Archive for May 28, 2026

EDAMAME isn’t a DevSecOps problem — it’s a compliance blind spot every enterprise is about to face

Posted in Commentary with tags on May 28, 2026 by itnerd

The launch of EDAMAME — a platform specifically designed to catch AI coding agents going off the rails — signals that the industry is starting to reckon with something important: autonomous AI agents in software development pipelines can take unintended actions, and existing security tooling wasn’t built to see it. But the conversation is almost entirely happening in AppSec and DevSecOps circles, and it’s missing the bigger structural problem underneath.

You can find out more here: https://www.securityweek.com/new-edamame-platform-aims-to-catch-ai-coding-agents-going-off-the-rails/

Justin Beals, CEO & Founder, Strike Graph, an AI-native GRC and compliance automation platform

“Building guardrails for AI coding agents is a meaningful step, and recognizing that autonomous code generation needs behavioral oversight is the right instinct. What’s incomplete is treating this as purely a developer tooling problem — the moment AI-generated code is deployed, it becomes a compliance and risk management challenge that most GRC teams have zero visibility into.

The real gap isn’t just catching an agent that misbehaves in real time. It’s that organizations have no systematic way to evidence that their AI-assisted development process meets the security requirements their certifications demand. Your SOC 2 or ISO 27001 was written assuming humans made the code decisions — it has nothing to say about what an autonomous agent pulled, modified, or deployed on your behalf.

As AI coding agents become standard in engineering orgs, compliance programs will need to evolve from auditing what humans built to auditing what AI built in humans’ names. The frameworks haven’t caught up yet, and the organizations waiting for them to before they act are building a gap that auditors — and attackers — will eventually find.”

Organizations need to ensure that the AI coding agents are as secure as the human agents they use. If they don’t, then it will end very badly for that organization indeed.

Microsoft criticizes public disclosure of unpatched zero-day vulnerabilities

Posted in Commentary with tags on May 28, 2026 by itnerd

In a statement published yesterday, Microsoft warned that recent public disclosures of unpatched zero-day vulnerabilities without prior coordination have placed customers at “unnecessary risk.”  The company said several researchers disclosed vulnerability details publicly before Microsoft had an opportunity to develop and distribute security fixes.

The company said coordinated vulnerability disclosure allows vendors time to investigate reports, prepare mitigations, and release patches before technical details become widely available to attackers. Microsoft argued that premature disclosure can increase the likelihood of exploitation against customers who have no available patch or remediation at the time information becomes public.

The warning comes as Microsoft continues addressing multiple recently disclosed vulnerabilities across Exchange Server, Defender, Azure, Windows networking components, and enterprise products during an unusually high-volume patching cycle. Microsoft released fixes for 138 CVEs during May Patch Tuesday alone, while additional vulnerabilities and mitigations were disclosed outside the regular patch release schedule.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “Coordinated disclosure is a shared obligation. Microsoft generates hundreds of billions in annual revenue. No researcher should be expected to subsidize product security for free. Six vulnerabilities across core Windows components including Defender and BitLocker that reached production represent a vendor engineering failure. These flaws should never have shipped. Vendors who ask for coordination must also invest in responsive triage and the development rigor that prevents this.

   “The traditional 90 day embargo was designed for a slower world. AI has compressed vulnerability discovery timelines so dramatically that ninety days is enough time for an entirely new frontier model to be deployed and pointed at the same codebase. Microsoft has patched over 500 CVEs in the first five months of 2026 alone. That volume is a signal that product security posture across the ecosystem is weaker than the market assumes. The Nightmare-Eclipse campaign has followed through on every public threat so far, and the warnings of further disclosures should be taken seriously.”

John Carberry, Solution Sleuth, Xcape, Inc.:

   “Microsoft’s sharp public rebuke against zero-day drops highlights an escalating war of attrition between independent researchers and enterprise vendors. While Microsoft argues that dropping vulnerabilities like RedSun, UnDefend, and BlueHammer puts the entire ecosystem at risk, this friction points to a deeper systemic breakdown. The security research community is clearly growing frustrated with vendor triage timelines, a bottleneck that has become critical given that Microsoft is already drowning in an engineering workload, evidenced by a massive 138-CVE patch cycle this month alone.

   “For enterprise risk leaders, this public spat is a dangerous distraction from the actual operational threat. The moment a researcher publishes full technical details or a working proof-of-concept for core Windows components like Defender, Azure, or Exchange Server, the time-to-exploit window for threat actors drops to zero.

   “Security executives cannot afford to wait around for vendor patches to slowly wind their way through QA and deployment pipelines. They must establish an aggressive, internal mitigation capability that treats uncoordinated disclosures as immediate, active incidents, forcing them to deploy temporary configuration workarounds and hyper-specific EDR detection rules the moment a flaw hits GitHub, long before the official automated fix arrives on a future Patch Tuesday.

   “Critical Takeaways

  •    “The zero-day names to watch: The uncoordinated drops specifically targeting core architecture(RedSun, UnDefend, BlueHammer, and the YellowKey BitLocker bypass) are not theoretical exercises. They represent immediate blueprints that threat actors are actively integrating into automated scanning tools.
  •    “Vendor triage under siege: Microsoft’s massive 138-CVE May release proves that vendor patch pipelines are stretched to their limits, systemically increasing the delay between a researcher’s initial private bug report and a public patch.
  •    “The mitigation engineering mandate: Relying entirely on automated patch management leaves an enterprise completely exposed during uncoordinated drops. Teams must be structurally capable of manually applying complex, out-of-band scripts and registry mitigations.

   “When researchers choose to drop working exploit code for core enterprise infrastructure directly to the public, they are giving the entire Internet an immediate, unauthenticated pass into your network before a lock has even been engineered.

   “The current standoff proves that the traditional model of coordinated vulnerability disclosure is buckling under its own weight, leaving enterprise security teams stuck in the crossfire between impatient researchers and overextended software vendors.”

Lydia Zhang, President & Co-Founder,Ridge Security Technology Inc.:

   “The number of CVEs patched by Microsoft on Patch Tuesday highlights the challenge facing security teams which is, what should I be prioritizing?   Security tools that just identify vulnerabilities are insufficient.   In fact, even knowing that a vulnerability is exploitable is insufficient.  Knowing the kill-chain is insufficient.  The missing piece of the puzzle is combining that exploitability and kill-chain knowledge with business context such as what assets can be reached thru these exposures and how valuable are those assets?”

My only advice is to hold companies like Microsoft accountable. Otherwise we will have vendors deciding what is and isn’t public domain. Which is of course dangerous.

Local volunteers create a friendlier future for 500 youth across London

Posted in Commentary with tags on May 28, 2026 by itnerd

Here’s some photos from yesterday’s volunteer event in London, where TELUS team members and community volunteers came together to create a friendlier future for 500 youth across London by packing 300 Kits for Kids, backpacks filled with essential school supplies and assembling 200 Kindnessgrams, sweet treats with handwritten notes of hope, as part of the 21st annual TELUS Days of Giving

Kits for Kids

For many families, rising costs are putting essential school supplies out of reach. Through TELUS’ Kits for Kids program, backpacks filled with school essentials including notebooks, pencils, pens, colouring supplies and loose-leaf paper are distributed to students facing financial barriers. To date, TELUS has distributed more than 250,000 Kits for Kids across Canada, including 10,000 this year alone.

Kindnessgrams

Sometimes, a simple gesture is all it takes to remind someone they aren’t alone. Each Kindnessgram package pairs a bag of sweet treats with a handwritten note of inspiration, designed to let our community’s most vulnerable youth know that their neighbors are rooting for their success. These small tokens serve as a powerful reminder that they are seen, supported, and valued.

Camp Mail

Attendees created camp mail kits to ensure youth who are attending camp are not left out while other campers are receiving camp mail from home. These kits include fun activities and hand written youth friendly jokes. 

The items from the London event will support five local charity partners: Big Brothers Big Sisters of London and AreaLondon Food BankLondon and Middlesex Community HousingYMCA of Southwestern Ontario and Youth Opportunities Unlimited (YOU). Together, these organizations provide critical support to vulnerable families, children and youth across London through social housing, food insecurity, health and fitness programming, camps, child care, specialized newcomer services, mental health and career support programs.

Check Point Software Launches Agentic Exposure Validation to Counter Frontier AI Models Now Capable of Autonomous Exploitation

Posted in Commentary with tags on May 28, 2026 by itnerd

Check Point today launched Agentic Exposure Validation (AEV) for Exposure Management, to put defenders on equal footing with AI-driven attackers. As frontier AI models like Anthropic’s Mythos and OpenAI’s GPT-5.5 gain the ability to autonomously find thousands of exploitable vulnerabilities at scale, the question for boards and CISOs is no longer “are we patched?” but “what can attackers actually exploit right now? and how do we find it before they do?” AEV is the answer.

Agentic Exposure Validation (AEV) uses AI agents that reason like attackers across the organization’s specific environment, correlating exposure data, asset context, live exploit research, threat intelligence, and protection coverage to determine whether an exposure is truly exploitable. Rather than relying on static severity scores, AEV follows a safe proving loop: it analyzes the relevant asset or CVE, enriches findings with live Check Point threat intelligence, checks whether existing controls already block the path, and builds a targeted validation that mirrors attacker reasoning without disruptive techniques. It then either proves the exposure with direct evidence, pivots to a new attack path when blocked, or discards the threat altogether.

AEV is a critical validation capability within Continuous Threat Exposure Management (CTEM) programs, helping organizations move from discovery and prioritization into confident, evidence-based exposure reduction at AI scale.
Early customer engagements have already demonstrated this pattern, and AEV was able to create novel exploit for dozens of vulnerabilities that had no known exploit.

Agentic Exposure Validation is available now as part of Check Point Exposure Management. To learn more or to request a complimentary AEV scan, organizations can complete the demo request form here to see what an agentic attacker would uncover on their external attack surface

TERAGO and Ericsson Launch Enterprise Private 5G Network at McMaster Manufacturing Research Institute

Posted in Commentary with tags , on May 28, 2026 by itnerd

TERAGO today announced the successful deployment of an Ericsson Private 5G network in collaboration with Ericsson Enterprise Wireless Solutions at the McMaster Manufacturing Research Institute (MMRI).

Building on its strategic partnership with Ericsson Enterprise Wireless Solutions, TERAGO continues to accelerate the adoption of enterprise-grade 5G infrastructure across Canada. This latest deployment represents a significant milestone bringing Private 5G into a live manufacturing and research environment where organizations can explore, validate, and scale next-generation applications.

The private 5G network at MMRI, utilizing the recently released Canadian industry spectrum, delivers secure, high-performance, low-latency connectivity across the facility, enabling advanced use cases such as AI-driven automation, robotics, real-time data processing, and smart manufacturing. Designed as a fully managed, dedicated network, it provides the reliability and control required for mission-critical industrial operations.

Ericsson’s Enterprise 5G solutions provide the mobility, performance, and flexibility required for complex industrial environments. Combined with TERAGO’s expertise in managed connectivity and licensed spectrum, the solution delivers a robust, enterprise-ready platform tailored to the evolving needs of modern industry.

Exclusive Ericsson Private 5G Launch Event – June 2, 2026

To mark the deployment, TERAGO and Ericsson will host an exclusive Ericsson Private 5G Launch Event at MMRI on June 2, 2026, bringing together industry leaders, customers, and partners for an immersive, hands-on experience showcasing Private 5G technology as well as applications.

This event will provide attendees with a unique opportunity to experience how Ericsson Private 5G enables integrated intelligence across modern industrial operations, bridging connectivity, automation, and real-time decision-making.

TELUS Rewards earns global loyalty award recognition and unveils massive program enhancements

Posted in Commentary with tags on May 28, 2026 by itnerd

TELUS Rewards is setting a new standard for customer loyalty with major new enhancements that give Canadians more benefits, more savings, and more everyday value. Starting today, every TELUS Rewards member gains access to an expanded suite of health, travel, entertainment and lifestyle perks worth more than $400 in annual value — simply for being a TELUS customer. This commitment to member value has earned TELUS Rewards global recognition, with three first-place honours at the 

2026 Loyalty360 Awards, including the 360-Degree Brand Award. The expanded lineup of exclusive benefits now available to all members include:

  • New TELUS Perks: Complimentary access to a virtual counselling session through TELUS Health MyCare (valued at up to $120), plus a complimentary veterinary consultation through TELUS Health MyPet (a $40 annual value) — making it easier for members to access trusted support and care for themselves and their pets.
  • New Partner Perks: Everyday savings through new partnerships with Skip and Turo. Perks include a complimentary one-year Skip+ membership, unlocking $0 delivery fees on eligible orders, member-exclusive offers, and hundreds in potential annual savings from Canada’s homegrown delivery network. And hit the road this summer with a one-time $50 Turo car rental credit.

TELUS Rewards is Canada’s award-winning loyalty program, featuring a tiered experience that rewards customers for their loyalty. As members progress through Purple, Gold, Platinum and Diamond tiers, they unlock increasingly exclusive perks, enhanced benefits and greater everyday value. Customers who sign up for TELUS Rewards with one eligible TELUS service join the Purple tier and gain access to a growing collection of benefits, savings and experiences from day one. Members can unlock Gold, Platinum and Diamond tiers by adding additional qualifying TELUS services, including Mobility, Internet, Optik TV and SmartHome Security.

For more information about TELUS Rewards, visit https://www.telus.com/my-rewards.

CrowdStrike Details Takedown of Glassworm

Posted in Commentary with tags , , on May 28, 2026 by itnerd

CrowdStrike, Google, and the Shadowserver Foundation said they disrupted the Glassworm botnet, a global threat targeting developers and open-source software ecosystems through supply chain attacks. CrowdStrike said the coordinated takedown simultaneously disabled all four of the botnet’s C2 channels, preventing communications with infected systems and delivery of additional malware payloads.

You can find out more by reading CrowdStrike’s writeup here: https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/

Liquibase VP Ryan McCurdy offers perspective:

   “Glassworm is a reminder that ungoverned automation can quickly become a privileged attack path. Once attackers compromise developer tooling, poison repositories, or steal CI/CD credentials, the pipeline stops being background infrastructure and starts acting like a privileged identity. That is what makes these attacks so dangerous. The answer is not less automation. It is more standardized, governed automation, so the workflows developers and pipelines already rely on are consistent, controlled, and harder to abuse.”

Honestly, while this is to be celebrated, it’s also time for organizations to look at themselves and retool themselves so that automation is not an attack path. Otherwise bad things will happen.

UPDATE: There’s additional commentary starting with Ryan McCurdy, VP of Marketing, Liquibase:

   “Glassworm is a reminder that ungoverned automation can quickly become a privileged attack path. Once attackers compromise developer tooling, poison repositories, or steal CI/CD credentials, the pipeline stops being background infrastructure and starts acting like a privileged identity. That is what makes these attacks so dangerous. The answer is not less automation. It is more standardized, governed automation, so the workflows developers and pipelines already rely on are consistent, controlled, and harder to abuse.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “When dismantling a single developer targeting botnet requires three organizations to simultaneously strike four independent command and control channels, that is a measure of how seriously adversaries have invested in compromising the people who build software. Glassworm’s operators layered Solana blockchain dead drops and BitTorrent alongside legitimate services like Google Calendar, building infrastructure designed to survive exactly this kind of operation. This coordination sets a model for how the security community should respond to entrenched supply chain threats. Precision and partnership delivered operational results without years of judicial process.

   “Disruption buys defenders a window. It does not reverse more than a year of credential theft. Glassworm used credentials stolen in earlier infections to poison over 300 GitHub repositories, the same cascading pattern the industry has tracked across multiple supply chain campaigns this year. Any organization consuming open source software should be checking telemetry against the published indicators now, not waiting for a downstream compromise to surface the exposure.

   “Glassworm did not operate in isolation. It ran alongside multiple supply chain campaigns targeting the same developer ecosystems over the same timeframe, including the Shai-Hulud worm and the Megalodon GitHub poisoning disclosed days ago. The volume and persistence of these operations make the case that developer environments and build pipelines require the same zero trust posture organizations have spent a decade applying to users and networks. Any organization that treats its build infrastructure as implicitly trusted is operating on assumptions that adversaries have already invalidated.”

Noelle Murata, Chief Operating Officer at Xcape, Inc.

   “The coordinated takedown of the Glassworm botnet by CrowdStrike, Google, and Shadowserver highlights a massive paradigm shift: threat actors are aggressively targeting the software developer’s workstation as the ultimate enterprise entry point. By targeting IDE marketplaces, package registries, and GitHub repositories rather than traditional corporate networks, the operators behind Glassworm turned infected developer environments into automated launchpads for broader downstream supply chain contamination.

   “What makes this campaign uniquely menacing is the extreme, multi-layered resilience of its command-and-control (C2) architecture. By hiding C2 infrastructure across the Solana blockchain, the BitTorrent peer-to-peer network, and public Google Calendar entries, the attackers built a decentralized dead-drop engine that could not be dismantled by traditional domain sinkholing or legal hosting takedowns. The fact that defenders had to execute a flawless, simultaneous strike across all four independent technical vectors proves that legacy, siloed perimeter defense is structurally obsolete when fighting a decentralized adversary.

   “For enterprise risk leaders, the Glassworm disruption is a severe warning that developer environments must be treated as highly privileged, zero-trust zones. To defend against this evolving threat landscape, security executives must immediately enforce strict application control policies on developer IDE extensions, audit code pipelines for unauthorized package installs executing via post-install hooks, and continuously monitor for suspicious, outbound programmatic access to public infrastructure.

   “Critical Takeaways

  •    “Targeting the pipeline creators: Adversaries are bypassing heavily defended enterprise production environments to compromise developers directly, leveraging their local code-signing access and platform credentials to seamlessly poison entire downstream software lifecycles.
  •    “The resilience of decentralized C2: Utilizing immutable blockchain ledger memo fields and decentralized peer-to-peer hash tables means attackers can permanently maintain connectivity to infected assets without relying on central, tear-down-vulnerable web domains.
  •    “Takedowns are a temporary shield: While disabling the current infrastructure disrupts immediate payload delivery, it does not erase the thousands of malicious, typosquatted npm/PyPI packages and poisoned source files that remain dormant across the broader public code ecosystem.

   “When a botnet embeds its command architecture into public blockchains and peer-to-peer networks, traditional security boundaries cease to exist. You aren’t just fighting a group of hackers anymore; you are fighting a permanent, decentralized exploit of the internet’s own infrastructure.”

Sage Intacct expands trusted automation across core finance workflows

Posted in Commentary with tags on May 28, 2026 by itnerd

Sage today announced new and enhanced capabilities in Sage Intacct designed to help finance teams accelerate operations, strengthen control and extend AI capabilities across finance operations.

The latest updates expand automation across receivables, accounts payable, purchasing and SaaS analytics, while introducing new ways for customers and partners to extend AI capabilities through Sage Intacct AI Gateway. Together, the updates help finance teams reduce manual work, improve visibility and move faster with greater confidence by embedding trusted AI and automation directly into day-to-day finance workflows with the transparency, control and accountability finance teams require.

As finance teams face growing pressure to improve cash flow, accelerate decision-making and operate with greater agility, many still rely on disconnected systems and manual processes that slow execution and limit visibility. Gartner research found that 88% of CFOs rank finance staff productivity among their top priorities in 2026, reflecting growing pressure to automate workflows, shorten cycles and control costs. Sage Intacct’s latest updates are designed to support this shift by embedding trusted automation across receivables, payables, purchasing and finance analytics workflows.

Advancing high-performance finance through automation, control and AI extensibility
The latest update expands customizable workflow automation across receivables and purchasing, with AI-powered enhancements in accounts payables and SaaS analytics, helping finance teams reduce manual effort and improve visibility across day-to-day operations.

The release also introduces new ways for customers and partners to extend the value of Sage Intacct by using the Model Context Protocol (MCP), an open standard for bridging AI solutions with business systems, to securely connect financial data to AI tools. This helps organizations adapt workflows more easily while maintaining defined permissions, approvals and operational controls.

What’s new in Sage Intacct May 2026:

Cash Intelligence: Payment Reminders
Helping accounts receivable and finance teams manage customer follow-ups, Payments Reminders proactively surfaces customers with open or overdue invoices in a single view. Teams can send one-click or bulk payment reminder emails using a default template, helping create more consistent outreach and reduce manual follow-up.

Available through an Early Adopter program globally.

AP Automation: 3-Way Matching
Reducing manual reconciliation and helping preserve oversight and control, 3-Way Matching uses AI-driven automation to link invoices, purchase orders and receipts, compare prices, quantities and totals, and flag line-level discrepancies for review before payment.

Generally available globally. 

Custom Approvals in Purchasing
Helping organizations manage purchasing approvals more flexibly, Custom Approvals in Purchasing enables teams to define multi-condition approval rules using transaction fields such as vendor, amount, department, location and category. This helps route transactions to the right approver and align controls with operational workflows.

Available through an Early Adopter program globally.

Sage Intacct AI Gateway
Helping customers and partners extend trusted AI across finance workflows, Sage Intacct AI Gateway enables tailored AI solutions to connect directly with Sage Intacct using REST APIs and using the Model Context Protocol (MCP) standard. This allows Sage Intacct data to be combined with external applications and AI services while operating within defined roles, permissions and workflow controls.

Generally available in the US, UK, Canada, Australia and South Africa.

SaaS Intelligence 2.0
Helping SaaS finance leaders gain deeper visibility into revenue performance, SaaS Intelligence 2.0 delivers enhanced AI-powered insights across forecasting, cohort analysis, customer segmentation and Annual Recurring Revenue and Monthly Recurring Revenue tracking. Interactive dashboards help organizations identify churn, retention and expansion trends more easily.

Available through an Early Adopter program in the US, UK, Canada, Australia and South Africa.

ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea

Posted in Commentary with tags on May 28, 2026 by itnerd

ESET Research has released its latest APT Activity Report, which highlights activities of select APT groups that were documented by ESET researchers from October 2025 through March 2026. During the monitored time frame, China-aligned threat actors remained highly active worldwide, conducting espionage campaigns shaped in part by geopolitical developments affecting Beijing’s economic and security interests. Following the US military operation in Venezuela and amid continuing instability in the Gulf region, ESET spotted signs that China-aligned groups were being mobilized to improve Beijing’s visibility into maritime, energy, and political developments abroad. North Korea-aligned Andariel attacked a company that appears to be involved in the nuclear power industry.

China-aligned FamousSparrow targeted a Venezuelan governmental entity connected to maritime affairs, likely to monitor the resilience of oil shipments after the US intervention. There, ESET also noticed SteppeDriver, another China-aligned APT group targeting a Syrian governmental network, activity that may reflect both Chinese commercial interest in Syria’s reconstruction projects and security concerns surrounding Uyghur fighters present in that country. China-aligned UNC5221’s SPAWN malware family targeted governmental entities in Cambodia and Panama, as well as an AI and robotics company in South Korea. The latter targeting South Korea aligns with Beijing’s enduring interest in strategic technologies prioritized under the Made in China 2025 industrial development policy.

The war in Iran that began in late February 2026 was the defining event for Iran-aligned activity during this period. Paradoxically, the conflict coincided with a decline in activity from established Iran-aligned APT groups in ESET telemetry, most likely because internet restrictions imposed by the Iranian regime hindered their ability to operate effectively. At the same time, this environment appears to have favored the mobilization of proxy and hacktivist actors targeting Israel, the United States, and other states seen as hostile to Tehran. ESET Research also documented an unusual spike in activity against Israeli targets that it could not confidently link to previously known groups. Two unattributed activity clusters, Rusty Boots and MoKhargosh, demonstrated both espionage capabilities and destructive potential against Israel – including deployment of a bootkit-style wiper while retaining destructive tooling for later use.

ESET Research also found a defense company in the United Arab Emirates being compromised, and Arabic-speaking users being targeted with Android spyware. It was possibly aimed at journalists or open-source intelligence practitioners since the name of attacker’s Telegram channel was likely inspired by Live Universal Awareness Map (Liveuamap), a legitimate, well-known OSINT platform dedicated to mapping military incidents worldwide.

North Korea-aligned threat actors remained active on several fronts. Multiple groups continued targeting developers and the cryptocurrency ecosystem with social engineering schemes that can yield both direct financial gain and opportunities for software supply-chain compromise. ESET also uncovered the reemergence of the Andariel group in attacks against South Korea, where the group deployed TigerRAT and attempted to spread Rook ransomware within an engineering company that appears to manufacture equipment relevant to liquid hydrogen handling and the nuclear power industry – technologies that are obviously of interest to Pyongyang’s ballistic and nuclear ambitions.

Russia-aligned threat actors continued to focus overwhelmingly on Ukraine and entities connected to that country’s defense efforts. Sednit deployed its Covenant and BeardShell implants against Ukrainian military personnel, drone manufacturers, and organizations involved in drone research and development, while also targeting logistics and transportation companies outside Ukraine. Sandworm intensified destructive activity over the winter, deploying several new wipers in Ukraine against governmental and private sector targets. Particularly notable was a December 2025 data destruction incident affecting a Polish energy company, which ESET attributed to Sandworm with medium confidence.

ESET products protect our customers’ systems from the malicious activities described in this released report. Intelligence shared here is based mostly on proprietary ESET telemetry data and has been verified by ESET researchers, who prepare in-depth technical reports and frequent activity updates detailing activities of specific APT groups. These threat intelligence analyses, known as ESET APT Reports, assist organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from criminal and nation-state-directed cyberattacks.

More information about ESET APT Reports, which deliver high-quality, strategic, actionable, and tactical cybersecurity threat intelligence, is available on the ESET Threat Intelligence page.

For more details about the mentioned and other APT groups’ activities, read the full APT Activity Report, “Conflict-informed espionage: Monitoring oil shipments, targeting drone makers,” on WeLiveSecurity.com

New data from 800k U.S. job postings challenges developer assumptions about what employers actually hire for

Posted in Commentary with tags on May 28, 2026 by itnerd

As layoffs reshape tech and AI dominates the conversation, new research from Oxylabs reveals that what developers think employers want doesn’t match what job postings actually show.

Oxylabs analyzed more than 800,000 U.S. job postings (January 2025–March 2026) requiring at least one programming language. Unlike survey-based rankings, this reflects real hiring behavior at scale. 

Key findings:

  • SQL is nearly as in-demand as Python (45% vs. 46% of postings), despite developers routinely dismissing it as “not a real language”. SQL beats Python as the No. 1 requirement in 38 states, Python leads in just 12.
  • The Python and SQL duo is the most requested skill, appearing in 1 in 5 tech job postings, far ahead of any other pairing.
  • Apple is hiring while others cut. Its Q1 2026 job postings jumped 9 times the 2025 quarterly average, with software engineering and AI/ML roles having the biggest spikes.
  • Foundational skills still dominate. Despite the AI-driven shift, the top most-requested languages are established tools (Python, SQL, Java, JavaScript).

The full report breaks down demand by role (backend vs. frontend vs. DevOps vs. data science), industry, and U.S. state – useful context for developers assessing their career options in an uncertain market.

Please read the full report here