AI set to help cyber attackers more than defenders, UK official warns 

Posted in Commentary with tags on September 23, 2026 by itnerd

The UK’s National Cyber Security Centre (NCSC) warned that artificial intelligence is currently positioned to provide greater advantages to cyber attackers than defenders, as attackers face fewer constraints when deploying AI autonomously.

Dave Chismon, the NCSC’s chief technology officer for architecture, said attackers can allow AI agents to operate with broad autonomy, while defenders must account for the risk that autonomous systems could disrupt or damage the networks they are intended to protect. This imbalance could allow AI-enabled attacks to scale faster than automated defenses.

The NCSC has also said AI is rapidly improving offensive capabilities, including vulnerability discovery and exploitation, while defensive uses such as automated mitigation and response carry risks including service disruption, data loss and operational failures.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“The NCSC’s warning that AI may favor attackers needs a harder qualification. Attackers cannot simply give an AI agent broad access and walk away.

“They still have to manage operational security (OPSEC), avoid attribution, control their infrastructure and stop the agent from creating evidence. If it scans the wrong target, contacts a victim or exposes the operator, the consequences can include arrest and prosecution. Criminal liability is a real constraint on offensive autonomy.

“Defenders carry a different risk. A security team whose AI-driven firewall change breaks a VPN may face an outage review, discipline or a lawsuit. The engineer does not usually face an arrest warrant because the agent made a bad change. That makes defensive autonomy a governance problem, not a simple question of whether the technology can act.

“Organizations should reduce that governance and organizational friction by creating pre-approved classes of low-risk, reversible actions, with clear asset ownership, deterministic validation and tested rollback. Changes with broad or uncertain impact should still require human approval. The goal is to remove unnecessary approval friction from routine remediation while keeping consequential actions gated.

“An attacker has to keep an AI agent quiet, scoped and out of the wrong network. A defender has to get an AI agent approved, tested and recoverable. The first is an OPSEC and criminal-liability problem. The second is governance and organizational friction, which defenders can reduce through better ownership, pre-approval and rollback design.”

Lydia Zhang, President & Co-Founder, Ridge Security Technology Inc.:

“The inconvenient truth that Chismon points out in this article has been the reality security teams have been dealing with for years: the imbalance between attackers and defenders in their ability to adopt and operationalize new technologies. AI has obviously widened that gap dramatically.

“But there is also a significant silver lining for defenders: many of the advantages AI gives attackers can also be turned toward defense. AI can help fix vulnerabilities early in the development lifecycle through automated patching, and it can also help remediate vulnerabilities in production.

“We recently demonstrated how an organization can practically combine a security testing tool with a code agent to reduce critical vulnerabilities from 10 to 0 in just four runs.

“So perhaps the challenge is no longer purely technical. The technology is increasingly capable. The bigger challenge is organizational: risk tolerance, processes, accountability, and mindset.”

Donald McFarlane, Board Member, Xcape Inc.:

“Treasury Secretary Scott Bessent articulated a useful starting point this week: accountability. Discussing the Hugging Face incident, he argued that responsibility rests with the humans and organizations deploying these systems, not with an AI agent treated as though it were an independent actor. He has also argued against shielding frontier labs from liability.

“I agree wholeheartedly with that basic principle. More specifically, liability should follow control, causation, intent and duty of care, rather than simply attaching every downstream harm to the person or company who trained the model.

“A malicious user deliberately employing AI to attack someone should bear primary responsibility. An operator that gives an agent powerful credentials, excessive authority and inadequate supervision should be responsible for negligent deployment. Integrators should be accountable for unsafe implementations. Model developers should remain responsible where foreseeable defects, or failures to exercise reasonable care in developing and testing their products, materially contribute to harm.

“That approach also recognizes that responsibility may be shared. Relevant questions would include who controlled what, what risks were reasonably foreseeable, what safeguards were available, and whose acts or omissions materially contributed to the outcome.

“The NCSC is also right that defenders cannot simply mirror attackers. Autonomous defensive action can itself disrupt the systems we are trying to protect, so greater autonomy has to come with governance, bounded authority, recoverability and clear human accountability. Its framework for evaluating potency, scope, criticality, rollout confidence and recoverability is a useful start.

“But I am more optimistic about the defensive side of this equation. AI gives defenders the opportunity to operate at machine speed as well. We should be designing systems that permit progressively greater autonomous action where it can be safely bounded and reversed. And cybersecurity has much to learn from military doctrine and tactics: deception, manoeuvre, shaping the battlespace and channeling adversaries toward ground of the defender’s choosing. AI can make those approaches substantially more powerful.

“AI is an extraordinarily powerful general-purpose technology. We need strong engineering, clearly assigned human accountability, meaningful incident reporting and judicially determinable duties of care. Autonomous software does not somehow break the chain of human responsibility, and we should not create regulatory barriers that only the largest incumbent laboratories can afford.”

John Strand, Owner, Black Hills Information Security:

“Absolutely, AI is going to create more attack opportunities simply because these systems have broad autonomy and more latitude in what they can do, especially when you start looking at open-weight models. But there’s another part of this that I don’t think people fully appreciate. Complexity is the enemy of computer security.

“The more services you have, the more attack surface you create. Even if those services don’t have known vulnerabilities today, AI can rapidly fuzz them, analyze them, and identify weaknesses that attackers may have previously overlooked because finding and exploiting them required significant time and skill.

“AI changes that equation. Vulnerabilities and exploitation opportunities that were previously out of reach for the average attacker are suddenly much more accessible. You no longer need to be an exceptionally skilled vulnerability researcher to find some of these weaknesses. AI can do a tremendous amount of that heavy lifting for you.”

Defenders always should have the advantage. Therefore the balance needs to be reset so that the good guys are the ones that win.

Exclaimer helps customers meet WCAG 2.1 AA accessibility requirements for email signatures

Posted in Commentary with tags on September 23, 2026 by itnerd

Exclaimer today announced the launch of Accessibility Controls, a collection of new and existing functionalities within Exclaimer that teams can use to ensure templates satisfy 28 WCAG 2.1 Level AA success criteria that apply to email signature content.

Most organizational accessibility work targets websites and apps. Email signatures are usually left out, even though they go out thousands of times a day and reach more external stakeholders directly than almost any other communication channel. In an email signature, something as simple as missing screen reader labels where links provide no context, missing alt text, or contact details embedded as an image rather than text can make important information inaccessible to someone using a screen reader.

For public sector and federally funded organizations in the US, accessibility requirements are becoming more prescriptive. The Department of Justice’s ADA Title II rule requires state and local government web content and mobile apps to meet WCAG 2.1 Level AA, with entities serving populations of 50,000 or more required to comply by April 26, 2027, and smaller entities and special district governments by April 26, 2028. Separately, organizations receiving HHS funding with 15 or more employees have until May 11, 2027, to bring web content and mobile apps into conformance with WCAG 2.1 Level AA under Section 504, while smaller recipients have until May 10, 2028. These rules do not set specific deadlines for email signatures, but they reflect growing regulatory focus on how organizations make digital information accessible.

How Accessibility Controls work

Exclaimer’s Accessibility Controls covers four capabilities inside the signature designer, some automatic and some configured by the template owner:

1. Semantic structure. Signatures are built and output as structured, readable content rather than a table, so screen readers announce information in the order it’s laid out.

2. Screen reader (ARIA) labels. Interactive elements like hyperlinks can carry a descriptive label, so a screen reader says “Book a demo with our team” instead of “link.”

3. Language declaration. Signatures can declare their language so screen readers use correct pronunciation, useful for organizations sending signatures in more than one language.

4. Clickable QR codes. QR codes in a signature are made more clickable, giving recipients who can’t or don’t want to scan a code a working path to the same destination.

These sit alongside existing controls: alt text set centrally at the template level, Brand Kits that keep approved color combinations and accessible fonts at or above WCAG’s minimum 4.5:1 contrast ratio for standard text, and text that renders as real HTML rather than an image, so it can be resized and read aloud.

A first for email signature management

Of the 50 Level A and AA success criteria in WCAG 2.1, 28 apply to content like an email signature. Exclaimer is the first and only email signature management provider to offer native functionality addressing all 28, without requiring customers to write HTML.

Set at the template level, Accessibility Controls apply across an organization’s email signatures in Microsoft 365 and Google Workspace as soon as a template is published, with no need to touch individual employee signatures.

Availability

Accessibility Controls is available now within the Exclaimer signature designer, as part of Exclaimer’s existing plans, for customers on Microsoft 365 and Google Workspace.

Lookout Unveils Social Engineering Protection

Posted in Commentary with tags on September 23, 2026 by itnerd

Lookout, Inc. today announced the launch of Lookout Social Engineering Protection (SEP). Integrated directly into the Lookout Mobile AI Security Platform, the new module delivers automated, real-time protection against the next generation of AI-driven mobile threats, including synthetic voice cloning, deepfake vishing, executive impersonation, and linkless smishing attacks.

Frontier AI is transforming social engineering by enabling attackers to create highly convincing deception with unprecedented realism, personalization, and scale. Advanced AI models can craft context-aware messages tailored to individual employees, while advanced voice cloning and deepfake technologies can convincingly impersonate executives, colleagues, and IT support. These capabilities make it increasingly difficult for employees to distinguish legitimate communications from malicious ones. As critical business interactions increasingly move to SMS, voice calls, WhatsApp, and other mobile channels, mobile has become a primary attack surface for AI-powered deception.

Legacy defenses were not designed for this new generation of AI-powered deception. Email security largely protects a single channel and often relies on detecting malicious links, attachments, and known indicators, while Security Awareness Training depends on employees recognizing increasingly sophisticated attacks themselves. Neither approach can keep pace with highly personalized, convincing attacks that span SMS, voice, and messaging applications. This new threat demands a more sophisticated approach—one that can continuously analyze the intent, context, and authenticity of mobile interactions in real time. Lookout Social Engineering Protection delivers that protection across mobile channels.

Omnichannel Defense Against Mobile Deception

Lookout Social Engineering Protection delivers AI-powered, multi-channel defense across text and voice communications:

  • Smishing Protection: Continuously analyzes incoming SMS, MMS, and RCS messages on iOS and Android to detect malicious links, phishing attempts, and suspicious intent in real time.
  • Vishing Protection: Analyzes audio and voicemail to detect AI-generated voice clones and deepfakes, while transcribing conversations to identify suspicious intent and scam patterns.
  • Phone Number Authentication & Centralized Call Blocking: Uses mobile identity signals and phone-number attributes to distinguish legitimate callers from numbers exhibiting suspicious characteristics or behaviors, enabling organizations to apply risk-based controls and centrally block known or suspicious numbers across the mobile workforce.

Addressing the Mobile AI Risk Triangle

With the launch of Social Engineering Protection, Lookout introduces the third core pillar of its Mobile AI Security Platform, delivering continuous protection across three critical areas of mobile risk: AI usage and data exposure, mobile software vulnerabilities, and AI-powered human manipulation.

  • AI Visibility & Governance: Protects enterprise data by providing visibility and control over employee interactions with generative, agentic, and Shadow AI applications.
  • Mobile Software Exposure Center (MSEC): Reduces mobile software risk by continuously identifying vulnerable components, SDKs, and libraries embedded within compiled mobile applications.
  • Social Engineering Protection (SEP): Protects employees from AI-powered deception by detecting and stopping smishing, vishing, voice cloning, and other sophisticated social engineering attacks in real time.

Availability

Lookout Social Engineering Protection is available as a native add-on module for the Lookout Mobile AI Security Platform. Existing customers can activate SEP capabilities directly in their unified admin console, without additional agents or infrastructure.

AI-native patent firm Fearn launches to take on the billable hour in a $14B market

Posted in Commentary with tags on September 23, 2026 by itnerd

A conventional patent application can take 30 to 40 hours of attorney time, cost $18,000 to $40,000 in legal fees, while startups wait months to protect technology that can change by the day. Fearn, the modern patent prosecution firm for startups, was built around a different model.

Today, the company launched an AI-native patent firm pairing former Big Law patent experts with an in-house AI and engineering team. Fearn drafts and prosecutes patents across software, hardware, robotics, semiconductors, defense, biotech and pharma, with fixed fees, provisional filings in as little as three business days, and a guarantee that puts its drafting fee at risk if a non-provisional application receives no allowed claims.

The company has raised $5.5 million from Kindred Ventures, a16z Speedrun, Designer Fund and Essence VC. Fearn enters a  $14 billion global patent market, with early-stage companies filing 150,000 new patent applications every year.

The journey 

Fearn was founded by Caltech alumni Han Kim and Angela Gao after they saw the same problem from opposite sides. Kim had prosecuted patents at Morrison & Foerster, while Gao earned a PhD in computer science and AI. They initially built software for law firms, but quickly realized better tooling alone would not fix a model where time saved meant revenue lost and sensitive pre-filing IP made AI difficult to deploy safely.

So they built the firm around the technology instead. Today, Fearn has hundreds of users, from venture-backed startups to public companies. 

How Fearn works  

At the center of the firm is FearnOS, its proprietary drafting and client management system. Instead of treating a patent as one long linear document, it represents the patent as a graph: it maps claims to the supporting text, figures and technical material behind them, while preserving attorney edits and a full record of how each section was produced.

That structure lets Fearn combine specialized AI with deterministic checks without taking the patent professional out of the loop. Every application is still reviewed by a former Big Law patent expert.

Fearn says work that typically takes 30 to 40 attorney hours can require as little as 30 minutes of attorney time on FearnOS. Provisionals cost $2,500, non-provisionals $9,000 including USPTO fees, and the firm reports gross margins above 80%.

Clients also manage their portfolio through the platform, with controlled access to individual patents, a complete version history and secure connections to the places where technical documentation already lives.

Customer outcomes

Fearn is already being used across technically demanding industries where filing speed can determine whether valuable IP is protected before a product demo, publication or competitive breakthrough.

London-based game studio Iconic went from invention disclosures to filed applications in days while protecting technology for AI characters that improvise in real time. American defense technology company Photon Spear used Fearn to file a hardware space technology patent in several days while keeping its material entirely on privately hosted infrastructure. Serova Bio uses the platform for patent work around AI-designed personalized cancer vaccines, where claims, supporting disclosure and a growing portfolio need to remain coordinated as the underlying science evolves.

The broader legal market is moving in the same direction. Major firms are making unusually large investments in proprietary AI infrastructure precisely because sensitive legal work requires more control over models and client data. Fearn’s thesis is that startups should be able to access that level of technical infrastructure without inheriting the economics and operating model of Big Law.

What’s next

Fearn’s ambition goes beyond drafting patents faster. It wants to give startups the kind of portfolio strategy once reserved for companies with large in-house IP teams and seven-figure outside-counsel budgets. The company is extending FearnOS across patent families, international filings, office actions and long-term portfolio strategy, so founders can see what protects each product, where coverage is weak and what should be filed next.

The end goal is simple: give a three-person startup the patent infrastructure of a much larger company, so the strength of its IP depends more on what it invented than what it can afford to spend protecting it.

Guest Post: “ClickFix” — a new wave of social engineering

Posted in Commentary with tags on September 23, 2026 by itnerd

The security industry keeps raising the bar on authentication, yet the weakest link is still the human — and with ClickFix attacks, hackers have found a way to make people hack themselves.

ClickFix is a social engineering attack where the victim is tricked into running malicious code on their own machine, thus giving the threat actor access to everything, including their saved passwords, passkeys, and session cookies.

A real case study

“Someone recently contacted me with a simple question: ‘Is my computer infected?’ For the record, he’s not a NordPass user — he found me through my personal website. He’d come across a LinkedIn post about ClickFix attacks and realized that, just a week earlier, he’d probably fallen victim to one himself. He was right. His story is worth telling — because everything about it looks harmless until the very last second,” says Deividas Ambrazevicius, an engineering manager at NordPass.

The man asking for help was chatting with a former colleague about a week earlier — a real person he knew, with years of message history between them. Or so he thought. This “former colleague” proposed a call, claiming he wanted to talk about work. However, the call failed — no audio — so he said that Microsoft Teams probably needed an update and sent a tidy set of instructions. Where to go, what to copy, where to paste — all neatly prepared. The man followed every step. Then “the colleague” disappeared. And a week later, doubts set in. 

Ambrazevicius suggested reaching out to the person in question through another channel — such as LinkedIn. And sure enough, the colleague knew nothing about any of it. His account had been hijacked. 

“I extracted the relevant data from the computer and ran a forensic analysis. What I found included both the malicious traces and pieces of the story of how the attack unfolded,” says Ambrazevicius.

  • The code was obfuscated at the individual character level, so a simple text search would not find it. 
  • It was launched using Invoke-Expression, without ever saving an executable file to the disk. That’s why the traditional antivirus software didn’t react. 
  • Curl.exe sent the data out over port 443 to a remote command-and-control server (C2). 
  • All session cookies saved in the Chrome browser were exfiltrated, along with files belonging to several different companies. 
  • The standard Windows firewall allows all outbound traffic without any warning by default — so the attack went unnoticed in real time.

He adds that after a week far less data remained than there could have been. The best course of action, according to the expert, would have been to immediately disconnect from the internet, but not shut down the computer so the RAM wouldn’t get wiped — that’s how most of the picture gets recovered.

Fake CAPTCHA 

According to Ambrazevicius, this was quite a sophisticated attack, involving a hijacked account and a degree of prior preparation. But there are simpler attacks. One of them is fake CAPTCHA — one of the most common ways a ClickFix attack is delivered.

Instead of asking the user to solve an image puzzle, the fake CAPTCHA claims that additional verification steps are required and instructs the user to press a quick sequence of keys. Frequently, that’s Windows Key + R (which opens the Windows native “Run” dialog box), then Ctrl + V (which pastes the hidden malicious payload from the clipboard), and then “Enter” (which executes the command).

“Don’t forget that infostealers don’t just steal passwords — they steal session cookies, the key a server issues after a successful login with 2FA. The criminal loads it into their own browser and opens the account — no password, no code needed. That’s why changing your password after an incident isn’t enough. You need to forcibly terminate all sessions,” Ambrazevicius cautions. 

How to avoid falling victim

  • If someone tells you that you need to update an app because they can’t hear you — that’s a red flag. Contact the person through a different channel. 
  • Be extremely cautious if a website or program unexpectedly asks you to paste text or run commands in PowerShell or Terminal.
  • A familiar name does not equal a familiar person. Accounts get stolen every day. 
  • These days, even if you see or hear someone you know, there’s no guarantee it’s really them — it might be a deepfake. Always exercise caution and agree on a code word that only your family and friends know — and ask for it if things feel suspicious.
  • If you work with sensitive data and suspect such an incident, do not delay — contact a professional. A computer can reveal a great deal, but only until the user unwittingly destroys the evidence.
  • If something like this happens and the sessions and files on your machine are confidential, they must be treated as compromised.

ABOUT NORDPASS

NordPass is a password manager for both business and consumer clients. It’s powered by the latest technology for the utmost security. Developed with affordability, simplicity, and ease of use in mind, NordPass allows users to access passwords securely on desktops, mobile devices, and browsers. All passwords are encrypted on the device, so only the user can access them. NordPass was created by the experts behind NordVPN — the advanced security and privacy app. For more information: nordpass.com.

FBI pwned by ShinyHunters

Posted in Commentary with tags on September 22, 2026 by itnerd

It’s been reported today that threat actor group ShinyHunters have said to 404 Media via the story ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees:

A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse.

The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies who want to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety.

“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative of the group told 404 Media.

Denis Calderone, CTO, Suzu Labs Had This To Say:

“ShinyHunters has spent the last week picking fights. On Friday they took over Cl0p’s leak site and put up a ‘seized by ShinyHunters’ banner, and by Tuesday the same banner was on the FBI’s jobs portal. Both were framed as payback, one for threats from a rival gang and one for an FBI advisory that told victims not to pay them. The FBI hasn’t confirmed anything yet, but if this holds up, it doesn’t look like the ShinyHunters we’ve been seeing all year. Their model has always been breach, extort, then settle or leak, and that only works when the victim can pay. The FBI isn’t going to pay, and it isn’t going to pull an advisory because a criminal group demanded it. Not sure what’s going to happen in a week, but I seriously doubt the FBI will act on this threat.

“They also say this isn’t financially motivated, but I’d take that with a grain of salt. I have a hard time believing terabytes of FBI personnel data just sit on a shelf. Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data. Meanwhile, agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.

“That zero-day is where everyone else should focus, since ShinyHunters says they plan to use it more broadly. If you run PeopleSoft, don’t wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren’t reachable from outside. Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud.”

“Limiting your blast radius is the best precautionary play here.”

If the FBI did get pwned, then that’s a hell of a black mark on the FBI. You have to wonder what the FBI has to say about that. Let’s see if they dare to comment.

EU auditors find critical gaps in response to large-scale cyberattacks

Posted in Commentary with tags on September 22, 2026 by itnerd

The European Court of Auditors has found significant gaps in the EU’s ability to coordinate its response to major cybersecurity incidents, particularly when sharing timely and actionable information between national and EU-level organizations.

The audit found that cooperation between two key cyber response networks has still not been formally defined, while differences in national security laws and implementation of the NIS2 Directive can hinder information sharing. The European Cybersecurity Alert System was also not operational at the time of the audit, with two security hubs delayed by procurement issues and key cooperation agreements, technical standards and classification systems still missing.

Auditors also identified overlapping responsibilities among EU cybersecurity bodies and weaknesses in checks on organizations receiving EU cybersecurity funding. The findings come despite €1.4 billion being allocated to cybersecurity through the EU’s Digital Europe Programme for 2021–2027.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Critical infrastructure crosses borders faster than authority does. A state-backed attacker can probe the same router or remote-access service across energy, transport, healthcare, telecoms, and water. The first defender to see the intrusion needs a way to warn every operator running the same technology.

“The European Court of Auditors’ audit shows why that warning can stall. National response teams, EU-CyCLONe, and the European Union Agency for Cybersecurity operate across different security laws, NIS2 implementations, classifications, and mandates. During an active incident, a technical warning becomes a permissions problem.

“CISA’s Automated Indicator Sharing moves machine-readable indicators and defensive measures in real time. The Joint Cyber Defense Collaborative adds playbooks and rapid exchanges across government, industry, and international partners. Europe needs those functions tied to its existing institutions, with shared rules for confidence, urgency, and action.

“I would measure the investment by one clock, the time between an energy operator seeing a state-backed probe and every similarly exposed operator receiving something usable. Every unresolved permission is attack surface.”

John Strand, Owner, Black Hills Information Security:

“There is absolutely nothing about this report that surprises me. It really doesn’t matter what type of organization you’re dealing with. It could be nation-states trying to coordinate during an incident, or internal security teams working inside the same company. You’re going to see the same communication gaps, overlaps, and confusion.

“My recommendation is simple. Drill. Run incident response tabletop exercises regularly. Keep them terse. Keep them quick. Don’t make them overly complicated. Run multiple scenarios specifically designed to expose where communication starts to break down.

“Then document those gaps and build a plan of action and milestones to fix them. Communication problems during an incident aren’t unusual. I would expect to find them in almost any organization. The important question is whether you find them during an exercise or during a real incident.”

Seemant Sehgal, Founder & CEO, BreachLock:

“The audit findings track with a pattern that shows up in a lot of large organizations trying to coordinate incident response across independent teams. Frameworks describe how the handoffs should work, but during a live incident, the seams where responsibilities were never clearly assigned are where delays happen, and 1.4 billion euros in funding does not close that gap on its own if the operational agreements underneath it are still being negotiated.

“The useful question is whether the ECA report will apply enough pressure to get the European Cybersecurity Alert System operational and to define those handoffs before the next major incident, rather than during one.”

Co-ordinating any sorts of incidents is key to bringing them under control quickly. And if anyone has the will to do it, the EU does. So I hope that they don’t prove me wrong.

ESET Research: China-aligned FamousSparrow expands operations in Latin America, targets governments with new backdoor

Posted in Commentary with tags on September 22, 2026 by itnerd

ESET Research’s ongoing monitoring of FamousSparrow discovered that the China-aligned APT group had developed a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025. In what was probably China’s reaction to the U.S.showing increased interest in Latin America, FamousSparrow increased its extensive targeting of governmental organizations there. ESET researchers chose to name the backdoor SparroWocky because the first samples collected all contained the first stanza of “Jabberwocky,” a nonsense poem by English author, poet, and mathematician Lewis Carroll (author of Alice’s Adventures in Wonderland).

SparroWocky is a modular C++ backdoor. Its architecture and the techniques used by its authors indicate strong knowledge of anti-analysis tricks and Windows internals. With the switch to SparroWocky, FamousSparrow started to incorporate code from open-source projects directly into its malware.  “Fortunately, while advanced, SparroWocky’s inner workings are much less arcane than a ‘gyre and gimble in the wabe,’ so a ‘through and through [of] the vorpal blade’ allowed us to bring you a detailed analysis of the backdoor,” quotes ESET researcher Alexandre Côté Cyr from the world-famous poem. Côté Cyr made the latest discovery during his investigation of the China-aligned group.

This cyberespionage trend against high-profile targets in Latin America started no later than in July 2025 and has continued with the more recent introduction of SparroWocky. In fact, from mid-2025 and into 2026, 90% of the group’s targets registered in ESET telemetry have been located in the region. “We have seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. This represents a rare occurrence among the China-aligned APT groups that ESET tracks, which are generally observed throughout various world regions within such an extended time frame,” says Côté Cyr.

ESET believes that this undivided focus is not coincidental and likely reflects China’s reaction to various recent U.S.initiatives in the region. Indeed, U.S. President Donald Trump’s second term has brought about an aggressive reaffirmation of U.S. interests in Latin America, which threatens various long-term investments that China has cultivated throughout the continent over the last decade, in domains such as energy, mining, and telecommunications. FamousSparrow’s activities are probably intended to help China better monitor and anticipate the reaction of local governments to current U.S. pressures. In some cases, certain elements clearly seem to confirm this hypothesis. For instance, one of the Panamanian entities targeted is directly involved in the ongoing commercial dispute regarding two major ports located in the canal area, which were, until recently, operated by a China-based company. 

Some of SparroWocky’s notable features include the ability to launch arbitrary files, to act as a TCP proxy, and to execute commands. The backdoor also collects general information about the compromised machine, such as the computer name, username, domain name, Windows version, and IP addresses of its network interfaces. SparroWocky is also capable of exfiltrating files and taking screenshots periodically. Exfiltrated information is encrypted using RC4 and sent over the TLS protocol. Depending on its configuration, SparroWocky can establish persistence either by creating a dedicated service or an entry in a registry Run key. 

The malware employs a few techniques to complicate its analysis and to evade security software that may be in place.The backdoor manipulates low-level structures in memory, and patches code at runtime in order to avoid detection.FamousSparrow still uses open-source offensive tooling for its own malicious ends. Previously, these tools were mainly used side by side with the group’s backdoor. With SparroWocky, ESET researchers observe that it also has the development capabilities to integrate open-source code directly into its own custom backdoor. SparroWocky has the capability to load and execute Beacon Object Files, a special type of executable file supported by many red-teaming and penetration-testing tools.

FamousSparrow is a China-aligned cyberespionage group believed to have been active since at least 2019. ESET Research first publicly documented the group in a blogpost from September 2021, when it exploited the ProxyLogonvulnerability. The group was initially known for targeting hotels around the world but has also targeted governments, international organizations, trade groups, engineering companies, and law firms. 

ESET attributes the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor. Moreover, not only does the victimology match FamousSparrow’s previous targeting, but ESET also recorded attempts to deploy SparroWocky at many of the same organizations that had previously been targeted with SparrowDoor. FamousSparrow is the only known user of the SparrowDoor backdoor. 

For a more details and technical analysis of SparroWocky, check out the ESET Research blog post “Beware the SparroWock: The backdoor that bites, the commands that catch” on WeLiveSecurity.com.

GAO finds FAA aircraft communications vulnerable to hacking and jamming

Posted in Commentary with tags on September 22, 2026 by itnerd

A new U.S. Government Accountability Office (GAO) report found that communications between air traffic controllers and commercial aircraft remain vulnerable to cyber and electromagnetic threats, including interception, spoofing and jamming.

GAO also found that text-based aircraft communication systems have vulnerabilities related to authentication, encryption and protocol design. The agency found that while the FAA has identified spectrum-related threats, it lacks tools to continuously monitor for them in real time and can generally investigate incidents only after they are reported.

The Department of Transportation, responding on behalf of the FAA, agreed with all nine of GAO’s recommendations. The report was released the same day as a telecommunications failure involving a severed backup fiber line that caused the FAA to halt incoming flights at several major Northeast airports, contributing to roughly 7,000 delayed or canceled flights nationwide. The disruption was not attributed to a cyberattack.

Damon Small, Board of Directors, Xcape Inc.:

“Unencrypted and unauthenticated aviation data links expose national airspace operations to severe financial disruptions, safety risks, and systemic operational failures. A recent Government Accountability Office (GAO) report reveals that legacy text-based communications lack cryptographic authentication and protocol integrity, leaving air traffic control (ATC) systems vulnerable to active spoofing, jamming, and interception.

“The nine recommendations from the GAO are valid, but they also show how far behind the Federal Aviation Administration (FAA) is in protecting and maintaining its aging infrastructure, a frightening prospect given that millions of passengers and crew depend on it every day. Furthermore, a single fiber cut led to the disruption of ATC in the northeastern United States, demonstrating a severe lack of redundancy in these safety-critical systems. Aviation executives and government leaders must prioritize implementing cryptographic payload signing across aircraft messaging systems, deploying continuous automated spectrum monitoring tools, and engineering true physical resiliency into ground network backbones.

“Critical Takeaways:

  • Valid GAO recommendations highlight how far behind the FAA remains in securing legacy aviation infrastructure against radio frequency spoofing and jamming.
  • A single severed fiber line disrupting northeastern air traffic control exposes a critical lack of redundancy in safety-critical ground networks.
  • Aviation leaders must enforce cryptographic authentication on text communications and deploy real-time spectrum monitoring equipment.

“Relying on post-incident investigations for radio frequency jamming in aviation is like buying a smoke detector after the house burns down.”

John Strand, Owner, Black Hills Information Security:

“The biggest concern with this report isn’t necessarily the findings. It’s how difficult the recommended fixes may be to implement.

“With a lot of standard technology, you patch it, update it, and move on. But when you’re dealing with the FAA and critical infrastructure, these are real-time systems where the tolerance for downtime or errors is basically zero.

“Even changes that look simple on paper can become incredibly complicated and expensive because of the systems involved and the requirement to keep them running. I applaud the report. It looks like they found some very real issues. The problem is that fixing them could be extremely expensive and take a significant amount of time.

“And time is the part that worries me. We’re already seeing attackers targeting critical infrastructure. We don’t have the luxury of assuming they’ll wait for us to finish fixing it.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“As a pilot, I cannot treat a clearance like an email that can wait for a second look. Under Instrument Flight Rules (IFR), crews may be flying by instruments with limited outside visual reference while responding quickly to a tower or controller. If the channel becomes suspect, every clearance becomes a verification problem as well as an instruction.

“The Government Accountability Office (GAO) findings show the trust problem inside the communications system. FAA lacks continuous, real-time detection for all spectrum-related threats. Aircraft Communications Addressing and Reporting System (ACARS) and Controller Pilot Data Link Communications (CPDLC) still depend on procedural checks because they lack cryptographic authentication and message integrity. Voice confirmation adds workload without proving message origin or integrity.

“Monday’s fiber outage showed the visible failure mode. A broken link produces silence. Spoofing creates a harder failure mode because the link can stay open while the message is false. I would treat live monitoring and authentication as urgent fixes.

“The FAA needs to distinguish an unavailable link from jamming or spoofing during operations. Until then, pilots and controllers remain the last security control in the loop, manually compensating for a network that cannot authenticate its messages.”

I have to ask if this is being truly taken care of at in order to make this go away. That’s the real question and I hope that someone has an answer.

Operation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures

Posted in Commentary with tags on September 22, 2026 by itnerd

Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs.

Recently, the SOCRadar Threat Research Unit (STRU) uncovered Operation Conflict Compass, a targeted campaign by the DPRK-aligned actor Konni, aimed at gathering intelligence on the ongoing trajectory of the Russian invasion of Ukraine.

Key points: 

  • Spear-phishing ZIPs with LNK files disguised as PDFs, using Russia-Ukraine peace framework. Targeting potentially points to diplomatic entities, think tanks, and NGOs.
  • The chain sets up a scheduled task that runs a PowerShell downloader STRU named VelvetCake every minute. It keeps almost no capability on the host, pulling and running server-side scripts on demand, then wiping its artifacts.
  • A recovered second-stage script performs host enumeration and screen capture, exfiltrated over HTTP POST.
  • The same components were also delivered via a trojanized Zoom installer.
  • Attribution to Konni is moderate confidence: targeting, VelvetCake code characteristics, shared C2 and GitHub staging infrastructure, and operator time zone. 

For full details, the research can be read here: https://socradar.io/blog/operation-conflict-compass-konni-ukraine-lnk-lure/