Archive for May 19, 2026

Guest Post: Pressing political topics reduce people’s vigilance against bots

Posted in Commentary with tags on May 19, 2026 by itnerd

More than 700 participants took part in a week-long experiment conducted by Surfshark and MSc students from Malmö University. Of them, 53% correctly identified more bots than they wrongly flagged humans as bots on the simulated social platforms. However, nearly half (47%) failed the task. A cybersecurity expert warns that the number of people unable to tell bots from real humans on social media will continue to grow rapidly.

“The ‘Bot or Not’ game and experiment help us keep connecting the dots and better understand the influence bad bots have on us, real social media users. Earlier this year, we found that major platforms remove over 6.3 billion fake accounts every year — roughly 47 times the annual number of babies born worldwide (around 135 million). Bots are being generated by the billions, and our latest experiment shows that half of the participants can no longer tell them apart from real people. This trend will accelerate, as the technology lets bots blend in seamlessly with real human profiles,” says Justas Pukys, Senior Product Manager at Surfshark.

When our emotions take over, bots thrive

The results of the recent social media bot experiment were eye-opening. The data suggests that engaging with sensitive political or social topics may reduce people’s ability to spot bots and make them more likely to falsely accuse real people.

The moment the “Bot or Not” simulation shifted to a more emotional tone, our participants’ bot-detection skills dropped. When the debate turned political and focused on immigration, participants’ bot-detection rate dropped to 54%, meaning that nearly half the social media bots slipped right past the players. Participants’ accuracy rate also declined to 63%, showing a spike in internet paranoia when participants accused humans of being bots.

The women’s rights topic presented the biggest bot-spotting challenges. The bot-detection rate crashed to 49%, meaning users missed more bots than they found. Worse, their accuracy rate fell to 61%, showing players most often accused real human content of being bot-generated.

“In comparison, while engaging in the data centers, a more technical debate for many, users performed the largest bot-detection rate of 71% (finding the majority of the bots), and a high (76%) accuracy rate. This suggests that when not directly emotionally triggered, we could detect more AI bots and are less likely to falsely accuse real humans,” explains Luís Costa, Research Lead at Surfshark.

The “Bot or Not” game is now online for everyone to play and take part.

Can we distinguish who is who on social platforms in the future?

“The experiment’s results are novel and significant. They suggest we can’t simply ‘read’ our way out of ‘botted’ social media. Bot-detection skills appear to be shaped by age, preferred platforms, and time spent on them. But the most striking finding was that our biggest blind spot is emotion: when debates get heated, it hijacks our digital radar.

To fight back against automated deception, we don’t need better textual analysis. We need a cooler head and a deeper awareness of our own vulnerabilities,” claims Luís Costa.

Justas Pukys, a cybersecurity expert at Surfshark, shares practical recommendations.

“Don’t forget to double-check the information you find on social media. Also, don’t take everything random users post at face value. Be careful when accepting and interacting with private messages that offer you prizes, invite you to click on strange links, or try to grab your attention with lines like ‘Your family member has been in an accident!’,” he advises.

The expert also highlights the importance of digital security hygiene, such as using anti-scam tools daily. They will help you analyze the content of emails, text messages, and websites and assess whether it has been generated by bots or other attackers.

This “Bot or Not” experiment inspired the launch of Surfshark’s Cybersecurity Advocacy Fund, which provides up to €100,000 in annual financial support distributed among students, researchers, and creative cybersecurity awareness initiatives worldwide. The upcoming application process will open in September 2026 — more information will follow.

METHODOLOGY

This bot-detection study analyzed data from 710 participants who played the interactive simulation “Bot or Not.” This machine and gameplay were created by Interaction Design students from Malmö University for the UNFOLD exhibition — a design competition for universities around the world during Milan Design Week, the world’s largest trade fair. Throughout the week-long public exhibition, visitors were invited to take part in the experiment.

Please find the full research methodology here.

Bonfy Launches Contextual Data Enforcement

Posted in Commentary with tags on May 19, 2026 by itnerd

Bonfy has announced Contextual Data Enforcement, a new capability in the Bonfy platform that introduces a control layer between AI clients and enterprise data, enabling organizations to govern what content AI systems can retrieve and use in real time—beyond native user permissions, and without new infrastructure.

The problem is simple and dangerous: AI agents, assistants and coding tools such as Claude, Copilot, and ChatGPT are being adopted at an accelerated rate across the enterprise. Very quickly, organizations are discovering a sharp mismatch: AI clients can connect to SharePoint, Google Drive, and other data stores instantly, but the underlying security tooling has no way to enforce content-level policies on what those AI systems retrieve. Native permissions determine what users can access. They do not determine what AI should be allowed to retrieve, use, or expose. The result is a significant and growing security blind spot with long-term implications.

A Missing Layer — Now Filled

Bonfy provides a governed connector path that intercepts and controls data retrieval performed through AI clients. As content flows back from Microsoft 365 or Google Workspace, Bonfy inspects it in real time, applying entity-aware, context-rich analysis, and blocks content that violates policy before it reaches the AI clients.

What the Platform Delivers

  • Control what AI can retrieve and use — enforce policies beyond user permissions 
  • Protect sensitive and customer data — even when users have access 
  • No infrastructure changes — no gateways or architectural overhaul 
  • Preserve identity context — never expands user access 
  • Works across AI clients — compatible with Claude, Copilot, ChatGPT and others 

Why This Matters Now

Security teams are being asked to enable AI agents and assistants across enterprise workflows—often before they have visibility into what data those systems will retrieve and use.

Once AI clients connect to Microsoft 365, SharePoint, or Google Drive, they inherit the user’s access and can retrieve large volumes of enterprise data. But native permissions do not determine what an AI system should be allowed to retrieve, ground on, or expose.

This creates a critical gap between access control and data protection—one that is already impacting real enterprise workflows.

Bonfy’s approach is different: built on the existing Bonfy engine that today protects email, browser flows, and file sharing, and extends it to AI data access and usage with a lightweight connector swap. No new analytics. No new architecture. Just a missing layer finally put in place.

Bonfy’s new capability pairs with Bonfy’s MCP inspection server, announced earlier this year, to cover both data in use (AI reasoning loops) and data access (AI retrieval). Together, they form the first comprehensive data security model for modern AI workflows.Availability: Bonfy’s Contextual Data Enforcement is available today with support for Microsoft 365 and Google Workspace, supporting Anthropic Claude and Microsoft Copilot Studio, and OpenAI ChatGPT. Additional enterprise data sources will be added continuously.

Microsoft’s Legacy MSHTA Utility Tool Abused in Attacks, Exploited to Deliver Malware

Posted in Commentary with tags on May 19, 2026 by itnerd

Bitdefender has released new research documenting how attackers continue to abuse Microsoft’s legacy MSHTA utility to deliver malware through stealthy, multi-stage attack chains. The abuse of MSHTA affects both businesses and consumers who run Windows.

Despite Internet Explorer reaching end of support years ago, MSHTA remains enabled by default on Windows systems and continues to be heavily exploited by cybercriminals to execute malicious scripts, retrieve remote payloads, and evade detection using trusted Microsoft-signed processes.

Key findings include:

  • MSHTA used to silently deliver multiple malware families, including LummaStealer, Amatera, ClipBanker, PurpleFox, and CountLoader
  • Multi-stage, fileless attack chains using HTA scripts, PowerShell, and in-memory payloads to bypass traditional detection tools
  • Use of ClickFix-style lures and fake software downloads designed to trick users into manually launching malware infections

The research highlights how legacy Windows utilities continue to pose risks to general users and organizations by providing attackers with trusted tools that blend malicious activity into legitimate system behavior.

You can read the research here: https://www.bitdefender.com/en-us/blog/labs/microsofts-mshta-legacy-malware-windows

UPDATE: Adrian Culley, Senior Sales Engineer, SafeBreach has this comment:

Adrian has extensive global cyber investigations experience, including technical roles at SafeBreach, Trellix, Palo Alto Networks, Norse, and the London Metropolitan Police Service. 

“Reporting this week of a fresh surge in malware campaigns abusing mshta.exe should surprise nobody who has spent any time on the offensive side of the trade. The Windows utility has been shipping for 26 years, it is signed by Microsoft, it runs script in a trusted process context, and it is allow-listed by default in most enterprise estates. From APT28 to FIN7, from MuddyWater to whichever commodity loader is fashionable this month, attackers reach for it for the same reason burglars reach for unlocked doors.

There is no patch for this, because mshta is working as designed. What isn’t working is the quiet assumption — held in nearly every security organisation I walk into — that the AppLocker rule, the ASR policy, the EDR behavioural detection written eighteen months ago all still fire today. Estates drift. Exceptions accumulate. Rules quietly degrade. And almost no defender can prove, on demand, that they don’t.

The fix isn’t another product. It’s a discipline: safely run the attack on your own production estate, on a continuous schedule, and watch your stack respond. Replace “we believe we’re covered” with “we proved we are.”

Anything less is exposure management by hope.”

Digitate Recognized as Solutions Partner with Certified Software Designation from Microsoft

Posted in Commentary with tags on May 19, 2026 by itnerd

Digitate today announced it has received the Solutions Partner* with certified software designation** for Azure within the Microsoft AI Cloud Partner Program (MAICPP). This designation recognizes software that delivers proven value for enterprise customers, reinforcing Digitate’s ignio platform as a trusted platform for real-world outcomes on Azure and across the Microsoft Cloud ecosystem.

Digitate has earned four certified software designations for Azure: Technical – Retail AI, Manufacturing AI, Financial Service AI, and Technical – Azure. These designations underscore the ignio™ platform’s seamless integration with Microsoft Azure, while highlighting its quality, reliability, and proven value for enterprise clients. Notably, fewer than 0.1% of all Azure solutions in the Microsoft Marketplace – approximately 50 out of more than 41,000 – hold this designation.

Digitate’s agentic AI platform has delivered enterprise grade benefits to our customers across the spectrum of IT Operations, IT for business, cloud operations and business function SLAs. This designation validates our demonstrable track record of meeting the highest technical standards for ensuring tangible success across enterprise cloud customers.

To learn more about Digitate and its certified software designation, visit: www.digitate.com.

Black Kite Research Finds Just 58 CVEs Posed a Critical Supply Chain Threat – Out of More Than 48,000 Published

Posted in Commentary with tags on May 19, 2026 by itnerd

Black Kite today released its 2026 Supply Chain Vulnerability Report, revealing that of the 48,000+ CVEs published in 2025, only 58 represented a genuine, discoverable, and exploitable threat to enterprise supply chains.

This finding reinforces a critical shift in how organizations must approach cyber risk. The challenge is no longer just scale; it’s precision. Vulnerability volume continues to surge, driven by rapid AI adoption and advances in AI-powered vulnerability discovery. At the same time, exploit timelines are compressing, with attackers moving faster than ever, exploiting vulnerabilities an average of seven days before public disclosure, a window expected to shrink further as AI technologies accelerate scanning and exploitation capabilities.

Yet despite the surge in CVE volume, the number of vulnerabilities that pose meaningful risk remains remarkably small, making the ability to quickly identify and act on what truly matters more essential than ever to defending the supply chain.

AI Changed and Expanded the Attack Surface

AI adoption is reshaping the supply chain risk landscape, creating a widening gap between organizations with advanced security capabilities and those without.

Large enterprises that have adopted AI-powered vulnerability scanning have reduced detection timelines to an average of 14 days and remediation cycles to 21 days. In contrast, mid-market vendors, smaller software providers, and open-source maintainers that often lack these advanced defenses, still average 197 days for detection and down from 60 days for remediation.

As enterprise perimeters harden through AI-driven security, threat actors are increasingly shifting their focus to these “Tier 2” suppliers, driving risk to concentrate around the smaller vendors that enterprises depend on. For TPCRM programs, this means mid-market vendors now carry a significantly higher systemic threat profile.

Key findings from the report:

  • AI is driving vulnerability growth: 2,130 AI-related vulnerabilities were reported in 2026, a more than 200% increase since 2023.
  • Volume is rising, but risk remains concentrated: More than 48,000 CVEs were published in 2025 (an 18% increase year-over-year), yet just 58 posed a genuine supply chain threat.
  • Exploitation timelines are compressing: According to Mandiant, attackers exploited vulnerabilities an average of seven days before public disclosure in 2025, a window expected to shrink further as AI accelerates exploitation capabilities. Anthropic’s 2026 Project Glasswing demonstrated that AI models can autonomously identify zero-day flaws at scale. This means the volume and velocity of zero-day exploitation may accelerate far beyond what any reactive program can absorb.
  • AI is expanding the attack surface: AI coding assistants and agentic frameworks are emerging as actively targeted attack vectors, with high-severity CVEs on the rise. Prompt injection is also gaining recognition as a weaponizable vulnerability class, effectively acting as the “new RCE” (Remote Code Execution) for agentic systems.
  • Risk is shifting to less mature vendors: As larger enterprises improve average time to detection and response with AI, the share of exploited vulnerabilities targeting mid-market and smaller vendors are expected to rise significantly in the near future.
  • Proactive prioritization is critical: In modern TPCRM, time is the ultimate metric. Organizations relying solely on the CISA KEV catalog are reacting to threats that may already be actively exploited.

The report, based on analysis of more than 1,240 manually reviewed high-priority CVEs published in 2025, details a five-stage prioritization framework that filters raw vulnerability data through discoverability, exploitability, and vendor exposure to surface only the threats that demand immediate action. In 2025, that process produced 329 FocusTags® (asset-level threat signals that link a global vulnerability directly to a specific vendor’s confirmed exposure), and identified just 58 highest-priority designations representing the vulnerabilities most likely to impact supply chains.

Black Kite applied a FocusTag® for 95.2% of OSINT-discoverable vulnerabilities before they were added to the KEV or within 24 hours of their addition, enabling customers to take a proactive approach to supply chain risk and mitigate threats before vulnerabilities are widely exploited.

Designed for TPCRM leaders, CISOs, security operations teams, and vendor risk managers, Black Kite’s report provides the definitive data and methodology for organizations seeking to secure their extended vendor ecosystem and transition from reactive patching to proactive risk mitigation. To download the report, visit https://blackkite.com/reports/2026-supply-chain-vulnerability-report.

Methodology

The findings within the 2026 Supply Chain Vulnerability Report are founded on a rigorous manual analysis process conducted by the Black Kite Research Group. While automated scanners track the raw volume of disclosures, raw CVSS data alone is insufficient for effective TPCRM. To extract actionable intelligence, Black Kite researchers manually analyzed 1,240 high-priority CVEs published in 2025. The criteria for designating a vulnerability as “high-priority” requires the flaw to extend beyond theoretical severity. The Black Kite Research Group evaluates vulnerabilities based on real-world exploitability, the prevalence of the affected product within enterprise supply chains, and the active interest of threat actors. Vulnerabilities that are strictly internal, highly theoretical, or confined to obscure hardware are filtered out of this high-priority dataset.

CData Appoints Raviv Levi as Chief Product and Technology Officer & Expands Executive Team

Posted in Commentary with tags on May 19, 2026 by itnerd

CData Software today announced the appointment of Raviv Levi as Chief Product and Technology Officer (CPTO), along with the additions of Amit Naik as Vice President of AI Architecture and Craig Sanchez as Senior Vice President of Embedded Sales. The executive appointments support CData’s continued momentum as organizations rethink how enterprise data is accessed, governed, and acted on, whether by people working through conversational AI or by autonomous agents operating across enterprise systems.

Levi joins CData from Sift, where he served as Chief Product and Technology Officer, following senior leadership roles at Cisco, including Vice President of Security Strategy and Innovation for Cisco’s Security Business Group. He has led product, cloud security, and platform initiatives focused on enterprise-scale infrastructure and AI-driven technologies.

As Vice President of AI Architecture, Naik will lead the design and evolution of CData’s AI architecture, working across product and engineering to ensure the platform meets the technical demands of enterprise AI deployments. He joins CData from Calix and previously held senior leadership roles in AI/ML solutions and infrastructure at PayPal, Financial Engines and Oracle.

Sanchez will lead CData’s embedded sales organization, helping software vendors and platform providers integrate enterprise-grade connectivity and AI data access directly into their products. He joins CData from Vectara and previously held senior sales and business development leadership roles at Elastic and Cloudera.

The appointments reflect growing enterprise demand for AI systems, both conversational and autonomous, that can securely operate across fragmented data environments while maintaining governance, auditability, and real-time access. CData’s customers include global organizations such as Adobe, Office Depot, GSK, UiPath, and Palantir.

NordStellar debuts MCP to accelerate and streamline threat intelligence analysis

Posted in Commentary with tags on May 19, 2026 by itnerd

Efficient threat intelligence analysis is key in order to stop cyber threats before they escalate. NordStellar, a next-generation threat exposure management platform, has launched a model context protocol (MCP) that connects with AI tools to quickly analyze threat intelligence findings and generate reports, helping security teams to rapidly identify and prioritize high-risk issues.

NordStellar users will find the MCP in NordStellar’s help center. After downloading the file or setting it up manually, they will be able to connect it to popular AI tools.

By connecting the NordStellar MCP to their existing AI tools, security teams will gain significant advantages, enabling them to:

  • Receive quick custom reports. They will be able to generate executive and weekly summaries, threat exposure reports to share with stakeholders and other team members, as well as generate dated summaries of NordStellar findings and monitoring activity to support internal reviews, audits, and compliance processes.
  • Stay informed and updated on the latest findings. Security teams will be able to ask questions about specific findings and receive plain‑English explanations of events, vulnerabilities, or leaked data, request clear summaries of what is being said about their company on the dark web, and, where supported by their AI workflows, receive recurring summaries of new or high‑risk findings.
  • Identify and prioritize risks. Users will see which leaked credentials, malware logs, cookies, or instances of employee exposure may need attention first, enabling security teams to quickly identify which incidents are of highest priority.

The MCP is now available to all NordStellar users. For more information, book a personalized demonstration here.