Archive for April, 2026

Microsoft’s Outlook.com Email Seems To Be Having Issues

Posted in Commentary with tags on April 27, 2026 by itnerd

I have received two calls today about people having issues with Outlook.com email accounts (which can be also hotmail.com). Here’s what they are reporting:

  • Outlook on iPhone is making users sign in.
  • You go through the steps to sign in and you still get a prompt to sign in.
  • Removing and re-adding the account does not fix this. Mi

I’ve been able to replicate this myself.

This issue seems to be widespread based on Down Detector which has similar reports of this issue. Microsoft’s Service Status page as well as on Twitter confirm this as well:

Thus it is safe to say that Microsoft has an issue that it is trying to wrap its hands around. There does not appear to be an ETA to resolution. Thus users of Outlook.com will have to wait it out until Microsoft fixes this.

TELUS Friendly Future Foundation Gala returns with headliner Lionel Richie

Posted in Commentary with tags on April 27, 2026 by itnerd

The TELUS Friendly Future Foundation announced its third annual gala will take place on June 18, 2026 at the iconic TELUS Centre for Performance and Learning in Toronto. As young Canadians face increasing challenges ranging from mental health concerns to employment barriers and financial hardship, the gala brings together Canada’s business, philanthropic, technology, and cultural leaders to raise funds to address these urgent issues. Since its inception, the TELUS Friendly Future Foundation, with the support of the 13 Canadian TELUS Community Boards, has provided $137 million to support youth across Canada. In 2025 alone, the Foundation exceeded $10 million in impact through grants that fuel critical youth-focused health and education programs and student bursaries that empower the next generation of changemakers to pursue their post-secondary dreams.

All funds raised from the gala directly support the TELUS Friendly Future Foundation’s mission to help youth reach their full potential through two vital programs:

  • The TELUS Student Bursary awards up to $5,000 annually to more than 500 deserving post-secondary students facing financial barriers and committed to giving back to their communities. Beyond financial aid, recipients gain access to comprehensive wraparound support including free or heavily discounted TELUS Mobility and Internet for Good plans, mental health services through TELUS Health and professional development opportunities. Since launching in 2023, the program has supported 2,000 students, with more than 50 per cent of all recipients being the first in their families to pursue higher education. 
  • TELUS Community Board Grants, which help fund critical, youth-serving charitable programs. The Foundation and its 13 Canadian TELUS Community Boards provide $6 million in grants annually to more than 500 local charities across the country. These grants support innovative, technology-enabled health and education programs that help millions of youth develop critical skills, confidence, and a deep sense of belonging in their communities.

The Together for Tomorrow Gala has become Canada’s premier philanthropic event dedicated to youth empowerment. Building on the success of the first two galas – which raised over $5 million – this year’s event, hosted by television personality Cheryl Hickey, promises an extraordinary evening of entertainment and impact. The night will culminate with an exclusive, one-night-only headline performance by four-time Grammy award winner Lionel Richie. Following the gala, guests are invited to continue the celebration at the afterparty with DJ Jake Wahlberg. A live auction will offer exclusive experiences and opportunities, giving guests the chance to bid on unique items while directly supporting the Foundation’s mission.

The Foundation would like to express a special thanks to TELUS, its many sponsors, donors and volunteers who help make this remarkable event possible.

For more information about the TELUS Friendly Future Foundation Gala, please visit friendlyfuture.com/gala. To learn more about gala sponsorship and attendance, please email info@friendlyfuture.com

KAYAK Launches Ask AI

Posted in Commentary with tags on April 24, 2026 by itnerd

KAYAK today introduced Ask AI, a new conversational travel planning experience designed to help travellers search, compare, and book trips more easily, as interest surges ahead of this summer’s World Cup.

Building on KAYAK’s mission to make travel search more personalized and conversational, Ask AI is an industry first that lets travellers start planning their trip in a chat—while flight, hotel and rental car results update live alongside the conversation, combining the ease of AI with the power of a traditional results page.

Launching just as travel interest ramps up around the World Cup, Ask AI arrives at a time when travelers are planning more complex, multi-city trips. KAYAK data already shows a 12 per cent increase in flight searches to Canadian host cities, including Toronto seeing a 19 per cent increase and Vancouver seeing a 5 per cent increase compared to last summer, with prices and availability expected to shift quickly in the months ahead.

Plan Your Trip with Ask AI
Whether you’re travelling to one match or several, Ask AI helps you move from inspiration to booking in one continuous experience. Search for hotels near a stadium, compare flights between host cities, or build your full itinerary—all without switching tabs.

With Ask AI, travellers can:

  • Ask questions using natural language and refine their trip in real time
  • Chat while results update live alongside the conversation
  • See up-to-date prices and bookable options from hundreds of travel partners

No restarting searches or juggling tabs—just a faster, more intuitive way to plan and book travel.

Tracking World Cup Travel Trends in Real Time

KAYAK is also launching a new dashboard to track how fans are planning trips around the World Cup. Powered by KAYAK’s search and pricing data, it highlights rising travel interest, shifting prices, and the destinations seeing the biggest spikes in interest.

Early trends show:

  • Toronto is emerging as Canada’s top host city, with flight searches up 19 per cent year-over-year outpacing Vancouver’s 5 per cent increase 
  • Hotel prices are climbing across all host markets: up 55 per cent in Canada, 36 per cent in the U.S., and 119 per cent in Mexico
  • Outside of U.S. and Canada interest, Germany and the UK are the regions searching most for travel to Toronto and Vancouver. 

Together, Ask AI and the World Cup Trends Dashboard help travelers plan and compare trips with real-time data, making it easier to make informed decisions as prices and interest change.

Methodology 

Based on flight and hotel searches made on KAYAK in the period between 12.5.2025 and 4.12.2026 for travel between 6.10.2026 and 7.20.2026. They were compared to searches made in the period between 12.5.2024 and 4.12.2025 with the travel period between 6.10.2025 and 7.20.2025. Percentages for changes in searches and pricing are approximate. 

Unit 42 Research: Fully Autonomous AI Attacks Closer Than Ever

Posted in Commentary with tags on April 23, 2026 by itnerd

Palo Alto Networks has shared new research regarding how effective autonomous AI offensive capabilities are against cloud environments. While Unit 42 did not use frontier AI models in testing, this research is a crucial look at how powerful AI models may ultimately be weaponized in cyberspace.

Building on the November 2025 Anthropic disclosure that showed AI acting as the operator in an espionage campaign, Unit 42 answers the question: Can AI systems operate autonomously end-to-end to attack cloud environments, or do they still require human guidance?

Unit 42’s research & findings include:

  • Unit 42 created “Zealot,” a multi-agent penetration testing proof-of-concept designed to see if AI could independently take down a hardened cloud environment without any human oversight.
  • In sandboxed GCP tests, the multi-agent system autonomously executed a full attack chain, including: Server-Side Request Forgery (SSRF) exploitation, Metadata service credential theft, service account impersonation and privilege escalation and BigQuery data exfiltration.
  • AI-driven attacks have reached functional maturity and current LLMs can chain attacks with minimal human guidance. The window between initial access and data loss is shrinking as tools like Zealot leverage misconfigurations faster and more consistently than a human attacker. 
  • However, creating a purely autonomous multi-agent cyber attack was not entirely possible (manual oversight was needed to prevent the AI from irrelevant rabbit-holing).
  • Current security detection models optimized for human attack patterns will struggle to catch agent-based operations that chain actions across services in seconds.

You can read the research here: https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/

Check Point Software Earns 2026 Technology Innovation Leadership Recognition for Prevention‑first WAF and API Security

Posted in Commentary with tags on April 23, 2026 by itnerd

Check Point today announced it has been honored with Frost & Sullivan’s 2026 Technology Innovation Leadership recognition for its advancements in web application and API protection (WAAP). The new recognition illustrates how Check Point’s prevention-first strategy and open-source contributions have established a new benchmark for securing modern digital architectures.

Check Point WAF is purpose-built to protect modern, cloud-native and AI-powered applications in real time. As applications grow more dynamic, organizations need security that prevents threats before they impact the business, helping customers move forward with confidence while reinforcing Check Point’s leadership in the future of cyber security.

Frost & Sullivan highlights that as enterprises accelerate adoption of cloud-native architectures, APIs, and AI-driven applications, the attack surface has expanded well beyond traditional security tools. Check Point’s Cloud Security Report reinforces this urgency, finding that 65% of organizations have experienced cloud-related breaches. Frost & Sullivan recognizes Check Point for solving these challenges head-on, with its WAF and API security platform emerging as an alternative to legacy solutions that struggle to defend against today’s sophisticated attacks.

The report highlights several key strengths of Check Point WAF, primarily focusing on its advanced AI capabilities, unified platform approach, and operational efficiency:

  • Advanced Dual-Layer AI Engine: Delivers close to 100% threat detection with fewer than (<1%) false positives, preemptively blocking all attack types, including zero-days without the need for emergency patching, giving security teams high-confidence protection
  • Unified Application Security Across the Full Attack Surface: Consolidates WAF, API, GenAI, bot, DDoS, file security, and CDN capabilities, eliminating the fragmented point solutions that create blind spots and increase administrative overhead
  • Operational Efficiency and Automation: Eliminates manual rule creation and signature updates via self-learning Al, continuously adapting to application changes, reducing false positives, emergency patching cycles, and operational lifts
  • A Community-Driven Model That Accelerates Innovation: Commitment to transparency and collective intelligence enables a community-driven approach to threat hardening, accelerating updates for emerging threats and techniques

The results speak for themselves: <1% false positives, automatic prevention of zero-day threats without emergency updates, and incident response times are measured in hours rather than days. Security and application teams see significant reductions in rule management overhead, while end users benefit from improved application availability and reliability. As Frost & Sullivan noted, “by converting continuous learning and runtime observability into instant, customized threat prevention with limited human intervention, Check Point WAF sets a new benchmark for what organizations should expect from a web application firewall in the cloud native and AI era.”
 
To learn more about this recognition, visit the Check Point blog or access the full Frost & Sullivan report here.

Sage launches Sage HCM 

Posted in Commentary with tags on April 23, 2026 by itnerd

Sage today announced Sage HCM, a new human capital management solution for mid-market organizations in North America.

Integrated with Sage Intacct, Sage HCM connects HR, payroll and workforce data with financial management to give organizations clearer visibility and control over workforce costs, often their largest and most dynamic expense, while improving payroll accuracy and supporting better workforce planning.

Launching with Sage HCM are industry capabilities, such as Sage HCM for Construction, designed to help firms connect labour, payroll and job costing in a single system, alongside a new HCM Agent that uses AI-powered automation to streamline HR and payroll workflows.

Sage will showcase Sage HCM at Sage Future, taking place in San Francisco from April 28-30.

Bringing workforce costs into clearer financial view

For many organizations, workforce data still sits in separate HR, payroll and finance systems, making it harder for HR leaders, payroll teams and CFOs to understand workforce costs and performance. According to Deloitte’s Human Capital Trends research, nearly three quarters (74%) of organizations say improving how workforce data supports decision-making is now a critical priority.

Sage HCM is designed to address this challenge by bringing core HR, payroll, time and talent workflows together in one connected system. Built for mid-market organizations with more complex requirements, including multi-entity operations and multi-jurisdiction payroll, it helps customers gain a clearer view of workforce costs and their impact on business performance.

Designed for industry needs, including construction

As part of this launch, Sage HCM for Construction extends these capabilities for firms managing complex labour and project-based operations. It includes support for union rules, certified payroll and prevailing wage requirements, while linking labour data directly to project financials.

AI-powered support for HR and payroll workflows

Sage HCM launches with the HCM Agent, Sage’s first AI agent dedicated to HR and payroll workflows. It helps organizations streamline tasks such as payroll preparation, validation and reconciliation, while highlighting potential compliance risks and reducing manual effort.

The HCM Agent is designed to improve efficiency and accuracy without reducing oversight, helping teams automate routine work while maintaining control over critical processes such as payroll and compliance.

New opportunities for partners

The launch of Sage HCM also creates new opportunities for Sage partners to support customers with workforce management, payroll and compliance alongside finance transformation. Partners can deliver Sage HCM together with Sage Intacct and industry-specific solutions, helping customers bring workforce and financial data together in a more connected system.

To get hands-on experience with Sage HCM, sign up to attend Sage Future here: Sage Future

Hisense Unveils UR9 Series

Posted in Commentary with tags on April 23, 2026 by itnerd

Hisense today announced the global launch of its latest premium television lineup, the UR9 Series.

More than a product launch, UR9 represents a new interpretation of “Natural and Real Colour” — one that is not only more vivid, but also more natural, comfortable and true to life for everyday viewing. At the heart of UR9 is a breakthrough in how colour is created and experienced. By generating colour directly at the light source, UR9 delivers richer tones, more accurate details and a viewing experience that feels closer to how the human eye perceives the real world — reducing visual fatigue while enhancing immersion.

This leap in user-centric experience comes from Hisense’s industry-leading RGB Mini-LED technology. In March 2026, the Consumer Technology Association (CTA) Video Division Board released the official industry definition for RGB LED TVs. As a CTA member, Hisense is a major force in establishing the global industry standard of what real RGB Mini-LED is, and continues to push the boundaries of conventional display technology.

At the forefront of this innovation, the Hisense UR9 Series represents a quantum leap in display engineering. Moving beyond traditional Mini-LED, it introduces a full RGB Mini-LED backlight system, where each LED integrates independent red, green and blue diodes — enabling unprecedented control over colour, brightness and contrast. This architecture achieves up to 100 per cent of BT.2020 colour gamut, delivering colour performance that is not only more expansive, but also more precise and lifelike.

Powering this breakthrough is the all-new Hi-View AI Engine RGB processor. Through real-time coordination of colour and brightness at the zone level, the processor ensures every frame is dynamically optimized — bringing greater depth, clarity and balance to each scene.

Beyond visual excellence, the UR9 is engineered as a complete sensory experience. Its integrated 4.1.2 Multi-Channel Surround Sound system, professionally tuned by Devialet, creates a fully immersive 360-degree soundscape. Featuring up-firing height speakers, dedicated surround channels and a powerful built-in subwoofer, the system delivers cinematic depth, dynamic range and spatial realism without the need for external equipment.

To ensure consistently comfortable viewing across environments, UR9 also delivers up to three-times deeper blacks and higher contrast, allowing for clearer details even in bright daylight. The Obsidian Panel reduces reflections to just 1.5–1.8 per cent by absorbing ambient light. For gaming enthusiasts, a native 180Hz refresh rate on selected models delivers ultra-smooth motion and responsiveness, enhancing next-generation gaming experiences to new heights.

Supporting a comprehensive suite of premium formats — including Dolby Vision IQ, IMAX Enhanced, and Filmmaker Mode — the UR9 is built to meet the evolving demands of both content creators and consumers. Its performance is complemented by a refined Pure Elegance Design, featuring a premium metal stand and a near bezel-less finish that seamlessly integrates into any modern living space.

With the launch of the UR9, Hisense brings its vision of Innovating A Brighter Life into sharper focus. By redefining “Natural and Real Colour” through true RGB Mini-LED, Hisense is not only advancing display technology, but shaping a viewing experience that is more natural, more immersive and more human-centric.

For more information, please visit hisense-canada.com.

ESET Research: New NGate hides in NFC payment app and possibly built with AI

Posted in Commentary with tags on April 23, 2026 by itnerd

ESET Research has discovered a new variant of the NGate malware family that abuses a legitimate Android application called HandyPay, instead of the previously leveraged NFCGate tool. The threat actors took the app, which is used to relay NFC data, and patched it with malicious code that appears to have been AI generated. As with previous iterations of NGate, the malicious code allows the attackers to transfer NFC data from the victim’s payment card to their own device and use them for contactless ATM cash-outs and unauthorized payments. Additionally, the code can capture the victims’ payment card PINs and exfiltrate them to the operators’ C&C server. The primary targets of this are users in Brazil; however, NFC-based attacks are expanding into new regions.

The malicious code used to trojanize HandyPay shows signs of having been produced with the help of GenAI tools. Specifically, the malware logs contain an emoji typical of AI-generated text, suggesting that LLMs were involved in generating or modifying the code, although definitive proof remains elusive. This fits a broader trend in which GenAI lowers the barrier to entry for cybercriminals, enabling threat actors with limited technical skill to produce workable malware.

ESET Research believes that the campaign distributing the trojanized HandyPay began around November 2025 and remains active. It should also be noted that the maliciously patched version of HandyPay has never been available on the official Google Play store. As an App Defense Alliance partner, we shared our findings with Google. ESET also reached out to the HandyPay developers to alert them about the malicious use of their application. 

As the number of NFC threats keeps rising, so too has the ecosystem supporting them become more robust. The first NGate attacks employed the open-source NFCGate tool to facilitate the transfer of NFC data. Since then, several malware-as-a-service (MaaS) offerings with similar functionality have become available for purchase. However, in this campaign the threat actors decided to go with their own solution and maliciously patched an existing app – HandyPay.

The first new NGate sample is distributed through a website that impersonates Rio de Prêmios, a lottery run by the Rio de Janeiro state lottery organization (Loterj). The second NGate sample is distributed via a fake Google Play web page as an app named Proteção Cartão (machine translation: Card Protection). Both sites were hosted on the same domain, strongly implying a single threat actor. The malware abuses the HandyPay service to forward NFC card data to an attacker-controlled device. Apart from relaying NFC data, the malicious code also steals payment card PINs, enabling the threat actor to use the victim’s payment card data to withdraw cash from ATMs.

For a more detailed analysis of the new NGate variant, check out the latest ESET Research blog post, “New NGate variant hides in a trojanized NFC payment app,” on WeLiveSecurity.com. 

Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware

Posted in Commentary with tags on April 22, 2026 by itnerd

Researchers have uncovered malicious Namastex.ai npm packages with the tradecraft of TeamPCP/LiteLLM style CanisterWorm malware, including install-time execution, credential theft from developer environments, off-host exfiltration, canister-backed infrastructure, and self-propagation logic intended to compromise additional packages.

More details here: https://socket.dev/blog/namastex-npm-packages-compromised-canisterworm

Dan Moore, Sr. Director CIAM Strategy at cybersecurity company FusionAuth, commented:

“This newest supply chain threat in the npm ecosystem demonstrates that a lot of the time, the issue isn’t an organizations’ code, but their credentials. Long-lived, over-permissioned CI/CD tokens are as risky as passwords written on a sticky note. Organizations need to have more than credentials for software systems. In order to maintain identity hygiene, organizations should rotate, scope, and continually monitor credentials.”

AI for coding is great. But you have to be incredibly careful to make sure that the benefit of being able to code more efficiently isn’t overshadowed by having threat actors set up shop by infecting your code.

Lovable access issue exposes project data, credentials in AI-generated coding

Posted in Commentary with tags on April 22, 2026 by itnerd

A security issue involving AI coding platform Lovable allowed users to access other users’ project data, including source code, database credentials, AI chat histories, and customer data, according to reports and user disclosures.

The issue was publicly highlighted after a user demonstrated that a free account could access data across projects created before November 2025.

Lovable initially stated there was no data breach, describing the behavior as expected for public projects, but later acknowledged a backend error that temporarily enabled access to AI chat data. The company updated its visibility and permission settings following the incident and said the issue had been addressed.

The incident involved exposure of project-level data within the platform environment and did not include confirmation of broader system compromise. Reporting indicates the issue remained unresolved for a period of time after being reported before changes were implemented.

Ryan McCurdy, VP of Marketing, Liquibase had this to say:

   “This incident is a reminder that the risk in AI-generated development is not just bad code. It is bad control design. When application creation speeds up, permissions, secrets exposure, and database access paths can become part of the attack surface just as quickly. If teams do not put governed change, least-privilege access, and clear separation between public artifacts and sensitive backend context in place, AI can amplify operational risk faster than traditional review processes can catch it.”

John Carberry, Solution Sleuth, Xcape, Inc. adds this comment:

   “The Lovable data exposure incident highlights a catastrophic failure in the fundamental security architecture of AI-powered “vibe coding” platforms. By failing to implement basic ownership validation on API endpoints, a textbook Broken Object Level Authorization (BOLA) flaw. Lovable allowed any user to traverse project IDs and scrape the source code, database credentials, and AI chat histories of others.

   “For security leaders, the primary risk is a silent supply chain compromise: while Lovable claims no “breach” of its own servers, the exposure of third-party secrets like Stripe and Supabase keys means the applications built on the platform are now effectively backdoored.

   “Technically, the crisis was compounded by a February 2026 backend regression that re-opened access to sensitive chats and a response cycle that spent 48 days ignoring a bug bounty report. Organizations must treat AI-generated code with extreme caution, ensuring that “vibe coding” speed doesn’t bypass mandatory secret scanning, environment variable isolation, and the hard-won security logic of the last twenty years.

   “Lovable proved that while AI can write your code, it can’t write your common sense, especially when “public by default” includes your Stripe secret keys.”

Hannah Perez, Director of Marketing, Suzu Labs followed up with this:

   “As we move toward AI-generated software, the ‘shared responsibility model’ is becoming dangerously blurred. Users expected a private sandbox for innovation, but instead found a communal space with paper thin walls.

   “Lovable’s eventual pivot is welcome, but the delay between the initial report and the actual fix suggests that AI startups are currently outpacing their own security protocols, which is as expected for most. In the rush to ‘vibe code,’ fundamental safety is being treated as a post-launch patch rather than a requirement. For this industry to mature, Secure by Default must be the non-negotiable standard for any platform handling sensitive IP and source code.”

Vishal Agarwal, CTO, Averlon provided this comment:

   “It’s one thing to have access to the sauce. It’s another to have access to its recipe. With inadvertent leakage of chat history, attackers gain access to reconnaissance information that can be leveraged to target the organization more precisely.

   “What makes sophisticated attackers dangerous isn’t just their technical capability, it’s their detailed understanding of the target’s systems. Exposing chat history and source code together hands that understanding directly to an attacker.”

This highlights the fact that AI has to be part of your security planning. Otherwise really bad things will happen. And this is a case in point.