Edinburgh Napier and Approov team up on smartphone security innovation

Posted in Commentary with tags on September 25, 2026 by itnerd

A new partnership between Edinburgh Napier University and mobile cybersecurity firm Approov Limited will aim to improve smartphone security.

The Edinburgh-based company has agreed a Knowledge Transfer Partnership (KTP) with ENU, which will include the recruitment of two cyber security researchers, co-funded by Innovate UK.

Over the course of 30 months, Approov and Edinburgh Napier will work together to create innovative defence mechanisms and an offensive test bed – known in cyber security as ‘blue team’ and ‘red team’. 

The project, which received the highest rating in Innovate UK’s assessment for this funding round, will involve the ENU-hosted Scottish Centre of Excellence in Digital Trust and Distributed Ledger Technology.

It builds on Edinburgh Napier’s strong record in cyber security and digital trust technology. It has been recognised by the UK’s National Cyber Security Centre and Department for Science, Innovation and Technology (DSIT) as an Academic Centre of Excellence in Cyber Security Education (ACE-CSE) – and was the starting point for several successful cybersecurity spin out companies.

Background:

Edinburg Napier holds early accreditation from the National Cyber Security Centre (NCSC), is recognized as a leader in cyber skills and training. It’s globally ranked in Computer Science and Electrical and Electronic Engineering by U.S. News & World Report, and the UK’s Research Excellence Framework (REF) ranked Edinburgh Napier as the top modern university in Scotland for both research power and research impact, with nearly 70% of evaluated research deemed world-leading or internationally excellent.

The CISA releases election security plan 40 days before midterms

Posted in Commentary with tags on September 25, 2026 by itnerd

The CISA released its 2026 Election Infrastructure Security Plan 40 days before the November midterm elections, outlining cyber and physical threats facing election systems and federal resources available to state and local election officials.

The plan identifies potential threats including cyberattacks against voter registration databases, election networks and other systems, as well as physical threats against election facilities and personnel. It recommends measures including vulnerability scanning, risk assessments, incident response planning, information sharing and the use of auditable paper ballots.

CISA also designated its 10 regional directors as Election Security Advisors responsible for connecting state and local officials with federal cybersecurity resources. The plan comes after staffing and program reductions affected CISA’s election security operations, with some state election officials raising concerns about reduced federal support ahead of the midterms.

Ted Miracco, CEO, Approov:

“CISA’s new 2026 Election Infrastructure Security Plan is right to insist on paper ballots and hand audits. But it never once mentions mobile devices, apps or APIs, which is a strange gap given how much of American voting now runs through them.

“Most US jurisdictions check voters in on electronic poll books, and the most widely used one runs on Apple iPads. Forty-two states and D.C. let people register online, and millions of voters track their mail ballots by text message.

“Bangladesh, which went to the polls in February, took a clearer-eyed approach. Its Election Commission built a mobile app that registered more than 450,000 overseas voters and let them follow their ballots. Then it had every one of them mark a paper ballot and mail it home. The same commission had already scrapped electronic voting machines for all future elections. That is the right design: phones for access and tracking, paper for the vote itself, and serious security for the digital layer in between. Nobody can hack a paper ballot from abroad. They can hijack the phone number that gets a county clerk into the voter rolls. America already has the paper half. What it lacks is a federal plan that treats the phone in a voter’s pocket, and in an election official’s hand, as election infrastructure. While the ballot itself can stay analogue, the threat model cannot.”

Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security:

“My firsthand work as an offensive security tester has taught me that election security extends beyond voting equipment to the people, infrastructure, vendors, and processes supporting elections. A plan or scan is a starting point; the safeguards need to be tested in practice.”

Cyber and physical threats are clearly present when it comes to the midterms. And I am glad that someone is securing them from being tampered with. I hope that true with any threat that comes along.

Guest Post: Why are the FBI hackers so obsessed with their reputation? 

Posted in Commentary with tags on September 25, 2026 by itnerd

By Stefanie Schappert

For most ransomware and extortion gangs, the end goal has always been pretty simple: money.

Steal enough sensitive data, threaten to leak it, and hope the victim decides paying millions of dollars is better than dealing with the fallout.

But what happens when money is no longer the ransom?

This week, the notorious ShinyHunters hacker group announced it had breached multiple FBI systems, claiming it made off with sensitive data belonging to “almost all” FBI agents, employees, and even job applicants.

The FBI has said it is investigating the alleged breach.

The thing is, in this case, the hackers aren’t asking the FBI for millions of dollars – they’re asking the FBI to take back what the group says are “false allegations” about how they operate. 

ShinyHunters gave the FBI seven days to remove or correct statements it made in a May cyber advisory that the group says falsely accused it of exaggerating hacking claims, threatening victims and their families, engaging in swatting, and falsely claiming to possess compromising material. 

Seemingly insulted by the suggestion, ShinyHunters also took the time to “unequivocally” declare they are “NOT SEXTORTIONISTS” and “unequivocally” unrelated to the nihilistic hacking collective known as The Com.

The hackers also “unequivocally” (they used the word unequivocally a lot) insist the attack has nothing to do with money.

So why would a cybercriminal group go to such extraordinary lengths to defend its reputation?

Because in the world of cyber extortion, reputation is just another form of currency.

Honor among thieves

Extortion only works if the victim believes the threat.

If hackers threaten to dump sensitive information if a victim refuses to pay, there has to be some reason for that company to believe they will. 


If companies begin to suspect a hacker group is bluffing, the threat loses its power, the ransomware gang loses leverage over its victims, and the well runs dry, so to speak.

That’s why an FBI warning suggesting ShinyHunters may exaggerate its claims isn’t simply an insult. 

From the hackers’ perspective, it potentially damages the very credibility their business model depends on.

And ShinyHunters isn’t the first cybercrime group I’ve seen fiercely protective of its public image.

Last year, another fine group of extortionists – known as the Qilin gang – contacted my newsroom after taking issue with how I characterized the ransomware group in an article, politely requesting I correct it. 

Rather than get on the bad side of one of the most active gangs for nearly two years running, I kindly obliged. 

And it appears ShinyHunters has joined the quest, publicly taking issue with how journalists are covering the FBI story, in an obvious attempt to control the narrative.  

ShinyHunters also slammed journalists for mishandling the proof samples it so graciously provided, essentially “ruining the experience for everyone.” 

Citing the inappropriate sharing of highly sensitive data (yes, the irony is not lost here), the hackers – who clearly have a reputation to uphold – simply decided they would no longer engage with media for this faux pas. 

Cash is king – or is it?

For organizations negotiating with these groups, this raises a much bigger question.

As hackers accumulate increasingly sensitive information capable of destroying careers, exposing trade secrets, or putting people’s physical safety at risk, organizations may face demands that have nothing to do with money.

Think of all the highly sensitive data out there potentially at risk.  

Medical records, trade secrets, proprietary technology, private communications, customer databases, information about executives – or, in the FBI’s case, home addresses, phone numbers, family information, and other personal details of highly specialized federal agents.

Furthermore, with ransomware attacks, the public may eventually learn that an organization was breached, but rarely sees everything that happens behind the scenes: the negotiations, whether a ransom is paid, or how much.

In the past few years at least, we’ve become accustomed to hackers demanding tens of millions of dollars from their victims in exchange for stolen data.

But stolen information, as we’ve now witnessed, can be leveraged for much more than money, and the more damaging the information, the greater the leverage. 

From a simple retraction or public statement to a forced change in corporate behavior – or potentially a demand we haven’t even seen or thought of yet – many cyber insiders believe the stakes are evolving. 

The question we must ask isn’t simply how much a victim is willing to pay to protect its data, but what else it would be willing to do to protect it.

ABOUT THE EXPERT

Stefanie Schappert is a Senior Journalist at Cybernews covering cybersecurity, AI, national security, cyber policy, critical infrastructure, data privacy, and the human impact of technology. Based in New York, she is the first American journalist at Cybernews and a broadcast news veteran previously at Fox News, NY1 News, and Verizon FiOS 1. She holds a Master’s degree in Cybersecurity and is ISC2 Certified in Cybersecurity (CC). A guest commentator on TV, radio, and podcasts, including CBS News, iHeartMedia, and KTLA, Schappert explores how technology and cyber risk shape society, from ransomware attacks and hacker groups to emerging technologies and digital policy. She has been published in Fortune and cited by the US Senate, FCC, HHS, Henry Jackson Society, academic institutions, and other leading technology publications.

TELUS brings Toy Story 5 to life in select GTA stores

Posted in Commentary with tags on September 25, 2026 by itnerd

Toy Story 5 is gearing up for its highly anticipated release on Disney+, and TELUS is celebrating with a special in-store activation at five locations in the greater Toronto area. Fans of all ages can step into the world of Woody, Buzz and Jessie and experience the magic of Toy Story 5. While there, they can also discover why TELUS Stream+ — with Disney+, Netflix, and an Amazon Prime membership, all in one bundle — is the ultimate home for family entertainment.

What awaits you in select GTA stores:

  • Family photo ops: Snap a pic at our fun Lilypad photo op, featuring life-size Toy Story 5 props for a frame-worthy family photo.
  • Giveaway: One weekend only (Oct 17–18): Make any purchase in-store and receive a limited-edition Toy Story 5 power bank— available to the first 25 customers per store.
  • Nationwide home cinema contest: Customers across the country can enter into our Ultimate Home Cinema contest at https://www.telus.com/toystory5 and one lucky winner will win a 4K TV, soundbar and 1 year of Stream+ Premium (which includes ad-free Netflix and Disney+ as well as an Amazon Prime membership).
  • Stream+ Benefits: Get your favourite shows all in one subscription with Stream+, and learn how you can save up to 15% compared to subscribing separately. 

Participating Locations:

  • TELUS Toronto Eaton Centre
  • TELUS Square One
  • TELUS Sherway Gardens
  • TELUS Pen Centre
  • TELUS Vaughan Mills

Guest Post: Fortune 500 not so fortunate: Employee credentials leak every 100 seconds

Posted in Commentary with tags on September 25, 2026 by itnerd

Findings from a report from NordLayer, a toggle-ready network security platform for business, reveal that credentials of Fortune 500 employees are being leaked on the dark web at an alarming rate, with the overall number of leaked credentials reaching nearly 10 million. The numbers are accelerating in 2026 — dated infostealer logs from this year show a new Fortune 500 credential appearing on the dark web every 100 seconds.

NordLayer analyzed findings from NordLayer Intelligence by NordStellar, a threat intelligence platform, which revealed that 9.96 million Fortune 500 employees’ credentials were leaked on the dark web. The research found that over 6.6 million unique corporate email addresses were exposed. 

The leaked credential sets analyzed in the research comprise combolists — re-purposed credentials obtained from data breaches and infostealer infections — and dated infostealer logs, the only sets that record when the data was collected. 

Analysis of infostealer logs shows that 130,000 Fortune 500 employee credentials were leaked on the dark web across roughly 147 days in 2026 alone. This amounts to a new Fortune 500 credential surfacing on the dark web every 100 seconds.

“The credential leaks that could be traced down to this year were harvested using infostealer malware,” says Andrius Buinovskis, cybersecurity expert at NordLayer. “Unlike ransomware, which typically targets specific organizations, infostealer campaigns are often more opportunistic, focusing on individual users rather than entire companies. This malware primarily hides within pirated software, gaming applications, fraudulent ads, fake captchas, and phishing emails.”

Almost all credentials harvested from browsers

According to Buinovskis, infostealers scrape data from users’ devices almost immediately after infection, stealing any credentials or credit card details they come across. The browser is their preferred hunting ground for users’ log-in information — of the analyzed 2026 infostealer logs that record a source application, 99% point to browsers.

“Infostealer malware is specifically designed to extract credentials from built-in browser password managers. Because standard browsers store this sensitive data in predictable local directories, it is an easy target for malware,” explains Buinovskis. “The vulnerability of these industry giants proves that even the best corporate defenses can be bypassed by a single employee’s habits. In the face of opportunistic malware, the browser has become the enterprise’s weakest link.”

Desk-heavy industries top infostealer exposure rates

2026 infostealer data analyzed in the research shows that mid-sized Fortune 500 companies record higher infostealer exposure rates than the largest employers. Companies in the mid-sized bands (between 5,000 and 25,000 employees) record the highest median credential leakage rate — 1.27 unique credentials per 1,000 employees — while the largest employers show the lowest rates. The highest per-employee credential leak rates come from mid-sized technology companies, topping out at 42 credentials per 1,000 employees.

By industry, media and entertainment companies show the highest median credential leakage rate at 10.59 per 1,000 employees, followed by telecommunications and technology at around 3. According to Vakaris Noreika, a cybersecurity expert at NordLayer Intelligence, the rates mirror the attack surface these industries expose — sectors where nearly every employee holds a corporate login and saves credentials in a browser present infostealers with more to harvest.

“Many Fortune 500 giants employ vast numbers of frontline staff — whether on factory floors or in retail outlets — who operate without a corporate inbox, naturally lowering the company’s overall credential footprint,” says Vakaris Noreika. “At the opposite end, companies operating in the media and entertainment, telecommunications, and technology industries are almost entirely desk based, meaning nearly every employee is a potential infostealer target — and that exposure accumulates fast.” 

Safeguarding against infostealers

Buinovskis highlights five main measures companies should implement to build an infostealer-resistant cybersecurity strategy. 

  1. Secure the browser. Browsers are the main hunting ground for infostealers, yet consumer-grade browsers often lack robust security measures and the ability to enforce centralized security controls. To reduce the risk of users downloading infostealers, the browser must block malicious websites and prevent users from downloading infected files.
  2. Implement proper password hygiene. “Abandon built-in browser password managers and ensure that employees are not reusing the same passwords for different accounts,” says Buinovskis. “Password reuse can turn a single leak into a total compromise. If an employee uses the same login for every work application, they’re not just losing one password to an infostealer — they’re handing over the keys to every company resource at once.”
  3. Raise employees’ cybersecurity awareness. Cybersecurity is everyone’s responsibility — fostering this mindset is crucial to reduce user error where possible. When an employee understands how a single pirated file or a click on a link in a phishing email can compromise the entire company, it’s easier for them to shift from treating cybersecurity incidents like an IT problem and start seeing them as their own responsibility. 
  4. Monitor the dark web for any company credential leaks. This enables companies to have a heads up as soon as possible, empowering them to quickly implement necessary remediation steps, like flagging compromised accounts, resetting passwords that appeared in the data leak, and keeping a close eye on any anomalies.
  5. Adopt a zero-trust approach to security to reduce the fallout. “A comprehensive cybersecurity strategy is essential to minimize the impact of a data breach,” says Buinovskis. “Instead of automatically trusting users and devices, companies should embrace a zero-trust mindset and treat every login attempt as a potential threat until proven otherwise. By verifying every move, organizations can effectively stop threat actors from infiltrating the network, preventing a simple credential leak from turning into a major security breach.”

Methodology

NordLayer and NordLayer Intelligence by NordStellar analyzed leaked credentials and identified those tied to domains belonging to 2026 Fortune 500 companies, covering 500 companies and 3,692 corporate domains. Subsidiary brands were not included. The research began with 34.86 million raw records, which were deduplicated to 9.96 million unique email and password pairs, counted once per company. Each company was matched to its industry, revenue, and headcount. The leaked sets are made up of combolists and infostealer logs, and only the infostealer logs carry a collection date. About 130,000 of those dated records fall within roughly 147 days of 2026, which works out to about 1 new credential every 100 seconds. Per-employee exposure was calculated by dividing a company’s unique leaked emails by its headcount, then scaled to a rate per 1,000 staff and grouped by company size and by industry for comparison. 

What Canadians Need To Know About Cellphone Searches At The US Border

Posted in Tips with tags on September 25, 2026 by itnerd

Everyone’s cellphones contains years and years of data about you. And that is likely why US Customs And Border Protection is super interested in looking at your cellphone. The fact is that this can tell them a lot about you and whether they should admit you to the US. So in the interest of getting the facts out there, here’s what Canadians need to know about those cellphone searches.

  1. This is not new: Canadians think that cellphone searches are a new issue because of the most recent Trump Administration. But they are not. On they Canadian side of the fence, I wrote about this here and here. And on the US side of the fence (Not to mention other places. More on that shortly) I wrote about it here in reference to laptops. But cellphones can be copied and pasted here as well. And that was 2008 during the Bush/Obama administrations.
  2. They’re looking for social media: US Customs And Border Protection appear to be looking for someone’s social media, text messages and emails. That way they can determine if you are admissible to the US. In other words, if you say something bad about the administration, you can be kept out of the US.
  3. Refusing to hand over your password can end badly for you: A lot of us has password, fingerprint, or face authentication on our phones. And refusing to unlock a phone can make you “inadmissible” to the US because you cannot be properly inspected. And for you specifically, that may last years or forever.
  4. Erasing your phone can end badly for you: If you get the bright idea to erase your phone to stop US Customs And Border Protection from looking at your phone. Don’t. A US citizen got arrested because he wiped his phone at the border. There’s zero reason to believe that non-US citizens can’t be arrested as well.
  5. A burner phone might not even protect you. An idea is to get a burner phone so that it only has country specific info on it and it leaves off anything else. A good idea. But I have heard from a couple in my condo that they were refused entry to the US because having a burner phone implied to US Customs And Border Protection that they had something to hide. And I heard this from other people as well. I looked around and couldn’t find a hard and fast policy on this, but I have to assume that this might be a thing.

So what do you do? Well you have to make a call whether going into or through the US is worth it for you. My wife and I for example have determined a long time ago that it wasn’t worth it. So we won’t be visiting the US anytime soon. Also, you might want to consider that these rules in some way, shape or form might or will be coming to other places as well. Something to keep in mind if you travel frequently.

Databricks Acquires Row Zero

Posted in Commentary with tags on September 24, 2026 by itnerd

Databricks today announced it has acquired Row Zero, the spreadsheet built for humans and agents to work together with data. The acquisition will expand the capabilities of Genie, Databricks’ AI coworker, which helps business teams turn data into trusted answers and actions. Genie can analyze why margins changed or produce a document on sales pipeline opportunities. With Row Zero, Genie will add a familiar spreadsheet interface that business teams can use to explore, model, and collaborate, all on a governed foundation powered by Genie Ontology, Unity Catalog, and Unity Gateway.

Why Bring Secure Governed Spreadsheets to Genie?
After four decades, spreadsheets remain the most broadly used analytics tool in the business world. Their flexibility lets users represent the most sophisticated business models through a set of familiar, well-proven formulas. For this reason, spreadsheets remain the primary engine of business decision-making despite continuous advances in the data and analytics market.

The prevalence of spreadsheets also creates major security and governance challenges for the modern enterprise. Teams have long relied on ungoverned spreadsheet files (“spreadmarts”) to store data or to share between humans and agents. Every data export adds to what is arguably the largest set of ungoverned data pipelines in the enterprise. As companies deploy agents that analyze, model, and act on business data, they can’t afford to have those agents operating on sensitive data of unknown lineage and quality.

Row Zero closes this gap by offering a scalable spreadsheet that connects directly to live, governed data. This means teams can work the way they always have, backed by built-in security and governance. And because they can work directly with the spreadsheet via Row Zero’s agent tools, every agent action remains fully interpretable and auditable by the business teams using the spreadsheet’s syntax and processing model. Row Zero will natively integrate with the Databricks Data + AI Platform, including Genie on web as well as desktop and mobile apps, so teams can easily move from chat to hands-on pivoting, modeling, and visualization.

Flexibility Meets Governance with Row Zero
Finance, operations, sales, and marketing teams have already picked spreadsheets as their tool of choice. Now, Row Zero extends Genie and the Databricks Data + AI Platform within the familiar spreadsheet interface. Key capabilities include:

  • Full compatibility with leading spreadsheets: Designed to complement popular tools such as Microsoft Excel and Google Sheets, Row Zero features the familiar formulas, pivots, and keyboard shortcuts teams already know and love, so users can leverage their skills and assets frictionlessly. 
  • Governed integration into leading data platforms: Row Zero features direct integration into leading data sources. Queries honor each user’s permissions, data auto-refreshes from authoritative live sources, exports can be locked down, and users can write results back, all without stale copies or manual refreshes. Every interaction is auditable, and security controls travel with the data wherever it goes.
  • Lightning-fast performance at scale: Row Zero features a data processing engine that allows business users to work with billions of rows at interactive speeds.

The team behind Row Zero was founded by former AWS and Tableau engineers. They are joining Databricks to continue expanding Genie’s capabilities. Row Zero will be available to all Databricks customers across all major clouds and will continue to feature support for data sources beyond Databricks.

The CISA, FBI warn critical infrastructure operators of third-party ICS risks

Posted in Commentary with tags , on September 24, 2026 by itnerd

The CISA and the FBI warned critical infrastructure operators about cybersecurity and supply chain risks associated with third-party industrial control system (ICS) integrators, urging organizations to limit access to operational environments and apply the principle of least privilege.

The agencies pointed to a 2025 incident in which foreign cyber actors compromised a U.S. industrial automation solutions company serving power utilities and transportation entities. The attackers searched for customer and SCADA information and created nine ZIP files containing approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details and schematics.

CISA and the FBI recommend that operators secure and monitor third-party remote access, minimize internet exposure, inventory hardware and software supplied by integrators, include cybersecurity and supply chain requirements in contracts, and maintain offline backups and manual operating capabilities.

Denis Calderone, CTO, Suzu Labs:

“The ugly side of the outsourced ICS model is the amount of trust that goes along with it. Integrators are a vital part of this ecosystem, especially for smaller operators that could never staff all of that engineering expertise themselves. The integrator needs the keys to the castle. They will be responsible for maintaining network diagrams, device configurations and SCADA details while maintaining a privileged path into the operational environment. CISA and the FBI have now documented exactly why this can be a problem and how this extension of trust directly alters the risk profile of the operator.

“The FBI has not said whether this company was selected because of its role as an integrator, but the post-compromise activity strongly suggests the actors knew what they were after. They searched specifically for ‘customers’ and ‘SCADA’ and staged roughly 800 files of device details and schematics. That is targeted intelligence collection against a company that holds a map of multiple critical infrastructure environments in one place. We have been concerned about how third-party integrators implement operational security for decades. As a professional penetration tester for more than 25 years, I have repeatedly seen integrators or all sorts (ICS, building security systems, environmental controls systems, etc) ignore basic security standards while the client fails to notice because, after all, they outsourced that headache. The more than 100 water systems compromised across the US since July illustrate the consequences of the same kinds of implementation failures. Weak or default passwords, architectures designed without meaningful isolation, little or no monitoring across ICS and SCADA networks, and PLCs placed directly on the internet where anyone can find and attack them. The fact that the integrator became the target itself is of no surprise to me.

“The way to manage this relationship is through the contract and then through audit. Put least privilege, named accounts, unique credentials, MFA, data location and retention, patching, incident notification, access termination and a right to audit into the agreement. Then verify those obligations in the environment. Inventory every component and connection the integrator supplied, inspect the remote-access logs, confirm default credentials are gone, make sure no controller is sitting on the public internet, and prove that your team can cut off the vendor, restore from a local offline backup and operate safely without them. If you cannot see, limit and terminate the integrator’s access, you have outsourced more than engineering.”

John Strand, Owner, Black Hills Information Security:

“Whenever I see stories like this, I keep coming back to the fundamentals. One of my mentors used to say, ‘Good security is nothing more than an inspired application of the fundamentals.’ And that still holds true.

“We talk about reviewing third-party access into systems, but that’s basic access control and authorization. These aren’t new security concepts. What stories like this continue to expose is just how often the fundamentals still aren’t implemented.

“For all the money we’ve spent and all the technology we’ve deployed, there are still legacy systems, legacy network connections, and old pathways into critical environments. We keep seeing the same lessons repeated because organizations haven’t fully addressed the lessons we should have learned years ago.

“The fundamentals are still fundamental. And unfortunately, we’re still failing at them.”

Critical infrastructure has been a target for threat actors forever. Now is the time to secure it. Because if not now, when?

Case Study: Peel Regional Police support mission critical technology with private cellular

Posted in Commentary with tags on September 24, 2026 by itnerd

Highly connected vehicles are creating smarter transport and more intelligent fleets. From logistics to emergency services, vehicles that communicate with each other and their environments in real-time are creating safer roads and more reliable transportation futures.

Ontario’s Peel Regional Police faced the challenge of preparing its 400 frontline cruisers for a future defined by in-car technology. The solution was to create a reliable, more predictable connected fleet using private LTE and Canada’s Public Safety Broadband Network. Below please find out how the connectivity powered features like in-car camera systems and gave them visibility necessary to discover the most heavily patrolled areas. 

Peel Regional Police support mission critical technology with private cellular

Improved reliability with better coverage and lower costs using Ericsson Enterprise Wireless cellular solutions

The Peel Regional Police protects 2.5 million people spread over 538 square kilometres. The force includes 2,200 uniformed members and approximately 400 frontline cruisers. Reliable broadband data is increasingly important in frontline cruisers. Everything from being able to run license plates in real time without human involvement to connected in-vehicle cameras and data and location sharing have become integral to police work. Additionally, cruisers are becoming “mobile offices,” allowing officers to spend more time on patrol and less time in the station.

Peel Regional Police originally relied on public cellular connections for their data needs. But they faced many challenges:

• With a single carrier they lost connectivity when there was an outage.
• They had no control over scheduled downtime for maintenance.
• The cost for cellular data from commercial carriers was becoming prohibitive.
• Is some cases network access was cut off for using excessive amounts of data.

The Solution

Peel Regional Police switched over to a private LTE (cellular) network using Canada’s Public Safety Broadband Network (PSBN) with failover to commercial carriers. Ericsson Cradlepoint dual modem routers are installed in the cruisers, providing automatic and seamless transitions between the private and public networks. The system supports the Axon Fleet 3 in-car camera system as well as the additional data needs of the cruisers.

With Ericsson NetCloud Manager, Peel Regional Police have real-time data on network performance. They can see which areas need improved coverage. NetCloud’s intuitive interface simplifies network management, even from remote locations.

Benefits
The combination of private LTE, Ericsson Cradlepoint cellular routers, and NetCloud Manager provides Peel Regional Police with highly reliable, high-performance connectivity for their entire fleet throughout their jurisdiction, with significant cost savings compared to the previous setup. NetCloud Manager has provided unanticipated benefits as well, such as letting them know where the most heavily patrolled areas are located. Additionally, Peel Regional Police are now prepared for the future, whether it is additional in-car technology, drones, or Next Generation 911. 

“When we compared the Ericsson Enterprise Wireless solution with a competitor, the Ericsson solution seemed to work a lot better, the interface was a lot nicer to work with, and the advanced features and NetCloud Manager were much more intuitive,” said James Felton at Peel Regional Police.

According to Jason Falovo, Vice President and General Manager, Canada at Ericsson Enterprise Wireless Solutions, “Emergency services face the unique challenge of balancing speed, security, and simplicity across highly mobile and mission-critical environments. They require uninterrupted access to critical data, real-time applications, and secure communication, whether in the field or on the road. Ericsson’s solutions provides law enforcement, fire services, EMS, and emergency operations centres with reliable, secure connectivity through public safety networks.” 

Additional resources:

New OT zero-day can take down a database with one packet, and you may not know it’s there 

Posted in Commentary with tags on September 24, 2026 by itnerd

Ridge researchers discovered CVE-2026-42542, a high-severity vulnerability in TDengine, a time-series database used in industrial IoT, manufacturing, energy, connected vehicles and other environments that rely on machine and sensor data.

The basic problem is pretty striking: an unauthenticated attacker can crash a TDengine server with a single malformed packet. No credentials, session or user interaction are required. Ridge has not yet observed exploitation or identified any attack IOCs – however, AI-aided vulnerability discovery and chaining have substantially changed the security equation, and the pace of exploitation is only expected to increase.

As Ridge researcher Yan Zhou puts it: “This is a one-packet, no-password kill switch on a database that quietly runs a lot of critical infrastructure. An attacker doesn’t need credentials, a foothold, or any real skill – just the ability to reach the port. What worries us isn’t sophistication, it’s location.”

The concern is what happens when the database underneath an industrial or IoT environment goes down. Telemetry can stop flowing, monitoring can go dark, and operations teams can lose visibility into what’s happening. There’s also the possibility of using an outage like this to blind defenders before pursuing another objective.

TDengine is also embedded in appliances and other vendor-delivered systems, so organizations may not even realize they have it running. And while a patch is available, industrial environments can be difficult to update quickly because of maintenance windows and vendor support requirements.

Detection is tricky:

This vulnerability produces a crash, not an implant, so there are no file hashes, domains, or C2 addresses to hunt for. The signal is behavioral:

  • Repeated taosd segmentation faults. Check dmesg, the kernel journal, and any core-dump collection. A database process that had been stable and is now segfaulting repeatedly is the primary indicator.
  • Service restart loops. If systemd or a supervisor is cycling taosd, treat it as a potential security event rather than a stability nuisance.
  • Anomalous connections to TCP port 6030 from sources outside your known client inventory – particularly short-lived connections that send a small payload and never establish a session.
  • Unexplained gaps in time-series ingestion. A hole in your own metrics is often the first visible symptom of a downed metrics database.

For teams writing network detection, there is a clean signature anchor: a packet to the RPC port whose declared msgLen is smaller than the fixed message header is never legitimate traffic. That condition alone is a high-fidelity indicator.

Ridge has published the technical details, including the root cause and remediation guidance, in this blog: https://ridgesecurity.ai/blog/one-packet-can-take-down-the-database-behind-industrial-operations-ridge-security-discovers-cve-2026-42542/