 365 Education from its previous unlimited cloud storage model to a free but limited pooled storage model (capped at 100 terabytes per tenant plus 50-100 gigabytes per licensed user) as universities renew their Microsoft 365 licensing agreements. For institutions that have relied on unlimited storage, the change will necessitate increased storage costs, significant data reduction or migration to lower-cost storage options. Institutions managing hundreds of terabytes or multiple petabytes of data could face additional costs of approximately USD $360,000 per petabyte per year.

Active Data Management for Microsoft 365 OneDrive and SharePoint Data

Arcitecta’s Mediaflux Connect 365 empowers universities to quickly identify and categorize the data within their Microsoft environment, enabling institutions to meet fast-approaching data migration deadlines and to start the often lengthy Microsoft-controlled egress process.

Key benefits of Mediaflux Connect 365 include:

  • Data analysis. Identifies the data residing in Microsoft 365 storage to help institutions determine what data they want to retain there, move or be deleted. Uses data analytics to identify what data must be moved and migrated into on-premises, cloud or hybrid storage.
  • Reduced storage costs. Organizations can avoid the significant cost increases associated with the new Microsoft 365 Education storage limitations and commercial pricing changes.
  • Improved governance under active data management. All institutional data can be managed from a single pane of glass, including from Microsoft’s OneDrive, SharePoint and Teams, providing simplified data management and visibility across storage types and locations. Today these data repositories are unmanaged, making it difficult to understand what data is stored, identify sensitive information, such as Personally Identifiable Information (PII), or verify backup policies.
  • Powerful metadata support. Rich, searchable metadata makes data genuinely manageable at scale, not just archived out of sight. Metadataenables data users to find what they need when they need it, understand and identify what data they have, and provide details such as how and where the data was generated.
  • Flexible storage options. Maintains choice and control through flexible, vendor-neutral storage options, including on-premises (flash, object and tape) and any cloud storage.

Worldwide Ecosystem Expansion

Arcitecta is expanding its ecosystem of technology partners to help universities worldwide respond to Microsoft’s new storage requirements. By combining any storage with Mediaflux’s active data management capabilities, institutions can reduce costs and optimize Microsoft 365 storage while meeting local requirements for data sovereignty, governance and long-term stewardship.

Availability

Arcitecta’s Mediaflux Connect 365 solution is available immediately. For more information, please reach out to an Arcitecta team member at talk@arcitecta.com.


Resources

Supply chain attack infects Android car systems with botnet malware

Posted in Commentary with tags on August 24, 2026 by itnerd

Kaspersky researchers uncovered a supply chain attack infecting Android-based car head units with malware designed for ad fraud and proxy botnet activity.

The malware was distributed through the built-in updater of TWCore, a legitimate system application installed on head units from Chinese automotive technology provider DoFun. Researchers said this is the first documented malware infection chain specifically designed to target automotive head units.

The attack uses a three-stage infection chain, beginning when the legitimate updater downloads a malicious APK. Once installed, additional malware components are retrieved that can generate fraudulent advertising activity and turn the vehicle’s internet connection into a proxy for other traffic. 

The threat is imminent. Today’s notice of the critical Keycloak Password Reset Flaw (CVE-2026-18963, CVSS 9.1) exposes thousands of enterprise identity servers to risk of complete, unauthenticated takeover.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “MoYu Group, the same actor behind BADBOX infections on cheap Android TV set-top boxes, expanded to car dashboards because to a residential proxy operator, any Android device with a Subscriber Identity Module (SIM) card is just inventory.

   “DoFun’s TWCore updater accepts instructions from a Message Queuing Telemetry Transport (MQTT) broker and includes a flag called installNotExists that lets the server push entirely new applications to the device without human approval. The attackers pushed malware through this privileged deployment channel exactly as it was designed to work.

   “The zhima proxy module on these head units ties back to residential proxy services PXYEDGE and ProxyForU, both connected to MoYu Group’s broader infrastructure. Compromised vehicles are being sold as proxy endpoints to whoever pays. A car sitting in a parking lot becomes someone else’s exit node, routing traffic through a cellular connection the vehicle owner pays for.

   “Every original equipment manufacturer (OEM) sourcing Android-based head units from third-party firmware providers should be asking who audited the update channel before it shipped. Arbitrary code delivery already works through loadlib2, while loadlib and loadlib3 command paths were not fully implemented at the time of analysis. The proxy botnet is the current monetization model; the underlying access gives the operator considerably more capability than proxying traffic.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “If I’m looking at the overall trend of attacks we’ve been seeing lately, this fits right in. Supply chain attacks, malicious NPM packages, and similar techniques are increasingly showing up in some of the more advanced and interesting attacks. I’m not necessarily talking about ransomware here. I’m talking about attackers deliberately targeting areas that create blind spots for information security teams.

   “For years, so much of information security has been focused on endpoints and EDR. More recently, organizations have started expanding that focus into cloud and identity security. That’s good, but attackers are moving into technologies that many traditional security stacks simply weren’t designed to monitor.

   “Supply chain attacks are a perfect example. So is Android malware targeting head units used by automobile manufacturers. Most people aren’t running EDR on their car.

That sounds funny, but it highlights a serious problem.

   “Attackers are finding technologies that fall outside the visibility of traditional security tools. Once they get into those environments, they have an opportunity to propagate, establish persistence, and potentially remain undetected for long periods of time. The problem isn’t necessarily that security teams aren’t paying attention. In many cases, the technology they’ve invested in simply doesn’t support these systems.”