Archive for April 28, 2026

Critical RCE in Hugging Face’s LeRobot

Posted in Commentary with tags on April 28, 2026 by itnerd

Researchers disclosed a critical remote code execution flaw (CVE-2026-25874, CVSS 9.3) in Hugging Face’s open-source robotics platform LeRobot, caused by unsafe deserialization through Python’s pickle format. The issue allows an unauthenticated attacker to send malicious payloads over unsecured gRPC channels and execute arbitrary code on both the policy server and connected robot clients.

You can read more here: https://github.com/advisories/GHSA-f7vj-73pm-m822

Eli Woodward, Cyber Threat Intelligence Advisor, Team Cymru has provided this comment:

     “The bigger issue here is that AI infrastructure is increasingly becoming part of the external attack surface, often without the same visibility defenders have for traditional enterprise systems. Services like this can expose privileged environments that connect directly to valuable internal resources, making them attractive entry points for both financially motivated actors and more advanced threat groups. Once an attacker gains access, the challenge becomes understanding what else that infrastructure is connected to and how quickly they can pivot. External visibility and context become critical because many of these risks originate well beyond the traditional network perimeter. This is also an interesting case where even ‘physical safety’ becomes part of the risk model. While we’ve certainly seen that before in medical devices, the implementation of AI into robotics can create a whole new level of risk we haven’t seen before.”

This is a today problem. Especially since there is no fix at present. Not good in my opinion.

Check Point Software Launches Canada Data Residency for SASE

Posted in Commentary with tags on April 28, 2026 by itnerd

Check Point today announced the availability of Canada data residency for Check Point SASE, enabling Canadian organizations to process and store key SASE security data within Canada.

This expansion follows the recent launch of Check Point WAF and further reinforces Check Point’s commitment to the Canadian market. By enabling Canada data residency for Check Point SASE, organizations gain greater control over where sensitive network and security telemetry is processed, helping organizations support their compliance efforts with Canadian privacy and data residency requirements without compromising enterprise-grade security capabilities. Key SASE data, including traffic inspection and session data, security event logs, metadata, and tenant configuration,[HK1] [IP2] [IP3]  is processed and stored within Canada, giving security, IT, and compliance teams greater transparency when addressing regulatory or audit requirements around data location.

Check Point SASE’s Canada data residency capability is designed to support organizations’ compliance efforts by helping ensure that critical network and security telemetry remains within Canada.[HK4] [IP5] [HK6]  Other key benefits include:

  • Processing and storage of key SASE data within Canada, including traffic inspection, session data, logs, metadata, and configuration[HK7] [IP8] [IP9] 
  • Support for Canadian privacy and data residency requirements without reducing security capabilities
  • Full access to the complete Check Point SASE platform, including Private Access (ZTNA), Internet Access (Secure Web Gateway), and SaaS Security (CASB)
  • Local data handling combined with global scale, backed by Check Point’s worldwide backbone and high-availability architecture

Canada joins the United States, European Union, India, and Australia as a fully supported data residency region for Check Point SASE, reflecting the company’s continued investment in regionally aligned security architectures that meet customers where their regulatory requirements are. Check Point SASE support teams operate globally, and customer information is handled solely as required to support service delivery

Availability

Check Point SASE Canada data residency is generally available to new customers immediately. Existing customers requiring Canada data residency should contact their Check Point representative to discuss onboarding options.

156 deepfakes targeted U.S. officials in the past two years: Cybernews

Posted in Commentary with tags on April 28, 2026 by itnerd

New research by Cybernews reveals that there have been 156 deepfake incidents targeting currently-serving U.S. officials in the past two years. Most of them are of Donald Trump. The research analyzed deepfakes of the President, Vice President, Cabinet members, governors, and Congress members.

Here are the key findings:

  • 23 out of 602 currently-serving U.S. officials were targeted at least once during the analyzed period.
  • In the past two years, there have been 156 deepfake instances of currently serving U.S. government officials. President Donald Trump alone accounts for 90 of the 156 instances recorded, or 58% of all deepfake incidents in the dataset.
  • The next most targeted figures are Marco Rubio (13 instances) and JD Vance (12 instances). Together, the top three account for 115 out of 156 instances, or 73.7% of all recorded cases.
  • 76% of deepfakes targeted Republicans – but without Trump, the distribution is more balanced.
  • The most-deepfaked democrat is Alexandria Ocasio-Cortez with 9 instances recorded.
  • The likelihood of being targeted by deepfakes drops sharply in larger groups, such as the House and Senate, where individual members are less visible and less recognized by the media.

For more information and visuals, here’s the full report: https://cybernews.com/ai-news/most-deepfaked-us-government-officials

Canada’s fragmented health records – could AI help connect them?

Posted in Commentary with tags on April 28, 2026 by itnerd

Canada’s healthcare system is still struggling with a basic challenge: patient information doesn’t always move easily between providers.

According to insights referenced in TELUS Health’s new Agentic AI discussion paper71% of physicians say interoperability across data and records would significantly reduce administrative burden. Yet many electronic medical record systems still function primarily as digital filing cabinets – storing information rather than helping care teams coordinate it.

The paper explores how AI-powered EMRs could help bridge that gap. By connecting data across providers, pharmacies, virtual care platforms, and health authorities, AI tools can help clinicians track longitudinal patient information, surface relevant insights, and coordinate care more effectively across settings.

For clinicians managing hundreds or even thousands of patients, that kind of system support can be critical – helping identify care gaps, monitor trends, and reduce the manual work required to piece together fragmented patient histories.

The discussion paper also examines how these systems can operate within Canada’s strict healthcare privacy frameworks. Solutions are designed to work within regulated environments governed by legislation such as PHIPA and PIPEDA, while supporting secure collaboration across care teams.

You can read the discussion paper here:

EN: https://go.telushealth.com/hubfs/whitepapers/telus-health-agentic-ai-discussion-paper-en.pdf
FR: https://go.telushealth.com/hubfs/whitepapers/telus-health-agentic-ai-discussion-paper-fr.pdf

Park Place Technologies Partners with Professional Athlete Genie Bouchard as “Genie from IT” in New TV Commercial

Posted in Commentary with tags on April 28, 2026 by itnerd

Park Place Technologies is serving up a fresh take on B2B brand storytelling by partnering with professional pickleball star Genie Bouchard for a new TV and streaming commercial and social media series themed around the “Genie from IT.” 

In the 30-second spot, Bouchard in her first TV commercial, steps into the role of the “Genie from IT,” a playful yet powerful representation of how Park Place helps customers eliminate complexity, respond quickly when issues arise and keep critical systems running smoothly. Just as a genie grants wishes, Park Place removes friction from IT operations so organizations can focus on what matters most.

The spot will begin to stream online this week (April 27) and in all PPA Tour and MLP coverage, such as Pickleball TV, Fox Sports 1 and 2, ESPN 1 and 2 and CBS and then will air on CBS-TV during the May 2 Atlanta Pickleball Championships. Beyond the screen, Bouchard, who will compete in this summer’s Wimbledon’s Legends, will represent Park Place both on and off the court, sporting the company’s logo during competitions and connecting directly with customers through hands-on experiences such as Play-with-a-Pro clinics.