Archive for October 7, 2025

Saviynt Launches UNLOCK Global Tour to Showcase the Future of AI-Powered Identity Security

Posted in Commentary with tags on October 7, 2025 by itnerd

 Saviynt, a leader in AI-powered identity security solutions, today announced the launch of its global UNLOCK Tour: Unlock Possibility. Govern Every Identity. Accelerate with AI. This exclusive 2025 event series will explore how organizations are approaching the AI era – spotlighting AI’s incredible potential alongside the critical need to secure and govern it. Attendees will gain actionable blueprints from global industry leaders and practitioners on how intelligent identity security can help enterprises achieve more than they ever thought possible.

The tour will feature a session led by Amazon Web Services (AWS) titled “Leveraging AI to Unlock Productivity and Elevate Security of Cloud Workloads.” In collaboration with Saviynt, AWS will showcase how organizations can harness the power of AI to achieve new levels of security, operational efficiency, and innovation in the intelligence age.

At each UNLOCK event, attendees will:

  • Hear from Industry Leaders and Analysts – Insights from global security experts, including keynote perspectives from recognized veterans and analysts such as Martin Kuppinger, Principal Analyst and Co-Founder of KuppingerCole.
    Explore AI’s Promise and Risks – Understand how AI is reshaping the enterprise, and why securing and governing it is essential to success.
    Experience Real-World Strategies – Learn from customer transformation stories and live demos of AI-powered identity security capabilities in action.
    Gain Practical Blueprints – Frameworks for streamlining compliance, consolidating tools, and improving efficiency.
    Connect with Peers and Innovators – Build relationships through panels, roundtables, networking, and executive 1:1s, with Saviynt executives including CEO Sachin Nayyar, President Paul Zolfaghari, Chief Product & Strategy Officer Jeff Margolies, COO Shankar Ganapathy, Chief Product Officer Vibhuti Sinha, SVP of Strategy Henrique Teixeira, Field CTO David Lee, and Field CIO Simon Gooch.

2025 UNLOCK Tour Dates:

  • Singapore, October 3 (Invite Only)
  • New York City, October 14
  • Frankfurt, October 21
  • London, October 23
  • Sydney, October 28
  • Gothenburg, October 28
  • Toronto, November 4
  • Paris, November 6
  • Dallas, December 11

Saviynt’s UNLOCK Global Tour is complimentary for prospects, customers, and partners. To learn more about the event and register for a city near you, please visit https://saviynt.com/unlock-roadshow.

ESET Research discovers new spyware posing as messaging apps targeting users in the UAE

Posted in Commentary with tags on October 7, 2025 by itnerd

ESET researchers have uncovered two Android spyware campaigns targeting individuals interested in secure communication apps, namely Signal and ToTok. These campaigns distribute malware through deceptive websites and social engineering and appear to target residents of the United Arab Emirates (UAE). ESET’s investigation led to the discovery of two previously undocumented spyware families: Android/Spy.ProSpy impersonates upgrades or plugins for the Signal app and the controversial and discontinued ToTok app, and Android/Spy.ToSpy impersonates the ToTok app. The ToSpy campaigns are ongoing, as suggested by C&C servers that remain active.

ESET Research discovered the ProSpy campaign in June 2025, and it has likely been ongoing since 2024. ProSpy is being distributed through three deceptive websites designed to impersonate communication platforms Signal and ToTok. These sites offer malicious APKs posing as improvements, disguised as a Signal Encryption Plugin and ToTok Pro. The use of a domain name ending in the substring ae.net may suggest that the campaign targets individuals residing in the United Arab Emirates, as AE is the two-letter country code for the UAE.

During the investigation, ESET discovered five more malicious APKs using the same spyware codebase, posing as an enhanced version of the ToTok messaging app under the name ToTok Pro. ToTok, a controversial free messaging and calling app developed in the United Arab Emirates, was removed from Google Play and Apple’s App Store in December 2019 due to surveillance concerns. Given that its user base is primarily located in the UAE, it is likely that ToTok Pro may be targeting users in this region, who may be more liable to download the app from unofficial sources in their own region.

Upon execution, both malicious apps request permissions to access contacts, SMS messages, and files stored on the device. If these permissions are granted, ProSpy starts exfiltrating data in the background. The Signal Encryption Plugin extracts device information, stored SMS messages, and the contact list, and it exfiltrates other files – such as chat backups, audio, video, and images.

In June 2025, ESET telemetry systems flagged another previously undocumented Android spyware family actively distributed in the wild, originating from a device located in the UAE. ESET labeled the malware Android/Spy.ToSpy. Later investigation revealed four deceptive distribution websites impersonating the ToTok app. Given the app’s regional popularity and the impersonation tactics used by the threat actors, it is reasonable to speculate that the primary targets of this spyware campaign are users in the UAE or surrounding regions. In the background, the spyware can collect and exfiltrate the following data: user contacts, device information files such as chat backups, images, documents, audio, and video, among others. ESET findings suggest that the ToSpy campaign likely began in mid-2022.

For a more detailed analysis and technical breakdown of Android/Spy.ProSpy and Android/Spy.ToSpy, check out the latest ESET Research blog post, “New spyware campaigns target privacy-conscious Android users in the UAE” on WeLiveSecurity.com.

Cybercrime: Who’s Paying, How Much, and What’s Changing

Posted in Commentary with tags on October 7, 2025 by itnerd

VPN Mentor has just published a report with the results of a research they have recently conducted related to the cost of cybercrime during the last year. While conducting the research they identified some key elements such as:

  • Only about 1 in 10 ransomware victims officially report their attacks or losses to authorities.
  • In 2024, the total number of cybercrime complaints reported to the FBI’s IC3 reached 859,532.
  • Phishing was the most-reported cybercrime in 2024 with 193,407 complaints.
  • In 2024, financial losses due to cybercrime reached a new record of an astounding $16.6 billion.
  • In 2024, investment scams led to financial losses nearing $6.6 billion.

You can check the full report here: https://www.vpnmentor.com/blog/cybersecurity/the-cost-of-cybercrime-whos-paying-how-much-and-whats-changing

Redis Has A Flaw That Is The Absolute Worst Possible Flaw A Product Can Have

Posted in Commentary with tags on October 7, 2025 by itnerd

A newly disclosed critical vulnerability in Redis, dubbed RediShell (CVE-2025-49844), has exposed up to 60,000 unauthenticated Redis servers to potential remote code execution. The flaw, which has existed in Redis code for over 13 years, carries a CVSS score of 10.0 (the worst possible score by the way) and stems from a use-after-free issue in the Lua interpreter. 

Anders Askasen, VP of Product Marketing, Radiant Logic:

     “This newly disclosed Redis vulnerability is a reminder that technical debt doesn’t just live in code, it lives in configuration. Thirteen years of latent risk surfaced because default settings and weak segmentation went unobserved. When foundational services like Redis run unauthenticated or exposed, they create invisible attack paths that can pivot directly into identity and access systems. The answer isn’t just patching faster but seeing sooner. Identity observability provides the real-time visibility, control validation, and remediation needed to uncover these blind spots before attackers do.”

This blog post has mitigation strategies that you should read and implement if you are affected by this. I say that because this flaw is the absolute worst possible flaw. Which means that this is a today problem if you are a Redis user.

KnowBe4 Pioneers Training AI Agents for the Next Generation Workforce

Posted in Commentary with tags on October 7, 2025 by itnerd

KnowBe4 today announced breakthrough innovations that train both people and AI agents to defend against evolving cyber threats. According to Gartner, forty percent of enterprise applications will be integrated with task-specific AI agents by the end of 2026, up from less than 5% today. These AI agents are the new targets for theft, adversarial manipulation and misuse, which emphasizes the importance of employee AI literacy. 

For years, the human element has been involved in over 60% of breaches, including social engineering as one of the top attack vectors, confirmed in reports such as the 2025 Verizon Data Breach Investigations Report. Given the prevalence of the human element in breaches, smarter defenses that address the dynamic between humans and AI agents is integral to build a solid cybersecurity defense strategy.  

Cyber threats are growing more sophisticated through AI, but AI itself is also becoming a tool and a high-value target. While most solutions focus solely on defending at the gateway layer, KnowBe4’s HRM+ goes further, delivering true defense-in-depth. Built on 15 years of user behavior and threat intelligence data, the platform ensures that protection extends beyond the edge, securing every layer of interaction, from the productivity environment to the individual user and the AI agents themselves. This layered approach provides resilience that no other platform currently matches and includes:

  • Agent-Safe Behavior Training: Just as employees learned to spot a malicious link, they must now learn how to safely interact with and oversee AI agents. 
  • Prompt Injection & Manipulation Defense: Simulated attacks train global workforces to identify and resist adversarial inputs designed to hijack enterprise AI agents.
  • Risk Scoring for Agent Interactions: Extending the industry-leading Risk Score to measure susceptibility to agent misuse provides comprehensive risk quantification. 

KnowBe4 customer credits the company with being at the forefront of evolving cybersecurity needs: “Threats change and adapt far too often. KnowBe4 knows this and adapts their training to meet the current threats. AI Defense Agents in particular help quickly adapt to the evolving threat landscape.” KnowBe4 is the pioneer of AI-driven human risk management. View previous released capabilities and watch the demo presented at the KB4-CON Conference in April 2025 here.

ESET Enhances its Basic Cybersecurity Awareness Training and Releases Free Resources for Cybersecurity Awareness Month

Posted in Commentary with tags on October 7, 2025 by itnerd

ESET today released a new and improved version of its free ESET Basic Cybersecurity Awareness Training. The revamped Basic course introduces an immersive storyline, interactive modules, and refreshed content designed to empower employees to be the first line of defence and help organizations of all sizes reduce employee-related cyber risks. 

For companies that need to track course completions or require training that meets HIPAA, PCI, SOX, GDPR, CCPA, and cyber insurance compliance requirements, ESET offers a comprehensive 90-minute Premium Cybersecurity Awareness Training. Re-released last fall, the premium course, “Digital Shadows: Cryptic Chronicles,” offers dozens of modules, unlimited phishing simulation tests, dashboards for administrators to track learners’ status, a customizable training portal, reporting and course completion certificates, engaging gamification, and more.

The updated Basic course places employees in the role of a cyber investigator at NetDetect, a fictional cybersecurity team tasked with helping organizations recover from breaches and fortify defenses. Learners are immediately drawn into a mission supporting EVX, an electric vehicle company whose groundbreaking battery technology has made it a target for cybercriminals. Guided by a storyline, employees analyze a breach, uncover risky behaviors, and put protective practices into action. Modules cover key topics, including creating and managing strong passwords, safeguarding email and spotting phishing attempts, protecting against malware, identifying personalized attacks, and staying secure while working online.

This October, the launch coincides with the start of Cybersecurity Awareness Month. Over the last two decades, Cybersecurity Awareness Month has grown into a collaborative effort between government and industry to enhance cybersecurity awareness, encourage actions to reduce online risk, and generate discussion on cyber threats on a national and global scale. 

ESET has also launched a Cybersecurity Awareness Kit today, which includes access to the free ESET Cybersecurity Awareness Training, ESET’s 2025 H1 Threat Report, and a free 30-day business trial of ESET’s full-featured security solution. On Oct. 23, consumers can also learn about the real-world applications and vulnerabilities of facial recognition technology from ESET’s Webinar, The Rise and Risk of Facial Recognition. To explore these resources, visit https://www.eset.com/us/business/cybersecurity-awareness-month-kit/.


To learn more about ESET Cybersecurity Awareness Training – Basic and Premium offerings, visit https://www.eset.com/us/business/cybertraining/

Safe Software Partners with Vancouver Canucks

Posted in Commentary with tags on October 7, 2025 by itnerd

Safe Software, the creator of FME, the only All-Data, Any-AI enterprise integration platform with true support for spatial data, is now a Proud Partner for the 2025-2026 NHL season. The data integration leader has entered a new partnership with Canucks Sports & Entertainment (CSE) and the Canucks for Kids Fund (CFKF).

As part of the partnership, Safe Software is donating $25,000 to the CFKF. The donation will support vital programs across British Columbia that help to improve the lives of children and families through education, health, and wellness initiatives and programming.

The partnership unites two organizations deeply rooted in BC and committed to making a positive impact in their community. Beyond the donation, this collaboration will encourage fans to learn about how FME leverages data and AI into actionable insights for organizations around the world.

Qilin Claims Asahi Group Holdings Breach

Posted in Commentary with tags on October 7, 2025 by itnerd

Comparitech is reporting that ransomware gang Qilin today took credit for a data breach at Asahi Group Holdings that forced the company to suspend orders, shipments, and customer service.

Rebecca Moody, Head of Data Research at Comparitech, provided the following comment: 

“As the most prolific ransomware gang of 2025 (it’s claimed 578 victims this year already), the odds that the attack on Asahi had been carried out by Qilin were relatively high. While the amount of data allegedly stolen by Qilin (27 GB), is quite low compared to some of Qilin’s other claims (e.g. 9.7 TB from Yooshin Engineering Corporation in South Korea), that’s not to say that the data involved isn’t highly sensitive. Qilin actually alleges that it includes financial documents and employee data and has provided screenshots to prove these claims.”

“Asahi now needs to respond to Qilin’s allegations and confirm what data could have been impacted so those affected can be on high alert for any potential phishing campaigns or suspicious account activity. This attack becomes the 19th confirmed attack on a food and beverage manufacturer this year so far.”

Qilin is really on a tear with victims all over the place. Thus proving that in this day and age, you need to be doing everything possible to not be a victim of them or some other ransomware gang.

Samsung’s Top Amazon Tech Deals (Oct 7–10): Up to 30% Off Ahead of Prime Day

Posted in Commentary with tags on October 7, 2025 by itnerd

With Amazon’s Fall Sale running October 7–10, many shoppers are already hunting for Prime Day-style savings—and Samsung has several strong offers for people looking for a deal on Samsung products.

Here are a few standout picks worth considering: 

  • Samsung Galaxy Book4 Edge – Save 30%, now $699.99 (regularly $999.99): Samsung’s next-generation AI laptop designed for seamless productivity and portability.
    • Copilot+ AI features with on-device processing for faster performance 
    • AMOLED display, long-lasting battery, ultra-thin design 
    • Perfect for students, creators and remote professionals 
  • Samsung Galaxy Tab S10 Lite (128GB) – Save 24%, now $379.99 (regularly $499.99): A bright, versatile tablet built for entertainment, creativity, and everyday use.
    • 10.9″ AMOLED display for streaming and video calls 
    • Lightweight and portable for work or on-the-go 
    • Available in Gray, Silver and Coral Red 
  • Samsung Galaxy Watch8 (40mm, Bluetooth) – Save 15%, now $424.99 (regularly $499.99):A sleek and powerful smartwatch that helps you stay connected and in control of your wellness goals.
    • Advanced BioActive Sensor for heart-rate, sleep & stress tracking 
    • Refined design with enhanced battery life 
    • Available in Gray and Silver 
ProductOriginal PriceSale Price% Off
Galaxy Watch8 (some variants) $499.99 $424.99 15.0% 
Galaxy Book4 Edge $999.99 $699.99 30.0% 
Galaxy Tab S10 Lite (128GB, any color) $499.99 $379.99 24.0% 

Sumo Logic Academy Expands Certification Program to Improve Critical Skills for Security and Operations Teams

Posted in Commentary with tags on October 7, 2025 by itnerd

 Sumo Logic today announced a new era for its popular educational training program, now called Sumo Logic Academy. The academy is designed to help Security, Operations, and Development teams validate critical skills, build on and enhance industry expertise and maximize the value of Sumo Logic’s platform to drive security, reliability, and operational efficiency, allowing participants to demonstrate their professional abilities.

Building on a commitment to education, Sumo Logic Academy includes a new role-based Sumo Logic Certified program that introduces a refined course catalog with in-depth training, live remote exam proctoring, and industry-recognized digital credentials. This structured certification path helps ensure that technology professionals gain specialized knowledge, earn verified credentials, and follow an industry-aligned learning journey—all while showcasing their proficiency with confidence.

Validated expertise with industry-recognized certifications

The new Sumo Logic Certified program offers a skills-based assessment that validates a user’s ability to effectively and proficiently leverage Sumo Logic products within their organization. With live, remote exam proctoring through its testing partner, Kryterion, candidates benefit from a certification process that is secure, fair, and reflective of the latest industry standards and Sumo Logic solutions. After completing the exam, learners will earn a digital badge issued through Credly, allowing them to share and promote their verified expertise with their professional network.

Flexible and accessible learning for every user

Sumo Logic remains committed to democratizing access to knowledge by ensuring that certain hands-on live instructor-led, virtual training classes and workshops, as well as self-paced learning, remain free for any user. In addition to the new certifications, organizations can also access custom and private training options tailored to their specific needs for a fee. New workshops include automation service, API and Terraform, and best practices for query efficiency to help users at every stage in their maturity.

Additional Resources

  • Discover the full catalog of Sumo Logic skill-based assessments
  • Learn more about Sumo Logic’s private training
  • Read the new Sumo Academy blog