Archive for April, 2026

Black Kite and Sayari Partner to Deliver Integrated Intelligence Across Cyber, Supply Chain, and Corporate RiskNew integration combines global corporate transparency

Posted in Commentary with tags on April 29, 2026 by itnerd

Black Kite today announced a strategic partnership and integration with Sayari, a leading provider of global corporate transparency and supply chain risk intelligence. Together, the two companies are enabling organizations to gain a unified view of third-party risk by combining deep visibility into global corporate and trade networks with continuous cyber risk monitoring.

As organizations face increasing pressure to manage risk across complex, global supply chains, many struggle with fragmented data spread across multiple tools and teams. This partnership addresses that challenge by bringing together Sayari’s unmatched insight into corporate ownership, trade activity, and hidden commercial relationships with Black Kite’s objective, standards-based cyber risk ratings and real-time threat intelligence.

Through the integration, customers can enrich third-party risk assessments with both who an entity is connected to and how exposed they are from a cyber perspective—providing a more complete and actionable understanding of risk across the extended enterprise.

Sayari’s platform delivers visibility into complex commercial relationships using one of the world’s largest collections of corporate and trade data, spanning over 250 jurisdictions worldwide. By integrating this intelligence directly into Black Kite’s platform, customers can more easily identify hidden ownership structures, upstream supply chain dependencies, and potential exposure to financial crime or geopolitical risk—while simultaneously assessing cyber posture.

The combined solution supports a wide range of use cases, including:

  • Enhanced due diligence through enriched corporate ownership and cyber risk insights
  • Supply chain risk management with visibility into N-tier suppliers and their vulnerabilities
  • Financial crime and compliance by correlating beneficial ownership with cyber posture
  • Government and national security applications requiring both transparency and cyber resilience
  • M&A and third-party onboarding with faster, more comprehensive risk assessments

By reducing manual research and connecting previously siloed data, the Black Kite and Sayari integration enables organizations to prioritize risk more effectively, accelerate investigations, and strengthen resilience across their third-party ecosystem.

The partnership reflects a shared commitment to helping organizations navigate the growing complexity of global risk with greater clarity, speed, and confidence.

There is a related webinar that was done in April called From Fragmented Signals to Connected Risk Intelligence, available to watch on-demand.

Team Cymru Launches Pure Signal MCP Server

Posted in Commentary with tags on April 29, 2026 by itnerd

Team Cymru today announced the general availability of the Pure Signal™ MCP Server, the first purpose-built, production-grade Model Context Protocol (MCP) server for threat intelligence. Available immediately, the server connects any MCP-compatible AI agent — including Claude, Microsoft Security Copilot, Copilot Studio, GitHub Copilot and custom agents — directly to Team Cymru’s Pure Signal platform, the world’s largest threat intelligence data ocean.

Cybersecurity teams are deploying AI agents to automate alert triage, accelerate threat hunting, and orchestrate incident response, with AI agents forecasted to be the primary consumers of threat intelligence within the next 18 to 24 months. MCP, an open standard introduced by Anthropic, has rapidly become the de facto interface between AI agents and the external data and tools they rely on, with Microsoft, Google, Anthropic and every major AI development platform now supporting it.

A Different Kind of MCP Server

Most threat intelligence vendors view MCP as a thin wrapper over their existing REST APIs. Team Cymru took a different path. The Pure Signal MCP Server is integrated into the existing API surface but layers purpose-engineered processing on top: responses are concise, context-rich and token-efficient by design, preserving the LLM’s context window so agents spend tokens reasoning about threats rather than parsing raw payloads.

Through a single MCP connection, AI agents gain native access to the full breadth of Team Cymru’s Pure Signal platform:

  • IP & Domain Intelligence — Full detail lookups including summary, communications, tags, maliciousness scoring, open ports, and behavioral context.
  • NetFlow Communication Patterns — Observe who an IP is communicating with across the global internet, the data only Team Cymru has at this scale.
  • Passive DNS (PDNS) — Historical DNS resolution data revealing infrastructure relationships over time.
  • X.509 Certificates — Certificate details exposing shared infrastructure, hosting patterns, and attribution signals.
  • WHOIS Intelligence — Registration data with pivoting capability for infrastructure mapping.
  • Scout Query Language — AI agents can construct and execute sophisticated queries using Team Cymru’s native search syntax.
  • Usage & Quota Management — Programmatic visibility into API consumption for governance and cost control.

Built for the Teams Defending the Internet

Pure Signal MCP delivers immediate value across every layer of the security organization. SOC teams can connect AI-powered triage agents to Pure Signal for instant indicator enrichment, reducing mean time to investigate from hours to minutes. Threat intelligence teams can task AI agents with autonomous hunting across the global internet using the same data that has powered Team Cymru’s government and Fortune 500 customers for two decades.

Security engineers and architects can integrate Pure Signal into custom AI workflows, multi-agent systems, and automated response pipelines through a single MCP connection rather than a sprawl of bespoke integrations. MSSPs and managed service providers can differentiate their offerings with AI-powered intelligence and scale analyst capacity without scaling headcount. CISOs and security leaders gain a clear, demonstrable path to AI-readiness backed by production-grade infrastructure.

Availability

Documentation, integration guides, and authentication setup are available at mcp.cymru.com/docs. Prospective customers can request a free trial at team-cymru.com or contact sales for an AI-native threat intelligence briefing. 

The Pure Signal MCP Server is generally available today to all Team Cymru Pure Signal customers, at no additional cost, by visiting https://www.team-cymru.com/mcp-server.

DevOps Incidents Rise by 21%, While Impact Hours Double to 9,255

Posted in Commentary with tags on April 29, 2026 by itnerd

The DevOps Threats Unwrapped Report 2026, a data-driven report from GitProtect.io is now online and worth your time to read.

The report identifies key incidents and weaknesses across leading DevOps platforms.

Some key findings include:

  • 21% year-over-year increase in incidents (607 vs. 502), with their time of disruption surged by nearly 95%, jumping from 4,755 to 9,255 hours. 
  • 156 incidents were classified as critical or major, lasting 1,769 hours and 43 minutes. That’s a 69% year-over-year increase in the most severe incidents – a clear signal that the risk landscape is intensifying.
  • Platforms’ degraded performance drives 62% of outages.
  • In 2025, GitLab recorded the highest cumulative number of critical and major incidents (62), totaling over 754 hours of impact. Jira followed closely with 44 incidents resulting in nearly 728 hours of downtime.

You can read the report here: https://gitprotect.io/devops-threats-unwrapped-2026.html

Deepgram Launches Flux Multilingual

Posted in Commentary with tags on April 29, 2026 by itnerd

Deepgram today announced the general availability (GA) of Flux Multilingual, expanding its conversational speech recognition model beyond English to support 10 languages, with the ability to automatically detect, understand, and switch languages dynamically within a single conversation in real time. Developers, enterprises, and product teams building voice agents now have access to the first real-time conversational speech recognition model, delivering accurate turn-taking, interruption handling, low latency, and natural human-like conversations at global scale. 

Traditional automatic speech recognition (ASR) is designed for transcription. Flux introduced a new approach, conversational speech recognition (CSR), built from the ground up to understand dialogue flow and enable real-time interaction. Flux has rapidly become foundational infrastructure for real-time voice agents, powering production systems that developers trust to deliver fast, natural conversational experiences with best-in-class accuracy in turn detection and speech recognition. Prior to today’s release, extending these experiences across multiple languages required stitching together multilingual transcription models, language detection, and routing logic, introducing latency, complexity, and brittle user experiences. Flux Multilingual replaces that complexity with a single model and API, making it possible to build conversational voice agents across 10 languages without re-architecting systems or sacrificing performance.

With native support for turn-taking, interruptions, and code-switching within a single interaction, voice applications remain fluid, responsive, and natural regardless of language or region. Flux Multilingual delivers monolingual-grade accuracy across languages. Developers can guide the model with language hints or let it auto-detect, adapting in real time even mid-conversation.

Flux Multilingual Capabilities

Supported Languages

English, Spanish, French, German, Hindi, Russian, Portuguese, Japanese, Italian, and Dutch

Ultra-low latency conversational speech recognition, now global

Flux Multilingual is built for understanding and interaction, not just transcription. It uses model-based turn detection, not simple silence detection, to deliver accurate end-of-turn decisions in under 400 milliseconds, keeping conversations fluid and responsive across languages.

Monolingual-grade accuracy with real-time language control

Flux Multilingual delivers monolingual-grade accuracy across languages, with flexible real-time control through language hints or automatic detection, native code-switching, and dynamic adaptation as conversations evolve.

Build and scale global voice agents with one model

Flux Multilingual supports 10 languages in a single conversational model, enabling teams to build and deploy voice agents globally with one integration. One model, ten languages, one API, with no additional infrastructure or model orchestration required.

Key Features

  • Native turn detection and interruption handling for natural dialogue flow
  • Low-latency streaming transcription for real-time responsiveness
  • Automatic language detection and language hint support for accuracy control 
  • Mid-session configurability for dynamic language adaptation
  • Native code-switching within a single conversation
  • Fully compatible with existing Flux API integrations 

Flux Multilingual is now generally available (GA). As part of the launch, Deepgram is offering a limited-time promotional rate on streaming speech-to-text, including Flux Multilingual and Nova-3 models.

Flux Multilingual is available via Deepgram’s Cloud API or as a self-hosted deployment, with support for EU endpoints, SDKs, and seamless integration into voice agent architectures. Developers can get started today at deepgram.com or try Flux Multilingual directly in the Deepgram Playground.

Critical RCE in Hugging Face’s LeRobot

Posted in Commentary with tags on April 28, 2026 by itnerd

Researchers disclosed a critical remote code execution flaw (CVE-2026-25874, CVSS 9.3) in Hugging Face’s open-source robotics platform LeRobot, caused by unsafe deserialization through Python’s pickle format. The issue allows an unauthenticated attacker to send malicious payloads over unsecured gRPC channels and execute arbitrary code on both the policy server and connected robot clients.

You can read more here: https://github.com/advisories/GHSA-f7vj-73pm-m822

Eli Woodward, Cyber Threat Intelligence Advisor, Team Cymru has provided this comment:

     “The bigger issue here is that AI infrastructure is increasingly becoming part of the external attack surface, often without the same visibility defenders have for traditional enterprise systems. Services like this can expose privileged environments that connect directly to valuable internal resources, making them attractive entry points for both financially motivated actors and more advanced threat groups. Once an attacker gains access, the challenge becomes understanding what else that infrastructure is connected to and how quickly they can pivot. External visibility and context become critical because many of these risks originate well beyond the traditional network perimeter. This is also an interesting case where even ‘physical safety’ becomes part of the risk model. While we’ve certainly seen that before in medical devices, the implementation of AI into robotics can create a whole new level of risk we haven’t seen before.”

This is a today problem. Especially since there is no fix at present. Not good in my opinion.

Check Point Software Launches Canada Data Residency for SASE

Posted in Commentary with tags on April 28, 2026 by itnerd

Check Point today announced the availability of Canada data residency for Check Point SASE, enabling Canadian organizations to process and store key SASE security data within Canada.

This expansion follows the recent launch of Check Point WAF and further reinforces Check Point’s commitment to the Canadian market. By enabling Canada data residency for Check Point SASE, organizations gain greater control over where sensitive network and security telemetry is processed, helping organizations support their compliance efforts with Canadian privacy and data residency requirements without compromising enterprise-grade security capabilities. Key SASE data, including traffic inspection and session data, security event logs, metadata, and tenant configuration,[HK1] [IP2] [IP3]  is processed and stored within Canada, giving security, IT, and compliance teams greater transparency when addressing regulatory or audit requirements around data location.

Check Point SASE’s Canada data residency capability is designed to support organizations’ compliance efforts by helping ensure that critical network and security telemetry remains within Canada.[HK4] [IP5] [HK6]  Other key benefits include:

  • Processing and storage of key SASE data within Canada, including traffic inspection, session data, logs, metadata, and configuration[HK7] [IP8] [IP9] 
  • Support for Canadian privacy and data residency requirements without reducing security capabilities
  • Full access to the complete Check Point SASE platform, including Private Access (ZTNA), Internet Access (Secure Web Gateway), and SaaS Security (CASB)
  • Local data handling combined with global scale, backed by Check Point’s worldwide backbone and high-availability architecture

Canada joins the United States, European Union, India, and Australia as a fully supported data residency region for Check Point SASE, reflecting the company’s continued investment in regionally aligned security architectures that meet customers where their regulatory requirements are. Check Point SASE support teams operate globally, and customer information is handled solely as required to support service delivery

Availability

Check Point SASE Canada data residency is generally available to new customers immediately. Existing customers requiring Canada data residency should contact their Check Point representative to discuss onboarding options.

156 deepfakes targeted U.S. officials in the past two years: Cybernews

Posted in Commentary with tags on April 28, 2026 by itnerd

New research by Cybernews reveals that there have been 156 deepfake incidents targeting currently-serving U.S. officials in the past two years. Most of them are of Donald Trump. The research analyzed deepfakes of the President, Vice President, Cabinet members, governors, and Congress members.

Here are the key findings:

  • 23 out of 602 currently-serving U.S. officials were targeted at least once during the analyzed period.
  • In the past two years, there have been 156 deepfake instances of currently serving U.S. government officials. President Donald Trump alone accounts for 90 of the 156 instances recorded, or 58% of all deepfake incidents in the dataset.
  • The next most targeted figures are Marco Rubio (13 instances) and JD Vance (12 instances). Together, the top three account for 115 out of 156 instances, or 73.7% of all recorded cases.
  • 76% of deepfakes targeted Republicans – but without Trump, the distribution is more balanced.
  • The most-deepfaked democrat is Alexandria Ocasio-Cortez with 9 instances recorded.
  • The likelihood of being targeted by deepfakes drops sharply in larger groups, such as the House and Senate, where individual members are less visible and less recognized by the media.

For more information and visuals, here’s the full report: https://cybernews.com/ai-news/most-deepfaked-us-government-officials

Canada’s fragmented health records – could AI help connect them?

Posted in Commentary with tags on April 28, 2026 by itnerd

Canada’s healthcare system is still struggling with a basic challenge: patient information doesn’t always move easily between providers.

According to insights referenced in TELUS Health’s new Agentic AI discussion paper71% of physicians say interoperability across data and records would significantly reduce administrative burden. Yet many electronic medical record systems still function primarily as digital filing cabinets – storing information rather than helping care teams coordinate it.

The paper explores how AI-powered EMRs could help bridge that gap. By connecting data across providers, pharmacies, virtual care platforms, and health authorities, AI tools can help clinicians track longitudinal patient information, surface relevant insights, and coordinate care more effectively across settings.

For clinicians managing hundreds or even thousands of patients, that kind of system support can be critical – helping identify care gaps, monitor trends, and reduce the manual work required to piece together fragmented patient histories.

The discussion paper also examines how these systems can operate within Canada’s strict healthcare privacy frameworks. Solutions are designed to work within regulated environments governed by legislation such as PHIPA and PIPEDA, while supporting secure collaboration across care teams.

You can read the discussion paper here:

EN: https://go.telushealth.com/hubfs/whitepapers/telus-health-agentic-ai-discussion-paper-en.pdf
FR: https://go.telushealth.com/hubfs/whitepapers/telus-health-agentic-ai-discussion-paper-fr.pdf

Park Place Technologies Partners with Professional Athlete Genie Bouchard as “Genie from IT” in New TV Commercial

Posted in Commentary with tags on April 28, 2026 by itnerd

Park Place Technologies is serving up a fresh take on B2B brand storytelling by partnering with professional pickleball star Genie Bouchard for a new TV and streaming commercial and social media series themed around the “Genie from IT.” 

In the 30-second spot, Bouchard in her first TV commercial, steps into the role of the “Genie from IT,” a playful yet powerful representation of how Park Place helps customers eliminate complexity, respond quickly when issues arise and keep critical systems running smoothly. Just as a genie grants wishes, Park Place removes friction from IT operations so organizations can focus on what matters most.

The spot will begin to stream online this week (April 27) and in all PPA Tour and MLP coverage, such as Pickleball TV, Fox Sports 1 and 2, ESPN 1 and 2 and CBS and then will air on CBS-TV during the May 2 Atlanta Pickleball Championships. Beyond the screen, Bouchard, who will compete in this summer’s Wimbledon’s Legends, will represent Park Place both on and off the court, sporting the company’s logo during competitions and connecting directly with customers through hands-on experiences such as Play-with-a-Pro clinics.

Unpatched Windows ‘PhantomRPC’ Flaw Allows Privilege Escalation

Posted in Commentary with tags on April 27, 2026 by itnerd

Researchers have published new findings PhantomRPC: A new privilege escalation technique in Windows RPC on April 24th about a  has no patch as it is said to be an architecture problem, and affects all Windows systems.

In response, three cybersecurity experts offer perspective.

Sameed Aijas Ahmed Khan with Dubai-based Secure.com:

“PhantomRPC is a meaningful finding because it sits at the architectural level of Windows, not in an isolated feature that can simply be switched off or patched. What makes it particularly relevant for organizations is the lateral movement risk. 

Once an attacker has a foothold, a flaw in how Windows systems communicate internally can become a pathway across the broader environment and that kind of silent spread is exactly what makes unpatched vulnerabilities so costly over time. We’ve written about how the Dell zero-day campaign went undetected for over 400 days precisely because the initial entry point wasn’t caught in time.

Architectural changes are genuinely complex, and caution is understandable. But as we’ve covered in looking at the Microsoft Word zero-day earlier this year, the window between disclosure and active exploitation tends to be short and organizations are left managing that risk largely on their own.

When remediation isn’t immediately available, mitigation becomes the working strategy. That means network segmentation to limit unnecessary exposure, tightening access controls around privileged accounts, and increasing monitoring for anomalous behavior in affected systems. As we note in our coverage of vulnerability remediation vs. mitigation, a mitigated vulnerability is still present so the goal is to reduce the blast radius while staying alert to how the situation evolves.”

Jacob Krell, Senior Director, Secure AI Solutions and Cybersecurity, Suzu Labs:

PhantomRPC can turn a lower-privileged service compromise into SYSTEM-level control. For an organization, that means a normal foothold can become full host compromise. From there, an attacker may be able to access sensitive credentials, tamper with security tooling, establish persistence, and use the machine as a staging point for lateral movement. The important point is that this is not just a single bad component. Kaspersky’s research points to a broader weakness in how Windows RPC handles server provenance, which means new abuse paths may continue to appear as researchers and attackers find additional privileged RPC clients.

Microsoft’s decision not to issue a patch makes sense only within a narrow vulnerability-triage model. The issue typically requires SeImpersonatePrivilege, and Microsoft appears to have treated that prerequisite as a limiting factor. The problem is that SeImpersonatePrivilege has been central to Windows privilege escalation research for years. It is not rare, exotic, or purely theoretical. Many real-world compromises already land in service contexts where impersonation privileges are available by design.

That is especially important because service accounts are often one of the first positions an attacker obtains after exploiting a web-facing application or local service. From an attacker’s perspective, the question after that initial foothold is simple: how do I become SYSTEM? PhantomRPC provides one answer by abusing the trust relationship between privileged RPC clients, expected endpoints, and impersonation. That makes the prerequisite less reassuring than it may appear on paper.

Microsoft should remediate the underlying architectural weakness, or at minimum provide stronger platform-level safeguards around RPC endpoint authenticity and privileged impersonation flows. The lesson from the Potato family was that broad impersonation rights can turn service-level access into SYSTEM. PhantomRPC shows that lesson still applies, just through a different IPC path. A flaw that repeatedly converts common service compromise into full host control should not be dismissed simply because the dangerous privilege was granted by design.

To protect themselves, organizations should focus on detection, hardening, and reducing unnecessary impersonation exposure. Kaspersky’s recommended approach is ETW-based monitoring for RPC activity where high-privileged clients attempt to connect to unavailable servers, especially when those calls use elevated impersonation levels. Those failures can indicate places where a malicious RPC server could be inserted.

They should also review which custom and third-party services hold SeImpersonatePrivilege and remove it where it is not strictly required. Where possible, legitimate services should be configured so expected RPC endpoints are actually registered, reducing the opportunity for an attacker to occupy the missing endpoint first. This is not a complete fix, but it reduces the attack surface and gives defenders observable signals.

PhantomRPC should be viewed in the same lineage as the Potato family of Windows privilege escalation techniques. Those exploits showed years ago that service accounts with SeImpersonatePrivilege can become a dangerous bridge to SYSTEM when Windows allows a lower-privileged process to impersonate a higher-privileged caller. PhantomRPC matters because it shows that the underlying design issue was never fully eliminated. The abuse path has moved from familiar COM-based techniques into the RPC layer itself.

That is why treating SeImpersonatePrivilege as a simple prerequisite misses the larger point. The privilege is widely granted to service identities because Windows services need impersonation for legitimate functionality. In practice, that makes it part of the operating system’s architectural attack surface, not an unusual edge condition. If a common service context can register the right endpoint, wait for a privileged client, and inherit its authority, the weakness is in the trust model around impersonation and endpoint provenance.

This is also unlikely to be the last route researchers find. Once the pattern is understood, the question becomes how many other privileged Windows clients connect to expected IPC endpoints without strong enough assurance about who is actually listening. Security teams should treat PhantomRPC less like a one-off vulnerability and more like a signal that Windows IPC and impersonation flows need sustained monitoring, hardening, and architectural attention.

Xcape, Inc. board member Damon Small:

Microsoft’s decision not to patch is technically defensible under their traditional servicing criteria – since the attacker already needs SeImpersonatePrivilege – but it is operationally negligent in a landscape where attackers frequently use compromised service accounts as a beachhead. This “Moderate” rating ignores how easily these prerequisites are met during real-world lateral movement. Since no patch is forthcoming, defenders must treat this as a permanent architectural debt. To be clear, it is not so much that Microsoft decided not to patch, but at this time it appears that it cannot be patched without fundamentally changing how RPC functions.

The most effective mitigation organizations should invoke is to restrict SeImpersonatePrivilege to the absolute minimum number of accounts and utilize Host Intrusion Prevention Systems (HIPS) or EDR rules to monitor for unauthorized processes attempting to bind to known RPC ports, particularly those associated with the Terminal Services port range.

This was reported to Microsoft on September 25, 2025. Microsoft assessed this as a moderate severity, not eligible for a bug bounty, and not in need of a CVE or immediate fix at the time. Because of the fundamental, architectural, nature of this vulnerability, we should expect to see variants on this attack pattern emerge in the future. Defenders should keep an eye on service accounts exhibiting anomalous behavior, such as spawning arbitrary listeners. This publication at this time is indicative of a pattern where Microsoft has downplayed an external researcher’s finding because resolving the underlying issue is a deep architectural change. It is a bold strategy for Microsoft to claim a flaw is not a bug simply because you have to be halfway into the house before you can use it to unlock the safe.

I strongly recommend that you read this report and consider this to be a “today” problem because there is no fix. Which means that it’s only a matter of time for threat actors exploit this if they have not already.