FBI, Secret Service warn FortiBleed campaign has compromised 86,000+ devices

Posted in Commentary with tags , on October 7, 2026 by itnerd

The FBI and U.S. Secret Service are warning that the ongoing FortiBleed credential-compromise campaign has affected more than 86,644 Fortinet devices across 194 countries, according to a new joint cybersecurity advisory.

The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways, using credentials obtained from previous Fortinet leaks and infostealer logs along with password spraying and credential stuffing. Stolen password hashes are sent to a distributed GPU cluster where attackers attempt to crack them and convert the data into usable credentials.

After gaining access, attackers create new administrative accounts to maintain persistence and can move further into victim networks by enumerating Active Directory accounts and searching for privileged credentials. In some incidents, attackers have changed passwords or deleted legitimate accounts, locking organizations out of their own Fortinet devices and requiring remediation beyond standard patching and password resets.

The FBI and Secret Service said the operation ultimately packages and sells working VPN configurations and access to compromised networks to other threat actors. The FortiBleed attack chain has already been observed providing initial access to ransomware affiliates, including INC/Lynx and Payload ransomware.

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

“FortiBleed is a good example of why organizations can’t treat perimeter security appliances as ‘set it and forget it’ infrastructure. Firewalls and VPN gateways are high-value targets because compromising one can give an attacker a trusted entry point into the network.

“What makes this campaign particularly concerning is that organizations may be dealing with more than a vulnerability that needs to be patched. If attackers have valid credentials or have already created new administrative accounts, applying an update and changing a password may not remove them from the environment. Defenders need to assume that previously exposed devices could already be compromised and investigate accordingly.

“Organizations should review administrative accounts, authentication logs and configuration changes, rotate potentially exposed credentials, enforce MFA wherever possible, restrict management interfaces from the public internet and look for evidence of lateral movement. If privileged credentials were accessible from the compromised environment, those credentials should also be considered potentially exposed.

“The ransomware connection also shows how mature the cybercrime ecosystem has become. The people gaining access don’t necessarily have to be the ones deploying ransomware. Initial access itself has value, and compromised VPN access can be packaged and sold to another criminal group that takes the attack from there.”

John Strand, Owner, Black Hills Information Security, Inc.:

“The most interesting thing to me about this particular attack is that some of these attackers are actually selling access to compromised networks to other threat actors. It’s basically malicious hacking as a service. And that concerns me because this isn’t necessarily a ransomware-style attack. You’re getting much closer to what we traditionally think of as an advanced persistent threat, and the persistence is what scares me. I’m not nearly as worried about an attacker who gets into an organization, locks everything down, and announces their presence. I’m terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access.”

If you haven’t addressed FortiBleed, you should have an incentive to do it now. If you have addressed FortiBleed, congratulations. Now do again as it is better to be safe than sorry.

60% of critical infrastructure organizations hit by significant cyber incidents

Posted in Commentary with tags on October 7, 2026 by itnerd

Nearly 60% of critical infrastructure organizations experienced a significant cybersecurity incident in the past year, while widespread gaps in OT visibility, legacy infrastructure and IT/OT integration continue to complicate security, according to Palo Alto Networks’ new State of Critical Infrastructure Cybersecurity Report.

The report surveyed more than 1,600 security leaders across manufacturing, healthcare and life sciences, energy and utilities, transportation, and government and public sector organizations in 11 countries. Among the findings:

  • 68% do not have complete, real-time visibility into all assets connected to their OT networks.
  • An average of 23% of connected OT assets are unmanaged or difficult to monitor.
  • 42% identify legacy, unpatchable OT assets as their biggest cybersecurity risk.
  • 59% experienced a significant security breach in the past year, with one in five affected multiple times.
  • Among organizations experiencing incidents, 50% cited safety concerns, 49% unplanned downtime, 46% production disruption and 46% financial losses.
  • Unplanned downtime costs organizations an average of $288,563 per hour.
  • 74% have not fully integrated their IT and OT security operations.
  • Only 37% have comprehensive OT asset visibility, while 40% have virtual patching or other compensating controls for vulnerable assets.
  • 95% are concerned about Frontier AI-powered attacks targeting critical infrastructure, while 91% expect AI-driven cybersecurity to play a role in defending against them.
  • 84% expect 5G to be widely or extensively adopted within their organizations over the next two to three years.

The report also found that organizations use an average of seven disparate security systems and tools. Fifty-nine percent said multiple systems create operational complexity, 56% reported higher operating costs and 41% said tool sprawl contributes to delayed incident response.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Critical infrastructure security is constrained by assets that cannot be taken offline long enough to patch, while geopolitical tensions and expanding connectivity increase pressure on providers already working with limited resources.

“Palo Alto Networks’ 2026 State of Critical Infrastructure Cybersecurity Report connects that pressure to real operational consequences, including safety concerns, unplanned downtime, production disruption, and financial losses. The common thread is incomplete visibility across legacy systems, unmanaged devices, private 5G networks, and other connected assets. Separate IT and OT security teams, along with multiple disconnected tools, make the response slower and harder to coordinate.

“The burden is heavier for utilities, hospitals, manufacturers, transport operators, and government agencies because they cannot treat cybersecurity as a normal software-maintenance exercise. A security team may know that a programmable logic controller (PLC) is vulnerable, but still lack a reliable answer to the question that matters operationally, which pump, production step, or safety process does it control? Without that context, a vulnerability score cannot tell the team what to protect first.

“Time-to-protection is the meaningful measure for unpatchable OT. Passive asset discovery, network segmentation, strict remote access, and virtual patching can block exploitation while engineering teams test a vendor fix and schedule a safe maintenance window.

“AI will compress the attacker’s timeline while defenders are still establishing what a connected asset does, what it controls, and whether it can be safely changed. Constrained headcount makes that gap harder to close. AI can multiply a small team’s reach, but safe use still requires people who understand the model, the network, and the physical process. A facility without that technical talent could turn automation into another unmonitored dependency. For providers facing geopolitical pressure and constrained resources, connecting every alert to the physical process that asset controls is the priority.”

Damon Small, Board of Directors, Xcape, Inc.:

“Operational disruptions averaging nearly $290,000 per hour in downtime highlight the staggering financial risks of operational technology (OT) vulnerabilities. The convergence of OT and IT networks has been underway for nearly three decades, yielding tangible business efficiencies while simultaneously introducing severe cyber threats. Early examples of targeted OT attacks date back to the 2000s and have steadily escalated in frequency and sophistication. Today, legacy and unpatchable devices combined with fragmented security operations leave defenders blind to over two-thirds of their connected environments. Rather than chasing hype around emerging threat vectors, security leaders must prioritize foundational controls: continuous passive network monitoring to establish real-time asset inventories, strict network segmentation to isolate vulnerable systems, and unified identity enforcement across IT and OT boundaries.”

“Critical Takeaways:

  • Unplanned downtime from OT security incidents costs organizations an average of $288,563 per hour.
  • Decades of IT and OT convergence leave 68% of critical infrastructure security leaders without real-time visibility into connected assets.
  • Effective defense requires prioritizing basic controls like network segmentation and passive monitoring over speculative AI threat vectors.

“Buying a seventh security tool will not fix the fact that nobody knows what is plugged into the OT network.”

John Strand, Owner, Black Hills Information Security, Inc.:

“This is unfortunately what we should expect when we look at a lot of these organizations. What you’re seeing is technological spread. Organizations have a tremendous amount of legacy technology that can’t simply be ripped out and replaced. At the same time, newer and more secure technologies are being introduced, but that doesn’t mean they’re evenly distributed across the organization. There’s that great quote, ‘The future is already here. It’s just not evenly distributed.’ I think this story is a perfect example of that.

“What worries me even more is the coming age of AI, where people can create applications and SaaS services incredibly quickly without necessarily knowing how to code. I believe the technical complexity of these environments is going to increase, not decrease. And complexity is the enemy of computer security. Security teams are going to be dealing with new technologies being deployed incredibly quickly, legacy technologies that were never properly secured, and constant pressure to get things into production as fast as possible. All of those problems become even more pronounced when you get into SCADA, ICS, and OT environments.”

Critical infrastructure should be treated as critical. Which means that any and all measures should be taken to secure it 100% of the time. Otherwise adversaries will pwn it 100% of the time.

2025 Oracle Health breach compromised data of nearly 20 million people 

Posted in Commentary with tags on October 7, 2026 by itnerd

A 2025 cyberattack targeting Oracle’s healthcare business compromised personal and medical information belonging to nearly 20 million people, including approximately 3 million Texans, according to newly released information from the Texas attorney general, Bloomberg reports.

The stolen information included Social Security numbers, addresses and medical information. Healthcare providers affected by the incident have said compromised records could also include patient names, diagnoses, medications, doctors and test results. Oracle initially notified customers of the breach in March 2025 but did not disclose how many patients were affected.

Attackers gained access to older servers belonging to Cerner, the electronic health records company Oracle acquired for $28 billion in 2022. Oracle told customers that the affected data had not yet been migrated from those legacy systems to Oracle’s cloud infrastructure.

The attack occurred sometime after January 22, 2025 and affected numerous Oracle healthcare customers, including hospitals and health systems. The FBI investigated the breach and attempts by the hackers to extort affected healthcare organizations. The newly disclosed figure provides the first indication of the nationwide scale of the incident.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“A cloud migration can increase breach risk when the migration server still holds the records attackers want. Oracle Health told affected customers in March 2025 that attackers had used compromised customer credentials to access older Cerner servers after January 22 and copy patient data to a remote location.

“Those servers sat outside Oracle Cloud because the data had not yet been migrated. Oracle acquired Cerner for $28 billion in 2022, but moving the destination did not remove the older copy. That is a data-lifecycle failure.

“I would treat every migration server holding patient data as a live clinical system until its access is separately controlled, its activity is logged, and its final copy is deleted. “Legacy” describes ownership and age. It does not describe the value of the data.

“The scale makes the lesson harder to ignore. Information belonging to nearly 20 million people was compromised, including about 3 million Texans. Hospitals also faced extortion attempts connected to the stolen records.

“Healthcare providers will keep moving records between vendors, platforms, and acquisition-era systems. If temporary migration environments receive weaker controls than production systems, attackers will target the copy that organizations have already stopped watching.”

Damon Small, Board of Directors, Xcape, Inc.:

“Exfiltrating nearly 20 million patient records proves that technical debt in healthcare M&A presents immediate, catastrophic operational liability. When Oracle acquired Cerner for $28 billion, inherited legacy systems remained unmigrated, leaving Social Security numbers and medical histories exposed to credential compromise and cyber extortion. The market reality directly refutes Larry Ellison’s bold assertion that “Oracle is unhackable.” Healthcare IT data is just as critical as the patients themselves, meaning software vendors and healthcare providers must treat electronic health records (EHR) as life-safety biomedical devices rather than basic back-office IT assets. Compromised EHR data unleashes severe risks, including long-term identity theft, medical insurance fraud, and targeted extortion. Security leadership must mandate multi-factor authentication, rigid network isolation, and deep logging across all unmigrated environments while treating legacy infrastructure as high-risk untrusted enclaves.”

“Critical Takeaways:

  • Classify EHR systems as mission-critical biomedical devices rather than standard back-office IT infrastructure.
  • Treat legacy systems inherited during M&A as untrusted enclaves with enforced multi-factor authentication, zero-trust network isolation, and centralized logging.
  • Prepare incident response strategies for high-impact post-exfiltration risks, including patient extortion, insurance fraud, and identity theft.

“It turns out “unhackable” legacy servers are surprisingly easy to hack.”

John Strand, Owner, Black Hills Information Security, Inc.:

“This news story should serve as a warning for anybody looking to acquire another company. Security due diligence absolutely needs to be part of the mergers and acquisitions process. It’s something we spend a lot of time doing for our customers. I don’t like the fact that Oracle is kind of hand-waving this away by saying these were legacy systems that hadn’t been migrated to their secure cloud services yet. They’re still responsible. The moment you acquire a company, you become responsible for all aspects of that company, and that includes its security vulnerabilities.”

I would love to say that Oracle learned its lesson from this. But the cynic in me says not so much. And that’s a shame.

Wikimedia’s finds that OpenAI rogue agents paid a visit

Posted in Commentary with tags , on October 7, 2026 by itnerd

Wikimedia says agents it believes were operated by OpenAI made unapproved edits to its wikis, tried to turn its citation tool and Etherpad into proxies for fetching outside data, and sent millions of automated requests.

The Wikimedia Foundation said it conducted its own investigation and found activity on its platforms that it believes came from agents operated by OpenAI. The unauthorized bots made edits to Wikimedia wikis, unsuccessfully attempted to exploit a public note-taking tool, and generated heavy traffic that may have contributed to a partial outage of one of its data services.

Wikimedia said it found no evidence that its systems or data were compromised. Still, the nonprofit said it was concerned about what could have happened, the difficulty of investigating these incidents, and “the growing risks of agentic AI activity.”

Bri Frost, Director of Product Management, Cloud Range Said This:

“When an AI agent hits a wall, the real question is whether it stops or starts improvising. Here, agents appear to have tried turning a citation tool and a note-taking service into proxies, which is exactly the kind of behavior organizations need to plan for as agents gain autonomy. An agent doesn’t need bad intent to create risk. It just needs a goal, access and no clear sense of where its boundaries are. That risk grows when the person giving instructions doesn’t know to set those boundaries. Every day, inexperienced users hand agents open-ended tasks without telling them when to ask questions, pause or get approval. Before giving an agent credentials or tools, teams should test it in a realistic environment, including with vague or poorly written prompts. Does it stay within its permissions? Does it try to work around restrictions? Does it escalate to a human when a task pulls it outside its lane? If you can’t answer those questions, the agent isn’t ready for that level of autonomy.”

OpenAI really needs to clean this up and fast. The problem is that Sam Altman and company does not seem to care. That needs to change. Quickly.

FortiBleed Is Still Active, Locking Organizations Out 

Posted in Commentary with tags on October 7, 2026 by itnerd

Yesterday, the FBI and the U.S. Secret Service published a joint Cybersecurity Advisory on FortiBleed, the active global credential compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.

Today, the SOCRadar Threat Research Unit, which first documented FortiBleed in June, published a new report to help organizations defend or triage the Fortinet exposure. It adds field-response detail that changes how you should scope, hunt and remediate. It also includes what is operationally relevant right now: what has changed since the earlier reporting, the indicators to hunt on today, and the actions that actually close the gap.

Here’s the new report: FortiBleed Is Still Active, Locking Organizations Out, 

Goldman Sachs and Man Group exposed in EY data breach 

Posted in Commentary with tags on October 7, 2026 by itnerd

Clients of Goldman Sachs’ wealth management division and UK-listed hedge fund Man Group are among the victims (paywall) of a major data breach at Big Four accounting firm EY, according to notifications sent out in recent weeks.

In other words, this is bad.

Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech: 

“This breach underlines how modern businesses rely on multiple layers of third-party software over which they have minimal oversight. Goldman Sachs didn’t get hacked. A vendor to a vendor to Goldman Sachs got hacked. Goldman Sachs entrusts client data to both of those vendors but has little to no oversight of either’s security. But clients entrusted Goldman Sachs with their data, not the vendors. Businesses are responsible for the security failures of vendors that they entrust with private data.”

Third party hacks are a thing. So if you assume that you’re only secure as the people you work with, you need to audit those people to ensure that you are secure.

Lumen Black Lotus Labs: Attacker running malware with a poem 

Posted in Commentary with tags on October 7, 2026 by itnerd

Lumen’s threat intelligence team, Black Lotus Labs, published new research on a campaign that breaks into exposed enterprise AI tools and uses their powerful hardware (i.e., data center GPUs) to mine cryptocurrency.

The campaign is proof of an attack tested in research: adversarial poetry. In this campaign, the attacker controls a malware campaign with poetry.

To steer infected machines, the attacker posted a poem on GitHub. The malware pulls out four specific words, converts each into a number, and gets the address of the attacker’s control server. When that server is blocked, the attacker simply edits the poem. It has been rewritten 11 times since April.

Quick details:

  • Who was hit: More than 2,000 servers, mostly in the U.S. and Western Europe.
  • Hijacked infrastructure: The attacker rented no servers. They used hijacked home and office routers instead.
  • Victims become recruiters: Each infected server scans the internet for the next victim.

Why it matters: Behind the quirky method is a trend. AI systems are now a target in their own right. Compounding this, companies are putting AI tools online faster than they’re securing them. This attacker is profiting from that gap and is already testing new ways to break into more systems.

Read more here: https://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malware

AI agents are being given far broader permissions than they need, Exclaimer security director warns

Posted in Commentary with tags on October 7, 2026 by itnerd

Exclaimer called on organizations to reinforce their cybersecurity practices as AI reshapes the business communications threat landscape. The security challenge is no longer just whether people are using AI, it is knowing what these tools can access, what agents are allowed to act on and who is accountable for the outcome. Cybersecurity Awareness Month is a reminder for organizations to confront these uncomfortable questions.

Exclaimer’s July 2026 research shows how common AI has become in everyday communication. The nationally representative OnePoll study of 1,000 US adults found that 65% used AI in some aspect of their communications, while 36% had questioned whether a message they received was genuine and 14% did not trust emails from external companies at all. The published findings are available here.

Karl Bagci, Director of IT and Information Security at Exclaimer said this:

“Cybersecurity Awareness Month is a useful reminder that AI is changing the speed of cybersecurity. Attackers can increasingly use automation to move faster than people and traditional defensive processes can respond, which means security teams must work out where they can safely automate detection and response without removing human judgment from decisions that still need context.”

“We can’t just make everything instant; that creates its own risk because an AI system can make the wrong decision, block the wrong thing, or take an action without understanding the wider business context. The challenge for security teams is to get as close as possible to the speed of the attacker while being very deliberate about where a human still needs to be in the loop. Good security automation should remove unnecessary delay, not remove accountability.”

“One of the biggest cybersecurity mistakes organizations can make with AI is to assume that saying no makes the risk disappear. Employees want to use these tools because they help them work faster, and if the business doesn’t give them a safe route, some will use personal accounts, devices, or unapproved services instead. The organization then has less visibility, not less risk.”

“A better approach is to give people approved tools, clear policies around what data can be used, and practical controls that make the safe option the easiest option. The same discipline needs to extend to AI agents. We are already seeing agents given far broader permissions than they need simply because it makes development easier. Cybersecurity Awareness Month should be a prompt to ask not only which AI tools people are using, but what those systems have been allowed to access and what they can do on the organization’s behalf.”

New Comcast Report Signals That Security Breaches Happen Now in the Thousands Every Second Due to AI

Posted in Commentary with tags on October 7, 2026 by itnerd

A massive new data set dropped today that shifts everything we know about digital security. The Comcast Business 2026 Cybersecurity Threat Report analyzed 79.3 billion events and revealed a staggering reality: automated AI tools have compressed the window between corporate exposure and network breach to almost zero. Security teams are now fighting off 2,514 events every single second.

The report highlights a critical shift: hackers aren’t breaking into companies anymore—they are simply buying stolen session credentials on the dark web for under $1,000 and logging right past multi-factor authentication (MFA).

You can get the report here: 2026 Comcast Business Cybersecurity Threat Report  | Comcast Business

AI order-to-cash platform Stuut raises $52.5M Series B after unlocking 40% more cash for enterprises

Posted in Commentary with tags on October 7, 2026 by itnerd

Businesses worldwide have $16 trillion locked up in unpaid receivables. Stuut, the AI platform that runs order-to-cash for the some of the world’s leading enterprises, is going after it. 

In a world where all finance software often looks and behaves the same, Stuut offers customers the ability to automate the vast majority of their work. It runs the entire order-to-cash process, moving dollars through collections, cash application, payments, disputes, and deductions. Stuut’s customers are freeing up to 40% more cash flow, with a 47% reduction in DSO. 

Now, just ten months after its Series A and amid overwhelming demand, the company is announcing a $52.5 million Series B led by Insight Partners, with participation from Andreessen Horowitz, M12, Microsoft’s Venture Fund, and Activant, bringing its total funding to $93 million.

The problem Stuut is solving

Most customers want to pay. But a missing PO, bad order data, or an invoice sent to the wrong person triggers weeks of emails, portal work, and internal chasing. By the time an invoice is overdue, one small error can drag sales, finance, operations, and multiple systems into the mess. At enterprise scale, getting paid turns into millions of tiny investigations consuming thousands of hours. 

The cost can be enormous: broken order-to-cash processes can wipe out as much as 5% of a company’s revenue, as much as $1 trillion a year across the Fortune 500 alone. 

How Stuut works 

A missing PO can snowball into a rejected invoice, then a portal submission, then a short-pay or deduction. Stuut follows that entire chain across thousands of invoices at once, reaching customers worldwide via SMS, email, and call, logging into AP portals, reconciling cash, and taking the next action without losing context.

Every interaction makes Stuut harder to replace. It builds a living memory of each customer: how they pay, which portals they use, what breaks and how it gets fixed. That memory compounds until Stuut disappears into the background. The work keeps moving without finance teams having to manage it. When they want visibility, they can ask what happened, why it happened and exactly what Stuut did to resolve it.

This is already happening at scale. 81.7% of outbound collections activity runs without human involvement, while 95% of incoming payments are matched automatically. Stuut now extends into credit and order management, catching issues upstream before they turn into payment problems.

Importantly, enterprises don’t have to change how they work. Stuut instantly integrates into any ERP, bank account, CRM, and payment system, going live in days. It’s configured to each company’s existing processes and controls, with every action auditable and any behavior change requiring approval.

Stuut is also partnering with leading firms across working capital to give enterprises a faster way to buy, deploy and scale the platform, including Fiserv, EY, Altamont, HIG, and more. 

Traction 

Today, Stuut is used by over 150 customers, including Fortune 50 and Fortune 500 companies. Its customer base has grown 5x since last year and more than $3 billion has moved through the platform, with customers aggressively pulling Stuut across more of the order-to-cash lifecycle. 

Some of the world’s largest companies are seeing similar results. Bishop Lifting has rolled Stuut across 45 branches for collections, disputes and cash application, cutting overdue receivables by 35%, unlocking $3 million in working capital and increasing accounts managed per employee by 50%. Honeywell runs Stuut on top of legacy SAP to reach the long tail of customer accounts and is expanding the platform into quote-to-cash. At ZoomInfo, Stuut has collected $21.2 million and reduced time to first touch by more than 90%.

Why this matters now

The work of getting paid is getting harder to do. Finance teams are handling more customers, more transactions and more systems, while more than 300,000 accountants have left the profession since 2019. And for all the software built around order-to-cash, most of the actual work still falls to people. US businesses are carrying $7.2 trillion in trade receivables and every additional day of DSO leaves roughly $150 billion tied up. DSO is closely watched by boards and, at some companies, tied directly to CFO compensation. Now that software can actually execute the work, rather than just organize it, order-to-cash is becoming one of the highest-value deployments of AI.

Looking ahead

With the company growing over 90% quarter over quarter, Stuut will use this funding to meet overwhelming customer demand and expand deeper into the financial infrastructure around every transaction, from credit and lending to the movement of funds. The long-term ambition is much bigger: make selling radically easier for some of the world’s largest enterprises. Stuut wants to carry every transaction from the moment a company decides to sell something, through every decision, document and payment in between, until the cash is in the bank.