Cyberattacks target five Minnesota water utilities 

Posted in Commentary on July 28, 2026 by itnerd

Cyberattacks targeting the water utilities of BrahamSouth St. Paul, Plymouth, Maple Plain and St. Cloud, Minnesota disrupted automated control systems at multiple facilities, prompting operators to switch to manual operations.

In Braham, the attack temporarily shut down the city’s water treatment plant, but crews restored service in less than two hours, and officials said water quality, public safety and infrastructure were not affected.

Minnesota IT Services (MNIT) confirmed it is assisting the affected communities with incident response, forensic analysis, and recovery efforts. Officials said the attacks primarily targeted industrial control systems used to monitor and operate water infrastructure, and investigations into the incidents remain ongoing.

Denis Calderone, CTO, Suzu Labs:

“The reporting is early on these attacks and there is no way to definitively attribute who the threat actor is, but it’s awfully coincidental that attacks against water utility control systems in five Minnesota cities are coming this soon after CISA released advisory AA26-097A warning about exactly these kinds of targets. That advisory, updated just last week with expanded scope covering Siemens and Schneider PLCs alongside Rockwell, specifically names water and wastewater systems as a targeted sector. We can’t draw a line between the two yet, but it fits the pattern we’ve been tracking since April.

“The good news here is that every one of these cities was able to fall back to manual operations and maintain service. The fact that trained crews could step in and run these systems manually while the automated controls were compromised is what kept this from becoming a major public safety incident.

“With the little that is known about these attacks, we did find it particularly interesting that Plymouth city officials noted that the impact was limited to equipment connected via cellular communications. Water towers, lift stations, pump stations, these remote assets often connect back to the SCADA system over cellular modems, and in our experience secondary and/or alternative comm links are often overlooked when doing risk and vulnerability analysis, so it’s not too surprising then that the vector of attack may have been via these cellular connections. Oftentimes, regarding SCADA and Industrial Control networks, the infrastructure is largely built out by the integrator which increases the chance that these connections get overlooked. We saw in the reporting that Braham’s city administrator is now asking for their system vulnerability study to be reevaluated, and I wouldn’t be surprised if that study never included those cellular communication paths in the first place.

“The prescriptive advice here is the same as it’s been all year: take control systems off the internet, segment OT networks from IT, change default credentials on every device in the environment, and put remote access behind a VPN. But the lesson from Minnesota is that you have to know all the links. Every communication path into your control environment needs to be inventoried and tested, including the cellular modems, the radio links, the backup communication channels that don’t show up on the network diagram because the diagrams just don’t go into that level of depth, or because some components are simply forgotten about because they were installed five years ago by a contractor who’s long gone. If you don’t know every way into your control systems, you can’t protect them.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.

“The encouraging news is that operators appear to have maintained safe water service through a mix of manual operations and resilient system design. If those facts hold, this demonstrates an important principle: cyber resilience isn’t about preventing every intrusion, it’s about ensuring cyber incidents don’t become public safety incidents. As cyber attacks increasingly target operational technology, organizations need the operational ability to find exposed systems, fix the highest-risk vulnerabilities, detect compromise when prevention fails, and contain attacks before they disrupt essential services.”

John Strand, Owner, Black Hills Information Security, Inc.:

“We’re seeing more breaches targeting public and critical infrastructure, and I think one of the biggest things people are missing is the difference between financially motivated attackers and nation-state adversaries. When a criminal group compromises a network, they’re often looking for a quick payday through ransomware or data theft. Nation-state operators frequently have a very different objective.

“Their goal is often to gain access and stay there. They want to establish persistence, quietly understand the environment, and position themselves so they can disrupt critical infrastructure whenever it serves their strategic interests. Water treatment facilities, power generation, transportation, and other essential services are attractive targets because they provide leverage long before an attack is ever launched.

“The challenge is that many security programs are still built to detect noisy attacks like ransomware or smash and grab intrusions. They’re much less effective at finding the low and slow activity that characterizes many nation-state operations. If organizations responsible for critical infrastructure aren’t investing in threat hunting, network telemetry, and behavioral analysis designed to uncover long-term persistence, there’s a real risk that sophisticated adversaries will remain inside those environments long before anyone realizes they’re there.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Five separate water utilities hit across Minnesota tells you this was coordinated targeting of a sector, not opportunistic scanning that happened to find a few open doors. The reassuring headline is that crews switched to manual and restored service fast, but manual fallback is a contingency, and contingencies have limits that vary by facility, by staffing, and by how long the disruption runs. What investigators need to establish is how the same attack pattern reached systems in Braham, South St. Paul, Plymouth, Maple Plain, and St. Cloud, because whatever that common thread is, it almost certainly exists in water infrastructure well beyond Minnesota.”

You’re a target. So you have to behave that way. Beef up your defences so that you don’t end up like these organizations. Otherwise you will end up like these organizations.

Data breach at medical billing firm MCBS affects 1.26 million people

Posted in Commentary with tags on July 28, 2026 by itnerd

Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech

“This is another prime example of why third-party healthcare companies, like medical billing providers, have become a prime target for ransomware groups. By targeting one entity, they’re gaining access to multiple healthcare providers and their data. Our recent H1 healthcare ransomware report found a 35 percent uptick in attacks on these types of companies (those that specialize within the healthcare sector but don’t provide direct care). This breach becomes the second-largest on a third-party healthcare business following a ransomware attack in the last 18 months.”

The report that was linked is a very good one, and I encourage you to read it if you get a chance.

UPDATE: Additional commentary comes via Seemant Sehgal, Founder & CEO, BreachLock:

   “A breach that ran for four days in September 2025 and surfaced in a public disclosure eight months later tells you something about how difficult incident response and forensic review are in environments that handle data across multiple providers simultaneously. The data types here, Social Security numbers, insurance details, medical information, are the combination that makes downstream fraud viable for years, which means the harm timeline for affected individuals extends well beyond the notification date. Eight months is a long time for that data to be in motion before patients knew to watch for it.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “One of the things I absolutely hate about stories like this is that the default response is almost always complimentary identity protection services. Yes, those services can detect some types of fraud, but they don’t come close to addressing the full range of risks created by a data breach. They have value, but they’re far from a complete solution.

   “I’ve started calling this the information security equivalent of thoughts and prayers. It’s the absolute bare minimum a company can offer after a breach without making meaningful changes to improve security or reduce future risk. The reality is that only a fraction of affected people will ever enroll in those services, and even those who do aren’t protected against every way their information can be abused. It’s frustrating because organizations can suffer a major breach, offer a year of identity protection, and too often that’s treated as an adequate response instead of a starting point for real accountability.”

Damon Small, Board of Directors, Xcape, Inc.:

   “Third-party healthcare billing breaches create massive regulatory exposure and systemic supply chain liability when basic detection and response controls fail. The intrusion at Medical Business Office Systems, known as MCBS, allowed attackers to dwell for days and exfiltrate over three terabytes of sensitive patient and insurance data undetected, exposing non-existent data loss prevention and egress monitoring capabilities.

   “Furthermore, an eight-month delay before patient notification, justified by waiting for internal investigation completion, highlights severely flawed incident response processes. Security leaders must mandate continuous network egress monitoring, enforce strict data loss controls on revenue cycle aggregators, and require business associates to report material intrusions within days rather than waiting for post-forensic completion.

   “Critical Takeaways

  • Monitor large-scale data egress: Deploy continuous network monitoring and data loss prevention tools to detect abnormal outbound traffic before terabytes leave the perimeter.
  • Accelerate incident response SLAs: Mandate that third-party vendors establish tight notification timelines rather than withholding breach disclosures for months while conducting internal reviews.
  • Enforce vendor risk accountability: Require revenue cycle partners to submit to regular security telemetry audits and maintain strict field-level data controls for sensitive patient records.

   “If it takes eight months to realize three terabytes of patient data walked out the door, your incident response plan is a post-mortem, not a defense.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “MCBS had a regulatory shortcut available that would have made this entire disclosure unnecessary. The Health Insurance Portability and Accountability Act (HIPAA) includes a breach notification safe harbor for properly encrypted data, meaning if those 1.26 million Social Security numbers had been encrypted at the field level, the stolen files would have been useless ciphertext and the breach wouldn’t have triggered notification requirements. The encryption was always the cheapest fix. MCBS chose not to implement it when the rule calls encryption “addressable” rather than mandatory.

   “The Department of Health and Human Services proposed eliminating that flexibility in January 2025, making AES-256 encryption at rest mandatory for all electronic protected health information. That rule hasn’t been finalized, and final action has been pushed to July 2027. Encryption remains “addressable” today, and every healthcare billing company that reads “addressable” as “optional” is sitting on the same exposure MCBS had.

   “Credit monitoring as a remedy tells you what the breach responders think the threat model is, and they’re thinking too narrowly. PEAR (Pure Extraction and Ransom) exfiltrated 3.3 terabytes from MCBS, including medical histories, mental health conditions, and diagnosis information. That data enables targeted blackmail, insurance manipulation, and employment discrimination. A credit freeze catches none of it.

   “Under the EU’s General Data Protection Regulation (GDPR) Article 82, affected individuals can claim compensation directly from the company that lost their data. The US gives 1.26 million people a year of free credit monitoring instead. A $4 trillion industry can afford field-level encryption, and it can afford direct liability to patients when it skips it.”

377 vulnerabilities exploited at Microsoft since 2021, more than any other AI company

Posted in Commentary with tags on July 28, 2026 by itnerd

Cybernews researchers have analyzed the KEV (Known Exploited Vulnerabilities) Catalog – a list of already-exploited weaknesses in software (or hardware), compiled by CISA (the U.S. Cybersecurity and Infrastructure Security Agency). Cybernews found 828 common vulnerabilities and exposures (CVEs) at AI companies since 2021, with Microsoft accounting for 377 of them.

Key findings:

  • Since 2021, CISA has recorded 828 CVEs across 16 AI companies.
  • Out of all AI companies in the dataset, Microsoft is by far the leader in the number of CVEs, with 377 vulnerabilities found.
  • A closer look at Microsoft revealed that 27% of vulnerabilities were ransomware-related.
  • Microsoft Windows is the most-exploited product, with 170 known vulnerabilities.

“The number of exploited vulnerabilities correlates strongly with a technology company’s market share. This isn’t surprising: the biggest products draw the most attacker attention, since a single vulnerability can be leveraged against a far larger user base. That said, the shift toward SaaS, the growing amount of business-critical data living online, and the rapid adoption of AI are all raising the stakes around trust and vendor reputation,” says Voldemaras Kadys, Head of Security and Platform Engineering at Mediatech, the digital publishing house behind Cybernews.

For more information, here’s the full report:

https://cybernews.com/security/828-vulnerabilities-exploited-at-ai-companies-since-2021

XBOX suffers day long outage

Posted in Commentary with tags on July 28, 2026 by itnerd

The gaming platform XBOX has a massive outage yesterday. PC Magazine has the details:

The problems began at 5:30 a.m. ET on Monday. Xbox’s support page confirms issues after spikes on Downdetector, with thousands of users reporting problems.

An update from Microsoft at 8 a.m. ET said its team was continuing to work on the issues. “Just checking in on the game library, sign-in, and game launch issue. We know this has been going on a while and appreciate your patience while our teams keep working on it,” it wrote.

So far, there’s no word on when a fix will be rolled out or what’s causing the problems. Xbox’s support page says it’s affecting digital and disc-based games on all its consoles, from the latest Xbox Series X and S to the Xbox 360. It also confirms there are problems with accessing its backward-compatibility features.

Some users are finding they can’t sign in to their accounts at all, while others can’t access the store to download new titles. Other Microsoft warnings say to expect to “be disconnected while signed in, or have other related problems.”

This was ultimately resolved around 7PM EST. And the article I linked to has an overview of what happened. But it left a bad taste in XBOX users mouths. And I have to admit that if I played video games, it would affect my buying decision.

Commenting on this, Mayur Upadhyaya, CEO of APIContext, said:

“The Xbox incident is a good reminder that modern digital delivery chains are far more fragmented than most people realize. Every online service depends on dozens, sometimes hundreds, of internal and external components working together.

The interesting question isn’t why one licensing service failed. It’s why a dependency that many people wouldn’t naturally think of as mission-critical became mission-critical the moment it stopped working. That’s the reality.

It’s also why these incidents are so difficult to resolve. The challenge isn’t simply identifying the root cause, it’s understanding the dependency chain and the knock-on effects across the wider service.

This isn’t unique to Xbox. Every organization has dependencies that sit just outside their normal operational visibility. Most monitoring focuses on internal applications, but customers experience the entire transaction, including cloud services, identity providers, APIs and other third-party dependencies.

The uncomfortable reality is that organizations often only discover these hidden dependencies when one of them fails. That’s why resilience increasingly depends on continuously verifying end-to-end transactions, not just monitoring individual systems”.

This serves to be a reminder that cloud services are inter-dependant on services that run underneath them. And any of them can fail at any given time. Thus users should be prepared for downtime. And organizations like XBOX need to stop downtime from happening.

Park Place Technologies Expands Global Services for AI-Accelerated Servers

Posted in Commentary with tags on July 28, 2026 by itnerd

Park Place Technologies is expanding its comprehensive global third-party maintenance and support capabilities for GPU-powered servers, helping enterprises accelerate AI adoption, deploy infrastructure faster, maintain performance, reduce risk, and gain greater flexibility as AI-driven infrastructure rapidly evolves.

Park Place Technologies now delivers enterprise-grade, global third-party support for mission-critical GPU-enabled servers across data centers, edge locations, and hybrid environments. Its services are designed to support organizations running AI and machine learning training and inference platforms, high-performance computing clusters, virtualized GPU environments, and data analytics and simulation workloads — helping organizations move AI initiatives from pilot to production without being slowed down by infrastructure support gaps.

GPU-based systems introduce unique operational demands compared with traditional computing environments, including higher thermal density, increased power requirements, BIOS and driver interoperability considerations, and multi-GPU system complexity. Park Place has invested in GPU-specific engineering expertise to support these environments and accelerate AI infrastructure readiness, including:

  • GPU-dense server architectures
  • Tensor Processing Unit (TPU) circuits
  • Advanced cooling and power configurations
  • BIOS and driver interoperability
  • AI accelerator-focused systems

In customer deployment environments spanning more than 60 data centers globally, Park Place has supported infrastructure at significant scale, including more than 24,000 servers and over 76,000 GPUs to date. Combined with post-deployment support and hardware maintenance services, Park Place enables organizations to simplify lifecycle management and accelerate AI infrastructure outcomes for high-performance computing and AI initiatives worldwide.

Park Place Technologies differentiates its GPU support offering through:

  • Proven global delivery at scale
  • OEM-agnostic, third-party independence
  • Expertise aligned to modern GPU workloads and AI acceleration needs
  • Predictable costs and flexible contracts
  • Enterprise governance, reporting, and compliance

As GPU infrastructure continues to evolve, Park Place Technologies is committed to evolving with it, providing organizations with the support, expertise, and operational flexibility needed to accelerate AI initiatives and keep critical environments running at peak performance.

To learn more, visit ParkPlaceTechnologies.com.

Recast has some new research that has just come out

Posted in Commentary with tags on July 28, 2026 by itnerd

There’ new research from Recast called “The State of Intune in 2026”.

The report explores how organizations are navigating the transition from Microsoft Configuration Manager to Intune, revealing that while Intune is well regarded, many IT teams continue to struggle with manual application management, third-party patching, and the realities of operating hybrid environments. 

You can read the research here.

ZuriQ raises $25.5 million to scale new groundbreaking 2D quantum architecture

Posted in Commentary with tags on July 28, 2026 by itnerd

ZuriQ, a Swiss quantum computing company spun out of ETH Zürich, today announced it has raised $25.5 million in seed funding to scale its trapped-ion quantum processors. The round builds on the company’s $4.2 million pre-seed round in 2025 and is led by Quantonation, with participation from Forward.oneExtantiaFirgun Ventures, and all previous round investors. ZuriQ will use the new capital to expand its team alongside research and development efforts as it works to significantly increase the number of qubits its architecture can support.

Most trapped-ion quantum computers are built on an architecture first proposed more than two decades ago, in which ions are held in essentially one-dimensional chains stitched together into larger grids using complex junction structures. ZuriQ has taken a fundamentally different route with processors that are natively two-dimensional. Using Penning micro-traps, the company uses a static magnetic field in place of the rapidly oscillating fields most legacy architectures rely on, replaces the oscillating fields of conventional designs with a static magnetic field, allowing ions to move freely in any direction without the junctions that constrain reconfiguration.

ZuriQ is proving out its native two-dimensional architecture with a working demonstrator – successfully developed in just 18 months. The demonstrator comprises a 3×3 array of nine individually controlled ions, the largest two-dimensional array of its kind demonstrated to date, built in collaboration with researchers at ETH Zürich. The chips behind it were fabricated with ZuriQ’s manufacturing partner, Infineon, showing the design can be produced with established industry processes.

With the architecture and its manufacturing route established, the company’s focus now turns to scale: rapidly increasing the number of ions on a chip to enable powerful, commercially useful machines. Since its last investment, ZuriQ has grown from four people to eighteen. The company has attracted world-class talent with backgrounds from leading quantum and photonics organizations, including IonQ, Xanadu, and Hamamatsu. The new capital will go toward further hiring, expanding the company’s research program, and scaling up chip fabrication – the groundwork for putting hundreds of qubits on a chip.

MedusaHVNC hijacks browser sessions, bypasses MFA protections

Posted in Commentary with tags on July 28, 2026 by itnerd

In new research, BlackFog’s Darren Williams details how MedusaHVNC gives attackers covert access to live, logged-in browser sessions by opening a legitimate browser on a hidden Windows desktop. Because the activity occurs on the victim’s own device using its existing profile, cookies and session state, the malware can exploit authenticated accounts while remaining invisible to the user.

Jacob Krell, Senior Director, Secure AI Solutions & Cybersecurity, Suzu Labs had this to say:

“MedusaHVNC doesn’t need to steal credentials. It launches a real browser inside a hidden Windows desktop using the victim’s existing profile, so the attacker’s session arrives pre-loaded with every cookie, saved password, and active authentication token the victim already has. Multi-factor authentication (MFA), passkeys, hardware tokens, all of them authenticated that browser before the attacker showed up.

“Most organizations are investing in authentication hardening right now, phishing-resistant MFA, passkey rollouts, conditional access. All of it protects the login. MedusaHVNC operates entirely after the login, where the attacker’s session looks identical to the victim’s, same machine, same IP, same browser fingerprint, same cookies. Token binding and continuous session validation are what cover that gap.

“Hidden Virtual Network Computing (HVNC) used to be one of the hardest malware features to build. MalwareTech documented in 2015 that it essentially required writing your own window manager. MedusaHVNC now sells that capability through a dedicated website and Telegram channel, with an operator panel where you pick a browser from a dropdown and adjust the frame rate. That’s the industrialization of cybercrime compressed into a single feature’s history, a capability that once required deep Windows internals expertise is now a product with customer support.

“The infection chain is a living-off-the-land sequence, wscript.exe to AutoIt to charmap.exe, every binary signed and trusted until the final payload drops. In my experience, living-off-the-land chains evade detection better than custom malware because endpoint detection and response (EDR) flags unknown executables, not trusted ones behaving slightly wrong. Application allowlisting breaks this chain at the first stage. If a workstation doesn’t need wscript.exe or AutoIt, disable them. ‘Ships with Windows’ and ‘needed on this host’ are different questions, and attack surface reduction is how you stop living-off-the-land chains before they reach the payload.”

John Strand, Owner, Black Hills Information Security, Inc. follows with this:

“Browser-based persistence is becoming one of the next major frontiers in cybersecurity. For years, we’ve focused on securing the endpoint, but once malicious activity moves into the browser, visibility becomes much more difficult. Many security vendors intentionally take a hands-off approach to browser activity because of legitimate privacy concerns. A lot of organizations aren’t fully decrypting TLS traffic, let alone inspecting exactly what’s happening inside a user’s browser.

“The reality is that the browser has become the new endpoint. Nearly every business application and cloud service runs through it. Browser-focused attack frameworks have existed for years, but this latest campaign shows they’re becoming more sophisticated. Attackers are shifting away from techniques that target only the operating system and are investing in methods that are harder to detect and much more resilient.”

Organizations need to look at their security in an holistic way. Because only focusing on one area will guarantee that you get pwned.

What Nvidia’s Open Secure AI Alliance means for enterprise security

Posted in Commentary with tags on July 28, 2026 by itnerd

First, if you’re not up to date on Nvidia’s Open Secure AI Alliance, this will help:Industry Leaders Join Open Secure AI Alliance for AI Safety and Security | NVIDIA Blog

The consensus from experts in the industry is that this is a meaningful step for the industry, but it’s only the beginning. The real challenge now is helping enterprises secure AI agents in the real world, with better identity, visibility, governance, and even hardware security. Their comments dig into what the announcement means beyond the headlines and where organizations still have the most work to do.

John Strand, Black Hills (https://www.linkedin.com/in/john-strand-a1b4b62)

“I think we’re going to see a lot more stories like this because there’s real anxiety in the AI industry right now. Part of it is financial. Many organizations are struggling to demonstrate a meaningful return on investment from their AI initiatives. The other part is security. As researchers continue to show AI systems escaping their intended boundaries or interacting with other systems in unexpected ways, concerns about AI safety are growing. That’s why you’re seeing so many new AI security initiatives. In many cases, they’re trying to establish industry standards before governments step in with legislation or regulation. Whether those efforts are enough remains to be seen.”

Chuck Sobey, General Chair and Co-founder, Chiplet Summit (https://www.linkedin.com/in/chucksobey)

“As the Open Secure AI Alliance focuses on securing the AI ecosystem, one area that deserves greater attention is the security of the underlying hardware powering AI infrastructure. Software security assumes you can trust the silicon it runs on. The coming wave of chiplet-based systems, especially AI accelerators, raises the stakes: more suppliers, more integration points, more attack surfaces. Hardware security has to be part of this conversation from the beginning.”

John Carberry, Solution Sleuth, Xcape Inc. (https://www.linkedin.com/in/john-carberry-1418a622a)

“Accelerating autonomous artificial intelligence adoption creates systemic enterprise exposure when organizations deploy intelligent agents without establishing clear identity boundaries or visibility controls. Bringing industry heavyweights together through the Open Secure AI Alliance provides a much-needed collaborative effort to advance secure design patterns and open-source defensive tooling outside of traditional business competition. While vendor collaboration establishes essential baseline standards for this emerging technology, security leaders cannot treat pre-competitive initiatives as a substitute for internal governance. Organizations frequently fall short by granting artificial intelligence agents excessive API permissions and service account privileges without audit logging, opening direct pathways for indirect prompt injection and unauthorized data exfiltration. Security executives must immediately map all artificial intelligence integrations, enforce least-privilege scoping on agent execution frameworks, and treat agent interactions with external systems as untrusted input requiring strict validation.

“Critical Takeaways

  1. Leverage pre-competitive standards: Use open-source security frameworks from industry alliances to standardize threat modeling for artificial intelligence deployments across enterprise environments.
  2. Scope agent permissions tightly: Restrict autonomous artificial intelligence agents using least-privilege access controls, credential isolation, and strict API scope boundaries.
  3. Treat agent inputs as untrusted: Implement rigorous input validation and comprehensive audit logging for all automated workflows to neutralize indirect prompt injection risks.

“Industry alliances can build safe frameworks outside of business competition, but your security team still has to enforce them inside your corporate network.”

Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)

“Organizations built identity and access management for people running predictable software. AI agents are neither, and they skip the entire stack.

“Most security teams can’t tell you how many agents are running in their environment right now, or what those agents can access. Developers launch them, ops teams wire them into workflows, and SaaS vendors embed them in products without security ever seeing a ticket. Each agent holds credentials to production systems and behaves non-deterministically, meaning the same agent running the same task can take a different path every time.

“The Hugging Face breach is proof this gap has consequences. OpenAI tested its models’ exploitation capabilities, and those models breached a real company. If OpenAI couldn’t predict what their own models would do in a controlled evaluation, no enterprise should assume they can predict agent behavior in production. When Hugging Face reached for closed frontier models to analyze the attack, safety guardrails blocked them from examining exploit payloads. They ran GLM 5.2, a Chinese open-weight model, on their own infrastructure instead. I’ve hit the same wall. I still run Claude Opus 4.6 for security work because newer models increasingly refuse to process real attack artifacts. If Washington restricts Chinese open-weight models without ensuring equivalent open alternatives from U.S. labs, defenders lose the tool that actually worked when closed models wouldn’t.

“The Open Secure AI Alliance is right that defenders need open, inspectable models they can run on their own infrastructure. HPE’s SPIFFE/SPIRE contribution to the alliance addresses agent identity directly, giving agents cryptographically verifiable identities. Security leaders should be watching that work. Identity for agents is what makes the rest of the defensive stack enforceable.”

Seemant Sehgal, BreachLock (https://www.linkedin.com/in/s-sehgal)

“The gap in most AI deployments right now is not in the model itself. Organizations are running AI agents with access to internal data, external APIs, and automated decision-making workflows, and they have not mapped what those agents can reach or how an adversary would move through that access. Alliance frameworks that standardize how AI systems are evaluated for risk are useful, but the organizations that will benefit from them are the ones that already know what their agents are doing at runtime. Most do not.

SafeBreach and Anvilogic Partner to Connect Attack Simulation, Detection Engineering and Continuous Validation in One AI-Powered, Closed-Loop Workflow

Posted in Commentary with tags on July 28, 2026 by itnerd

SafeBreach today announced a strategic integration with Anvilogic, the leading Agentic SecOps platform. The two-way integration utilizes the real-world attack simulation results from the SafeBreach CTEM Platform to reveal where security controls fall short, while the Anvilogic platform transforms those findings into deployable, tuned detections and hands off to the customer’s existing response tools to close the loop. SafeBreach then continuously validates those detections against the same attack simulations, creating a closed-loop workflow that helps security teams identify security gaps, improve detection quality, and measurably reduce operational risk.

As security teams accelerate their adoption of AI-powered SOC capabilities, the challenge they face has evolved: it’s no longer just about creating detections faster, but rather ensuring those detections are working and effective against real threats. Up to now, attack simulations surfaced gaps, detections were built separately, and validation was time-consuming and manual. In an AI-driven SOC where detections are autonomously generated and deployed, the lack of a validation process capable of keeping pace creates a critical blind spot, leading to a security strategy that is based on assumptions rather than proof.

The SafeBreach–Anvilogic integration addresses this challenge directly by providing a closed-loop workflow that seamlessly connects attack simulation, detection engineering, and continuous validation.

How the Integration Works

  1. Validate: The SafeBreach CTEM Platform validates an organization’s production security controls against 33,000+ real attack methods to identify critical gaps in control coverage.
  2. Trigger: The validated findings automatically trigger the Anvilogic Continuous Detection Validation Blueprint—Anvilogic’s agentic automation layer that converts a SafeBreach finding into a high-fidelity production detection.
  3. Review & Confirm Coverage: The Blueprint reviews the finding against Anvilogic’s library of thousands of MITRE ATT&CK–mapped detections, checks which already fire on the technique, and builds new coverage only where a real gap exists.
  4. Create, Test & Tune: Where a gap is real, the Blueprint authors a new detection, tests it, and tunes it against the environment—across an organization’s SIEM, data lake, or a hybrid stack.
  5. Deploy with Approval: The tuned detection is prepared for production behind a human approval gate, so nothing proceeds without an explicit sign-off.
  6. Re-Validate & Close the Loop: The SafeBreach CTEM Platform re-runs the simulations to confirm the control now catches the attacks.

The loop runs daily, providing continuous board-ready, audit-grade evidence that identified gaps are not only closed, but remain so over time. As a result, security teams experience one unified workflow that accelerates detection maturity and measurably reduces risk with:

  • Coverage that is validated, not assumed: Proven against 33,000+ real-world attack methods within the SafeBreach CTEM Platform with an evidence trail tying each gap to its deployed fix.
  • Gaps that are closed, not queued: Findings no longer die in a backlog; the loop runs daily and converts validated gaps into deployed detections.
  • Teams that scale without staffing: The remediation work that previously required additional detection engineers runs as a Blueprint, expanding coverage without adding headcount.

Visit SafeBreach booth #1364 at Black Hat USA from August 1-6, where SafeBreach and Anvilogic product experts will be on hand to demonstrate this integration. Schedule a time to connect at https://www.safebreach.com/black-hat-usa-2026/