Archive for September 11, 2025

US Senator Calls for FTC Investigation of Microsoft for Ascension Hospital Ransomware Hack 

Posted in Commentary with tags , on September 11, 2025 by itnerd

In a letter to FTC Chairman Andrew Ferguson, U.S. Senator Ron Wyden urged the FTC to launch an investigation of Microsoft and “hold the company responsible for the serious harm it has caused by delivering dangerous, insecure software to the U.S. government and to critical infrastructure entities, such as those in the U.S. health care sector.” This includes the hack of millions of patient records from Ascension, the major hospital system, in 2024 

You can read the letter here: https://www.wyden.senate.gov/news/press-releases/wyden-calls-for-ftc-investigation-of-microsoft-for-enabling-ascension-hospital-ransomware-hack-with-insecure-software

Ensar Seker, CISO at cybersecurity threat intelligence company SOCRadar, commented:

“The letter underscores a long-standing tension in enterprise cybersecurity, the balance between legacy system support and secure-by-default design. What happened at Ascension isn’t just about one bad click or an old cipher. It’s about systemic risk inherited from default configurations and the architectural complexity of widely adopted software ecosystems like Microsoft’s. When a single vendor becomes foundational to national infrastructure, their security design decisions, or lack thereof, can have cascading consequences.

“From a technical standpoint, allowing deprecated encryption like RC4 to remain enabled by default, even at 0.1% usage, introduces avoidable exposure. The challenge is that many organizations still rely on legacy applications that can break when more secure defaults are enforced. Vendors are often reluctant to force those changes out of fear of business disruption, but in security, inertia can be dangerous.

“This incident also reinforces the importance of zero trust segmentation and endpoint detection. A single compromised contractor laptop should never have been able to reach Active Directory in the first place. That speaks to deeper gaps in lateral movement defenses, privilege boundaries, and user behavior monitoring, not just a software flaw.

“Ultimately, this isn’t about blaming one company. It’s about recognizing that national security is now tightly coupled with the configuration defaults of dominant IT platforms. Enterprises and public sector agencies alike need to demand more secure-by-design defaults and be ready to adapt when they’re offered.”

The EU has proven via strict enforcement and high fines that if you give organizations a reason to care about cybersecurity, they will care because it will get expensive if they don’t. It’s time that this sort of thing comes to North America.

New Phishing Campaign Leverages Google AppSheet to Steal Login Credentials

Posted in Commentary with tags on September 11, 2025 by itnerd

Researchers have uncovered a new phishing campaign targeting Google Workspace organizations through fraudulent AppSheet-branded emails. The attack illustrates how traditional security controls become useless when attackers abuse legitimate infrastructure to deliver malicious content that sails past every deployed security filter.

You can find more details here: https://ravenmail.io/blog/appsheet-phishing-scam

Erich Kron, security awareness advocate at KnowBe4, commented:

“The reliance on commonly used or well-known brands in social engineering attacks is nothing new, however, these attacks still remain quite effective. Leveraging brands that are known to potential victims exploits the trust that these brands have worked so hard to establish. These types of attacks are meant to blend in with normal day-to-day activities, further increasing the trust level of the potential victim.

“While people can be suspicious about emails sent from spoofed accounts, by using a platform that sends from a known and trusted source, many technical filters and controls are bypassed, and a key red flag is taken away from the potential victim. It is important that people learn multiple ways to identify potential social engineering attacks, including identifying potentially harmful URLs and other traps.

“Organizations should be aware of attacks such as this and consider the importance of a strong and well-organized human risk management process. This includes technical controls and education.”

This is another example of why you always need to be on your toes as the bad guys in cyberspace are trying to stay one step ahead of you so that they can make your life miserable.

Trump pushes for sleeker government sites, but 73% have security issues

Posted in Commentary with tags on September 11, 2025 by itnerd

As President Donald Trump calls for sleeker, more user-friendly government websites through a new executive order, the Business Digital Index (BDI) team examined how well each state’s main government website is protected — revealing that cybersecurity, not design, should be the priority.

Here’s the methodology the BDI team used to evaluate the cybersecurity of government websites:

And here are the findings:

Best-performing states

  • Democratic-leaning: Connecticut (96/A), Colorado (87/C), Hawaii (83/C)
  • Republican-leaning: Arkansas (96/A), Kansas (81/C), Oklahoma (80/C)

Most improved states (Feb–Aug 2025):

  • District of Columbia (+28 points, from 38 to 66)
  • Nevada (+27 points, from 60 to 87)
  • Texas (+27 points, from 49 to 72)

Worst-performing states (Aug 2025):

  • Democratic-leaning: Delaware (37/F), Minnesota (42/F), Maine (49/F)
  • Republican-leaning: Indiana (27/F), Wyoming (28/F), Iowa (35/F)

States with the steepest declines (Feb–Aug 2025):

  • North Dakota (–18 points, from 68 to 50)
  • Louisiana (–13 points, from 64 to 51)
  • Tennessee (–13 points, from 65 to 52)

Political trends 

  • Democratic-leaning states: 59 (Feb 2025) → 63 (Aug 2025), +8% improvement
  • Republican-leaning states: 57 (Feb 2025) → 59 (Aug 2025), +4% improvement
  • The three lowest-ranked states — Indiana, Wyoming, and Iowa — are all Republican-leaning, with Indiana at the bottom at just 27/100.

To see the full report, please visit:

https://businessdigitalindex.com/research/trump-pushes-for-sleeker-government-sites-but-73-have-security-issues/ 

New agentic AI to boost scalability and efficiency in Ericsson’s enterprise wireless portfolio

Posted in Commentary with tags on September 11, 2025 by itnerd

Ericsson has unveiled the integration of agentic AI into its NetCloud platform, representing a major leap forward in enterprise 5G networking. As NetCloud evolves to effortlessly manage both Wireless WAN and private 5G solutions, Ericsson is also launching the industry’s first enterprise 5G agentic AI virtual expert that will transform how businesses deploy, optimize and manage their 5G networks.

The integration of agentic AI advances Ericsson’s generative AI-based NetCloud Assistant (ANA) from a user-prompt driven tool into a strategic partner empowered by a team of AI agents. By interpreting high-level intents, ANA will be able to handle complex workflows, execute administrator decisions and learn in real time. This reduces burdens for lean IT and Operational Technology (OT) teams while boosting network reliability and user experience. 

Key AI features include:

  • Agentic organizational hierarchy: ANA will be supported by multiple orchestrator and functional AI agents capable of planning and executing (with administrator direction). Orchestrator agents will be deployed in phases, starting with a troubleshooting agent planned in Q4 2025, followed by configuration, deployment, and policy agents planned in 2026. These orchestrators will connect with task, process, knowledge, and decision agents within an integrated agentic framework.
  • Automated troubleshooting: ANA’s troubleshooting orchestrator will include automated workflows that address the top issues identified by Ericsson support teams, partners, and customers, such as offline devices and poor signal quality. Planned to launch in Q4 2025, this feature is expected to reduce downtime and customer support cases by over 20 per cent. 
  • Multi-modal content generation: ANA can now generate dynamic graphs to visually represent trends and complex query results involving multiple data points.
  • Explainable AI: ANA displays real-time process feedback, revealing steps taken by AI agents in order to enhance transparency and trust.
  • Expanded AIOps Insights: NetCloud AIOps will be expanded to provide isolation and correlation of fault, performance, configuration, and accounting anomalies for Wireless WAN and NetCloud SASE. For Ericsson Private 5G, NetCloud is expected to provide service health analytics including KPI monitoring and user equipment connectivity diagnostics. Planned availability is Q4 2025.

Planned to be available Q4 2025, the integration of Ericsson Private 5G into the NetCloud platform brings powerful advantages to enterprise 5G customers, including access to AI features, real-time feature availability, simplified lifecycle management, greater agility across multisite deployments and better administrator controls with distinct user roles and permissions. NetCloud acts as a foundation for future agentic AI features focused on removing friction and adding value for the enterprise. These innovations directly address critical adoption barriers as more industrial enterprises leverage private 5G for business-critical connectivity. With this integration, Ericsson is empowering businesses to overcome these challenges and unlock the full potential of 5G in IT and OT environments.

ESET Research discovers new Chinese threat group: GhostRedirector manipulates Google, poisons Windows servers with backdoors

Posted in Commentary with tags on September 11, 2025 by itnerd

ESET Research has discovered a new threat actor, which it has named GhostRedirector. In June 2025, this threat actor compromised at least 65 Windows servers, mainly in Brazil, Thailand, Vietnam, and the United States. Other victims were located in Canada, Finland, India, the Netherlands, the Philippines, and Singapore. GhostRedirector used two previously undocumented, custom tools: a passive C++ backdoor that ESET has named Rungan, and a malicious Internet Information Services (IIS) module it has named Gamshen. GhostRedirector is very likely a China-aligned threat actor. While Rungan has the capability of executing commands on a compromised server, the purpose of Gamshen is to provide SEO fraud as-a-service to manipulate Google search engine results, boosting the page ranking of a configured target website. Its purpose is to artificially promote various gambling websites.

Besides Rungan and Gamshen, GhostRedirector also uses a series of other custom tools, in addition to the publicly known exploits EfsPotato and BadPotato, to create a privileged user on the server that can be used to download and execute other malicious components with higher privileges. Alternatively, it can be used as a fallback in case the Rungan backdoor or other malicious tools are removed from the compromised server.

While the victims are located in different geographic regions, most of the compromised servers located in the United States appear to have been leased to companies that are based in Brazil, Thailand, and Vietnam, where most of the other compromised servers are actually located. Thus, ESET Research believes that GhostRedirector was more interested in targeting victims in Latin America and Southeast Asia. GhostRedirector hasn’t shown interest in a particular vertical or sector; instead, ESET has identified victims across multiple sectors, including education, healthcare, insurance, transportation, technology, and retail.

Based on ESET telemetry, GhostRedirector probably gains initial access to its victims by exploiting a vulnerability, likely an SQL Injection.  The attackers compromise a Windows server, then download and execute various malicious tools: a privilege escalation tool, malware that drops multiple webshells, or the already mentioned backdoor and IIS Trojan. In addition to the obvious purpose of the privilege escalation tools, they can also be used as a fallback in case the group loses access to the compromised server. Backdoor capabilities include network communication, file execution, directory listing, and manipulating both Services and Windows registry keys.

ESET telemetry detected attacks by GhostRedirector between December 2024 and April 2025, and an internet-wide scan from June 2025 identified further victims. ESET notified all the identified victims it discovered via the scan about the compromise. Mitigation recommendations can be found in our previously published comprehensive white paper.

For a more detailed analysis and technical breakdown of GhostRedirector, check out the latest ESET Research blogpost, “GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes,” on WeLiveSecurity.com.

Countries where GhostRedirector victims were detected:

Anker Announces The C1000 Gen 2

Posted in Commentary with tags on September 11, 2025 by itnerd

Anker has launched the C1000 Gen 2. A compact, rugged portable power station built for Canadian life – from cottage weekends and road trips to storm season backup at home. The C1000 Gen 2 will be available across Canada now and has a limited-time special pricing for orders up until September 13.  

Highlights at a glance:  

  • 49-minute full recharge (0–100% from a wall outlet with UltraFast Charge Mode) making it the fastest-charging portable power station in its class, an achievement Guinness World Records has officially certified globally 
  • 2000W output (3000W peak) for fridges, tools, laptops 
  • LFP battery, 4,000 cycles to 80% capacity 
  • App control for monitoring and firmware updates 

Canadian availability & pricing  

  • Available now across Canada at ankersolix.com/ca  
  • MSRP CAD $1,199  
  • Limited time early price; purchase between September 8 and 13 and pay CAD $679 

Where the C1000 Gen 2 fits 

  • Sub-1-hour full recharge makes portable power practical for last-minute outage prep, quick turnarounds between jobs, and road-trip pit stops. 
  • Clean, quiet alternative to gas generators for homes/condos and other noise-sensitive settings. 
  • Portable for cottage/RV/van-life; solar-ready and suited to Canadian conditions. 

SIOS Technology to Showcase High Availability Clustering Solutions at Key Events Across the US, Europe, and Middle East in Fall 2025

Posted in Commentary with tags on September 11, 2025 by itnerd

 SIOS Technology Corp. has announced it will demonstrate its high availability clustering software for business-critical applications at three premier technology events this fall, including: 

At each event, SIOS experts will demonstrate how SIOS LifeKeeper and DataKeeper software deliver high availability and disaster recovery for critical applications such as SQL Server, SAP, and Oracle. Attendees will discover how SIOS clustering solutions help ensure application uptime, eliminate data loss, and simplify HA/DR operations across physical, virtual, cloud, and hybrid environments.

SIOS clustering software enables IT teams to create highly available application environments without the need for shared storage. Through intelligent application monitoring, real-time data replication, and automated failover and recovery, SIOS ensures business continuity with minimal complexity and reduced cost. With support for Windows and Linux in any infrastructure, SIOS solutions are trusted by enterprises worldwide.

Google security veterans raise $13M seed round for AegisAI to fix email security 

Posted in Commentary with tags on September 11, 2025 by itnerd

 AegisAI, a cybersecurity startup founded by former Google Safe Browsing and reCAPTCHA leaders Cy Khormaee and Ryan Luo, today announced its public launch and funding round with a radical approach to email security: autonomous AI agents that eliminate Phishing, Malware, and Business Email Compromise (BEC) attacks before they reach user inboxes — while reducing false positives by up to 90% compared to traditional solutions.

The $13m seed funding round was led by Accel and Foundation Capital. The funding will accelerate product development, expand the engineering team, and support go-to-market efforts as the company scales its autonomous email security platform.

AI has created a new wave of threats that rule-based systems are not prepared for. Adversaries can rotate graphics, messaging, and fabricate supporting content to create lures that look more real than ever. A 2024 study showed LLM-generated phishing messages had a significantly higher click-through rate (54%) than human-written ones (12%), proving their effectiveness. 

Modern attackers are also increasingly abusing trusted platforms like Salesforce, Zoom or Google to deliver malicious content, exploiting the inherent trust these services carry to bypass traditional reputation-based security filters and rules that would typically block suspicious domains or unknown senders.

AegisAI introduces a paradigm shift: an orchestrated network of real-time AI agents that inspect, analyze, and neutralize email threats autonomously, eliminating the need for static rules, extensive user training, or complex playbooks.

The AegisAI platform integrates seamlessly with Microsoft 365 and Google Workspace via API deployment. Unlike traditional rule-based gateways, its AI agents continuously learn from real-world adversarial behavior and share threat intelligence across organizations, enabling rapid detection and remediation of emerging phishing, spoofing, and executive impersonation tactics.

Core Platform Capabilities:

  • Autonomous Threat Detection – Real-time analysis of every message component including links, attachments, metadata, QR codes and behavioral patterns.
  • Intelligent False Positive Suppression – Customers in production environments have seen up to 90% reduction in False positives (good emails being quarantined) compared to traditional solutions.
  • Zero-Configuration operation – Autonomous response, escalation, and policy enforcement requiring minimal SOC setup or maintenance.
  • Security-First Design – Built with enterprise-grade encryption and data minimization principles.

The founding team brings deep expertise from Google. Following a successful stealth phase with pilot customers across fintech and tech companies, AegisAI has demonstrated significant improvements in threat detection accuracy and operational efficiency.

The Nikon ZR: A New Era of Limitless Cinematic Possibilities, Born from Nikon’s Synergy with RED Digital Cinema

Posted in Commentary with tags on September 11, 2025 by itnerd

Nikon Canada Inc. announced their first cinema camera made for filmmakers, the ZR. The ZR is an ultra-lightweight, full-frame camera that marks an audacious introduction to the Z Cinema series, a collection that invokes the best technologies and philosophies of both companies. Designed for emerging cinematographers and high-end content producers, the supremely capable Nikon ZR packs an unparalleled amount of professional video production features at a price that puts cinematic quality within reach for all types of filmmakers. 

The Nikon ZR is as versatile as it is powerful, with a multitude of original and class-leading capture and workflow features never seen before in this level of camera. The new Nikon ZR can record up to 6K/60p (59.94p) and incorporates the new R3D NE RAW video file format with RED colour science based on RED’s popular R3D RAW codec, with 15+ stops of dynamic range. This new codec uses colour science and exposure standards of RED cameras to ensure accurate colour matching, even for multi-cam shoots. The impressively huge 4 inch DCI-P3 LCD is nothing short of stunning, and bright enough to be used even in direct sunlight, while often eliminating the need for an external monitor. It also has class-leading audio capabilities such as 32-bit float audio from built-in and external microphones, plus OZO directional audio. The ZR also has 7.5 stops of built-in image stabilization (IBIS) and unlocks a whole new world of optical versatility, since the wide Nikon Z mount enables a large variety of lenses to be adapted using third-party lens adaptors.

Legendary RED Colour Science, Built-In

The new ZR features a full-frame sensor for excellent depth of field and video quality and supports internal recording up to 12-bit RAW 6K/60p. This is the first camera to use the new 12-bit R3D NE RAW codec, a new RAW format which REDCODE RAW users will find familiar. By leveraging its broad 15+ stop dynamic range, it achieves well-balanced image quality from highlights to shadows. Support for Log3G10 and the REDWideGamutRGB gamut reproduces exposure standards and colours consistent with RED colour science, with true RED colour tonality, skin tone integrity and tonal roll-off—similar to the output of RED’s cinema cameras such as the V-RAPTOR [X] and KOMODO-X. Two base ISO sensitivities are available, ISO 800 and ISO 6400, allowing users to choose the best option for a particular scene or situation such as bright daylight or lowlight interior scenes. However, just like REDCODE RAW, ISO in R3D NE files is fully adjustable in post for maximum flexibility.

Furthermore, users also have the option to shoot in N-RAW, ProRes RAW, and other formats to best suit their production and workflow. The camera also features a new view assist function which allows the user to store and select from up to ten LUTs in the camera. This will let the filmmaker preview the effect of the colour grade in real time using the monitor. Three types of LUT data (17-point, 33-point, 65-point) can be loaded into the camera. RED’s Creative LUT Kit is available for free via the RED website here

The ZR features a new Cinematic video mode, a user preset for those who want to easily enjoy the RED cinematic look with a faster workflow in less data-intensive non-RAW formats. Cinematic mode automatically adjusts the shutter angle to 180 degrees, changes the frame rate to 24 fps, and applies the RED Cine Bias Picture Control for gorgeous yet simple cinematic colour. What’s more, nine RED-curated cinematic Picture Controls based on RED creative LUTs will be available for free download via Nikon Imaging Cloud, expanding possibilities for more diverse imaging expression.

Incredible Audio: 32-Bit Float Audio Recording + OZO Audio Support for Built-In Mic

With uncompromising attention to audio capabilities, the ZR is the world’s first cinema camera to support 32-bit float audio recording with both built-in and external microphones, as well as through the 3.5 mm microphone jack. This unique ability enables the recording of clear, distortion-free sound from quiet to loud, without requiring on-location gain adjustment. It supports recording a wide range of sound sources, from interviews to live concerts, with maximum audio flexibility in post. The three high-performance mics built into the camera use Nokia’s OZO Audio technology to realize cutting-edge audio recording. Filmmakers can choose from one of the five polar pickup patterns — [Front (Super directional)], [Front], [All directions], [Rear], and [Stereo (binaural)] — that best suits the situation, from interviews or product tutorials to immersive audio applications.

The ZR is also the first Nikon camera to feature a digital accessory shoe, which enables two-way digital communication between the camera and compatible accessories, allowing for advanced functionality such as tally lamp and microphone LED control. Additionally, the camera can supply power directly to supported accessories, eliminating the need for separate batteries or cables. The newly designed rubber shoe cover provides excellent dust and drip resistance, ensuring reliable performance in a variety of shooting environments. Going forward, Nikon will collaborate with third-party accessory manufacturers to offer a wide range of solutions that meet the diverse needs of filmmakers.

High-Performance Autofocus with Nikon’s Deep Learning-Based AI Technology

The impressive processing power of the EXPEED 7 image-processing engine installed in Nikon’s flagship camera Z9 and AI technology that utilizes deep learning enables more accurate subject detection and tracking for optimal image processing in accordance with the subject, scene and situation. This makes capturing the intended subject with greater accuracy much easier, significantly expanding possibilities for film production. The camera also detects nine types of subjects automatically, including people, animals and vehicles. It even detects small faces occupying as little as 3 per cent of the long side of the frame for precise focusing on distant human subjects. Users can also adjust AF speed and sensitivity to suit their creative style, enabling a slow rack for cinematic effect or fast-paced focus for action. 

Designed to Thrive in any Production Environment

The ZR uses an innovative fanless design, with the entire camera body contributing to efficient heat dissipation and thermal management. This design decreases audible noise, enhances battery life and increases durability. The ZR can shoot uninterrupted recording for up to approximately 125 minutes. Additionally, USB power delivery capability allows for long takes and worry-free shooting at events that require extended recording, such as weddings, concerts and interviews. 

With its magnesium alloy chassis, the ZR inherits the same rugged durability standards of Nikon’s Z6III. This means it’s designed to handle the pressures of professional production environments—indoors or out. The body is resistant to dust, sand and moisture, thanks to careful sealing at critical points like buttons, seams and ports. It’s a tool designed for real-world filmmaking—resilient under pressure and ready to shoot on location. The controls on the ZR also reflect a new filmmaker-oriented UI, with familiar menus, a new quick menu for filmmakers, as well as customizable button placement made for a cinematographer’s most used features. 

Additional Features of the Nikon ZR

  • Super lightweight with small footprint at just 1.19 lb (body only).
  • A short 16mm flange focal distance (the shortest among full-frame cameras) offers greater flexibility in the lenses that can be used, allowing filmmakers to make the most of their existing lens assets.
  • The shutter angle can be adjusted from 5.6° to 360° for video recording. Shutter speed is also available.
  • The brightness of the information display (histogram/waveform monitor size, transparency and position, and zebra pattern colour) can be changed.
  • Automatic rotation of vertical video for social media content creation.
  • A front tally light /rec lamp lets subjects know you are recording. Additionally, it receives tally control signals input via HDMI-CEC and displays the status of each camera when multiple cameras are used.
  • A superior dust- and drip-resistant, durable construction expands shooting possibilities.
  • Equipped with advanced still photography features inherited from the Z6III, as well as new features such as a preset for starscape photography and a new dehaze function. 
  • Slow-motion presets: Instant access to 4K/119.88p and Full HD/239.76p cinematic motion, as well as user modes for 4x and 5x slow-motion. 
  • It also supports Frame.io Camera to Cloud using NX MobileAir, automatically transferring video data directly to the cloud for a faster and more efficient post-shooting workflow.

RED Digital Cinema, Inc. Releases the V-RAPTOR XE

RED Digital Cinema, Inc., a subsidiary of Nikon Corporation, is pleased to announce the release of the new V-RAPTOR XE digital cinema camera, which was released on September 9, 2025. The newest addition to its acclaimed Z CINEMA camera lineup, this streamlined version of the revolutionary V-RAPTOR [X], curates the essential tools for cinematic storytelling. Designed for independent creators who demand uncompromising image quality, the V-RAPTOR XE delivers large-format, cinema-grade features at a more accessible price point. The new camera retains RED’s industry-leading 8K large format (VV) global shutter sensor found in the V-RAPTOR [X] series, ensuring cinematic image fidelity, dynamic range, and low-light performance that filmmakers trust. Nikon and RED will meet a wide range of needs in film production with an extensive lineup of cinema-oriented products under the Z CINEMA series.

New ME-D10 Shotgun Microphone

The ME-D10 is a 32-bit float shotgun microphone compatible with the new digital accessory shoe developed for the ZR. It requires no battery or cable and has built-in shock mounts to minimize any interference. It offers two recording modes, PURE and FOCUS, which can be selected with a switch on the microphone. PURE mode features a wide dynamic range and a sound design true to the original source, allowing natural and accurate capture of raw audio, including the ambient atmosphere. FOCUS mode accurately captures the intended voice, even in noisy surroundings such as those outdoors, ensuring clear audio for product presentations and live streams.

Price and Availability

The new Nikon ZR Cinema Camera will be available in late October 2025 for a manufacturer’s suggested retail price (MSRP) of $2,999.95 for the body only. The ME-D10 shotgun microphone, also scheduled for release in late October, has a suggested retail price of $459.95.