Archive for June 3, 2026

Governor Abbott Appoints Five To Quantum Initiative Advisory Committee

Posted in Commentary with tags on June 3, 2026 by itnerd

Governor Greg Abbott appointed Victor Fishman, Ph.D. and Lin Zhou, Ph.D. to the Quantum Initiative Advisory Committee for terms set to expire on January 31, 2027. Governor Abbott also appointed Richard “Ross” Coffman for a term set to expire on January 31, 2029, and appointed John Josephakis and Jeff Prevost, Ph.D. for terms set to expire on January 31, 2031. The Initiative will develop a strategic plan for the promotion of the quantum economy in this state.

Victor Fishman, Ph.D. of Allen is the executive director of the Texas Research Alliance. He is a board member on the Dallas Innovation Alliance and the North Texas Innovation Alliance and a member of the National Defense Industrial Association. He is a veteran of the Vietnam war, having served in the U.S. Army Ordnance Corps. Fishman received a Bachelor of Science in Chemistry from the University of Miami, a Master of Science in Chemistry from Clemson University, and a Doctor of Philosophy in Chemistry from The University of Texas (UT) at Austin.

Lin Zhou, Ph.D. of Lubbock is the vice president, chief information officer, and executive director for AI and Quantum Computing at Texas Tech University. He is a founding member of the Texas Quantum Summit and serves on the board of directors for the Lonestar Education and Research Network. Additionally, he is a certified Project Management Professional (PMP) by the Project Management Institute and served on the Texas Department of Information Resources State Strategic Plan Advisory Committee. Zhou received a Bachelor of Science in Physics from Nanjing University and a Doctor of Philosophy in Physics from the University of Glasgow.

Richard “Ross” Coffman of Austin is the president of Forward Edge AI. He received an Honorable Discharge from the United States Army. Coffman received a Bachelor of Arts in Economics and Government from Centre College, a Master of Business Administration from Embry-Riddle Aeronautical University, and he completed a National Security Fellowship at the Harvard Kennedy School.

John Josephakis of Dallas is a global vice president at NVIDIA. Josephakis received a Bachelor of Arts in Economics from UT Austin with a minor in Mechanical Engineering and a Master of Business Administration in Finance from St. Edwards University.

Jeff Prevost, Ph.D. of San Antonio is an associate professor at UT San Antonio where he currently serves as a vice president for the Cyber Manufacturing Innovation Institute as well as the executive director for the Open Cloud Institute. He is a founding member of the Texas Quantum Summit and represents UT San Antonio on the UT System Quantum Planning Committee. He is a senior member of the Institute of Electrical and Electronics Engineers. Prevost received a Bachelor of Science in Economics from Texas A&M University and a Doctor of Philosophy in Electrical Engineering from UT San Antonio.

Free SOCRadar ‘Hacker Score’ Helps MSSPs and MSPs Support Prospects With Automated Threat Assessments to Build Trust and Generate Leads on Day One

Posted in Commentary with tags on June 3, 2026 by itnerd

SOCRadar today launched Hacker Score, a new tool designed to help Managed Security Service Providers (MSSPs) and Managed Service Providers (MSPs) garner immediate trust with prospects by showing them where they are vulnerable using automated external exposure checks in order to generate leads. Available free of charge for a limited time, Hacker Score delivers an instant score of a prospect’s digital footprint, identifying vulnerabilities, leaked credentials, and surface/dark web exposures without a complex set up.

MSSPs and MSPs continue to struggle with the manual, time-consuming process of conducting initial security assessments for prospects. Standard “scans” often lack the depth of Extended Threat Intelligence (XTI), making it difficult for them to differentiate their services from their competitors and prove the necessity of their security stack in a crowded market.

Hacker Score helps organizations see themselves through the eyes of an attacker. By continuously monitoring more than 150 indicators and attack vectors that hackers typically evaluate before launching an attack, Hacker Score reveals what adversaries already know about an organization. Combining attack surface intelligence with SOCRadar’s deep and dark web datasets, including stealer logs, compromised credentials, ransomware intelligence, and phishing infrastructure, Hacker Score delivers a real-world assessment of organizational exposure and highlights the weaknesses most likely to be targeted.

Hacker Score’s features include:

  • External Attack Surface Mapping: Provides visibility into all internet-facing assets.
  • Credential Leak Detection: Identifies employee data exposed in recent breaches or stealer logs.
  • Vulnerability Assessment: Instantly identifies critical, exploitable vulnerabilities across a prospect’s infrastructure.
  • Supply Chain Risk: Evaluates the risk levels of a prospect’s third-party ecosystem.

Astrolight Wins Startup World Cup Regional, Heading to Silicon Valley to Compete for $1M Investment

Posted in Commentary with tags on June 3, 2026 by itnerd

Astrolight has won the Lithuanian regional competition of the Startup World Cup, the world’s leading startup pitch contest. The company will head to the Startup World Cup Grand Finale in San Francisco on November 6, 2026, and compete with finalists from around the world for the title of global champion and a US$1 million investment prize.

Earlier, Astrolight secured contracts and partnerships with the European Space Agency (ESA), industry primes, and leading satellite manufacturers. The company has launched three of its ATLAS-1 laser terminals into orbit for testing, joined a Kepler Communications-led team developing ESA’s HydRON optical multi-orbit transport network, and is working with ESA to build the first Arctic optical ground station in Greenland.

Novaspace, the leading space market research firm, projects global revenues for space laser communication terminals will reach $12.9 billion through 2035, driven by the industry’s structural shift away from radio-frequency (RF) communications as operators face mounting RF spectrum constraints: regulatory scrutiny, licensing delays, and interference bottlenecks.

Similar pressure is now reaching AI infrastructure. As land-based datacenters run into limits around space, power, and cooling, industry leaders are starting to look at putting datacenters and compute systems in orbit, with high-speed laser communications as a core infrastructure layer.

Unlike radio-frequency communication, laser links use narrow and focused beams of infrared light, which can transmit data at up to 100 times faster rates than RF and are extremely resilient to electronic interference, jamming, and interception.

Incidents of electronic warfare in space and on land are growing. Russian GPS spoofing from Kaliningrad can now reach 450 km into Europe, GPS/AIS interference has surged in the Middle East Gulf, and Russia has been accused of intercepting European satellite communications and regularly jamming UK military satellites.

Startup World Cup is a global startup competition and conference organized by Pegasus Tech Ventures, a Silicon Valley-based multinational venture capital firm. The competition includes more than 100 regional events across North America, South America, Europe, Africa, Asia, and Australia, followed by the Grand Finale in Silicon Valley.

DeepTempo Launches Intelligent Defense Platform to Defeat AI-Powered Cyberattacks

Posted in Commentary with tags on June 3, 2026 by itnerd

DeepTempo today announced its Intelligent Defense Platform, the first comprehensive cyber defense system built to deliver machine speed intelligence to enterprises, MSSPs, service providers, and critical infrastructure providers. With this move, DeepTempo has expanded from a LogLM foundation model provider to embrace a system-level approach that both provides visibility into detection quality across an enterprise’s corpus of security telemetry and includes optional integrations with Vigil, the leading OpenSource AI SOC, which DeepTempo launched in April of 2026. 

DeepTempo anticipated today’s reality – the emerging use of AI by attackers is overwhelming human speed cyber security systems. While much has been made of the efficacy of Mythos and similar models in finding vulnerabilities, substantial evidence suggests that attackers are also using AI to orchestrate and execute campaigns that traditional systems struggle to identify and isolate.  

The DeepTempo Intelligent Detection Platform extends existing cybersecurity investments by adding an intelligence layer across threat intelligence, detection, threat hunting, response, and related workflows, making every SIEM, SOAR, and AI SOC more focused and effective, reducing MTTD and MTTR while controlling spending on both human and AI intelligence.  

Use cases in cyber traditionally have been fragmented across countless point products.  Investments in telemetry platforms such as Cribl and data lakes such as Snowflake have made the Intelligent Defense Platform possible. Running in customer environments, DeepTempo’s IDL delivers insights and, optionally, takes actions without the cost, delays, and risk of siloed products that backhaul telemetry into their SaaS solutions for analytics.

DeepTempo’s Intelligent Defense Platform unifies, evaluates, and continuously improves detection across telemetry classes, embracing and supporting existing investments rather than replacing them. Additionally, this learning loop can extend to the use of Vigil and other AI SOCs for common workflows.  By closing this loop with visibility into performance, efficacy, and both historical and projected costs, the Intelligent Defense Layer helps operators transition to the safe and cost-effective use of machine-speed intelligence.  

DeepTempo’s approach provides an AI-native detection and operations foundation to thwart AI-enabled attackers. Recent research shows that 67.2% of exploited CVEs in 2026 have been zero-days, while 82% of detections in 2025 were malware-free. The window between vulnerability and exploitation has narrowed in the era of AI. DeepTempo’s Intelligent Defense Platform builds upon the LogLM, which was pretrained on billions of logs and performs approximately 279 billion calculations per sequence. The LogLM uncovers complex, compound behavioral patterns that no human-authored rule can anticipate while eliminating the costly and error-prone retraining that undermines traditional anomaly detection.

The Intelligent Defense Platform’s key features include:

  • Pluggable Architecture Extends Capabilities while Reducing Lock-in: DeepTempo has partnered with Cribl, Snowflake, and others at the data layer, and works well with Splunk and other SIEMs, as well as agentic solutions within the SOC.  Agentic intelligence is pluggable through skills and similar patterns, whether Vigil is used or not, allowing users to leverage their own AI solutions, such as enterprise licenses for OpenAI, Gemini, and Claude, as well as on-premises reasoning models.
  • End-to-End Validation and Monitoring: Continuously evaluates the efficacy of existing rule-based and ML-based detections alongside LogLM-generated detections and can also be used to measure the efficacy and projected costs of many workflows.  
  • Broader Telemetry used by the LogLM: DeepTempo’s LogLM has broadened its capabilities and can now ingest network flow, firewall, DNS, WAF, cloud performance, commonOT, and agentic AI logs. In some recent deployments, the LogLM has achieved <1% false positives and <1% false negatives without any adaptation required, far better protecting defenders while saving time and money by being pinpoint focused on malicious behavior.
  • Edge-Appropriate Deployment: DeepTempo has simplified the deployment and management of LogLM and related software at the edge.  Distilled versions of the LogLM run on small systems, for example, adding the state-of-the-art ability to see novel and rapidly evolving attacks to systems running in critical infrastructure, including on fly-away kits. 

This announcement follows DeepTempo’s recent launch of Vigil, the first open-source AI SOC built on an LLM-native architecture, underscoring the company’s commitment to providing security teams with a more transparent, extensible foundation for modern security operations. To learn how DeepTempo is advancing AI-native detection and response through both Vigil and its Intelligent Defense Platform, visit www.deeptempo.ai. Free assessments, or threat hunts, are available for a limited time.  

Black Kite’s 2026 State of Financial Services Report Reveals Ransomware Surge and Vulnerability Deluge Driving Two-Front Cyber Threat

Posted in Commentary with tags on June 3, 2026 by itnerd

Black Kite today released its newest report, 2026 State of Financial Services: The Dual Storm of Ransomware and Vendor Ecosystem Risk, which explores how direct attacks and supply chain risk are now rising together. The report found that direct ransomware attacks are escalating again and occurring concurrently with a massive surge in vendor vulnerabilities, shifting the industry from a single-direction tactical problem to a two-front structural crisis.

The financial sector’s 2024 relief, which was largely fueled by law enforcement disruptions of major ransomware groups like LockBit and Clop, was short-lived. In 2025, direct attacks rebounded as operators restructured under new banners. This fracturing ecosystem saw the number of distinct threat groups targeting finance climb from 37 in 2023, to 45 in 2024, and to 48 in 2025, led by threat actors Qilin, Akira, and Kill Security.

Ransomware targeting within finance has shifted significantly since 2023. In 2023, banks were the primary ransomware target with 71 disclosures compared to 44 disclosures reported by investment firms. By 2025, those positions reversed, banking incidents fell to 36 disclosures, and investment firm disclosures nearly doubled, as they became the most-targeted segment with 84 disclosures (41.6% of all incidents). This investment-sector surge was driven by a September 2025 campaign against South Korean asset managers, which accounted for 32 disclosures (38.1% of the subindustry’s total).

The CVE Volume Problem Is Accelerating, and the Gap is Widening

Over 48,000 CVEs were published globally in 2025 alone, an 18% year-on-year increase. Growing AI adoption is expected to further increase that volume through both AI-assisted vulnerability discovery and the widespread use of AI systems as new attack surfaces. In the 2026 Supply Chain Vulnerability Report, Black Kite Research Group identified 1,240 CVEs as high-priority for third-party risk in 2025, a 59% increase since 2024. 

Across all financial services vendors, 50.2% carry high-severity CVEs. As CVE volume increases and exploitation timelines compress globally, the operational impact on financial institutions is becoming increasingly direct. According to Verizon’s latest Data Breach Investigations Report (DBIR), vulnerability exploitation overtook phishing as the leading initial access vector for breaches for the first time in the report’s history. In this environment, visibility into the supply chain vulnerabilities that can introduce the greatest operational risk is essential.

Key findings from the report:

  • Ransomware returns to finance: Direct ransomware attacks on financial institutions resumed their upward trajectory in 2025 after a brief decline the year before. Reported incidents increased by 30% from 2024 to 2025, while early 2026 data indicates the trend is accelerating further, with Q1 incidents rising 76% year-over-year.
  • Vendor risk is a sector-wide threat: In September 2025, Qilin’s compromise of a single South Korean MSP cascaded into 32 financial institutions and over 2 terabytes of stolen data, making South Korea the second-most-targeted country for finance ransomware that year.
  • A reorganized threat ecosystem: The number of distinct threat groups targeting finance climbed to 48 in 2025, led by emerging threat actors Qilin, Akira, and Kill Security. The dismantlement of major ransomware groups did not reduce the threat; it rerouted it. Operators from disrupted groups have rebuilt under new banners. Emerging actors have rapidly filled the vacuum, with Qilin alone responsible for 59 finance-sector incidents in the past year.
  • Vendor vulnerabilities multiply: From 2024 to 2025, the number of critical vulnerabilities carried across vendors serving the financial sector increased 387%. Among the 140 vendors whose client base is meaningfully concentrated in finance, critical vulnerabilities increased 181%.
  • Active exploitation at scale: 54% of the 140 vendors whose client base is meaningfully concentrated in finance carry at least one vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, meaning those vulnerabilities are actively being exploited in the wild.
  • Patch management gaps are widespread across the financial supply chain: Critical-level patch management failures are present in 78% of the 140 vendors whose client base is meaningfully concentrated in finance. As exploit timelines compress and vulnerability exploitation overtakes phishing as a leading breach vector, the ability to identify, prioritize, and drive remediation of the most critical exposures across the vendor ecosystem is becoming increasingly essential.

Financial institutions now face simultaneous pressure from direct ransomware targeting and the growing volume of exploitable vulnerabilities carried across their vendor ecosystem. While the sector itself operates under extensive regulatory scrutiny, many third-party vendors face far less pressure to mature at the same pace, widening the exposure gap across the financial supply chain.

As vulnerability exploitation becomes a leading initial access vector and exploit timelines continue to compress, resilience increasingly depends on the ability to continuously identify, prioritize, and respond to critical exposures across both internal environments and third-party relationships. In this environment, capabilities such as continuous monitoring, predictive analytics, and quantified risk are no longer differentiators, but operational requirements.

To read the report, visit https://blackkite.com/reports/2026-financial-services-report.

Microsoft pulls the plug on passwords TOMORROW

Posted in Commentary with tags on June 3, 2026 by itnerd

Tomorrow, June 4, Microsoft is officially retiring the master password feature for its Edge browser.

The move marks the end of password-based authentication for the browser’s built-in manager and a broader shift toward passwordless authentication across the Microsoft ecosystem. Users will now be required to use device-based authentication methods, such as Windows Hello (PIN, fingerprint, or facial recognition) to access their saved passwords in Edge. It’s the latest move in Microsoft’s offensive against passwords, pushing the world toward a passwordless future of passkeys and biometrics. If you haven’t set up Windows Hello yet, you should act now.

Ignas Valancius, VP of engineering at the cybersecurity company NordPass, comments:

“By disabling the master password in Edge, Microsoft isn’t just changing a setting — they’re forcing a change in habit. While biometrics and passkeys are considered more convenient and secure than passwords, this ‘cold turkey’ transition might become unpleasant for users who prefer to hold on to their passwords.

“And there absolutely are people who prefer passwords, because we’re creatures of habit. We can all relate to that feeling of being in a comfort zone and not wanting to change anything. Users who want to stick with a master password can easily find alternatives in third-party password managers. But personally I think a push toward passwordless authentication is a positive development.

“When people manage too many passwords, they tend to reuse them or create simple variations, such as changing a single letter or number. This practice creates significant vulnerabilities — if one of these accounts is breached, all other accounts sharing the same or a similar password become compromised.

“Microsoft began phasing out password-based authentication last year, starting with its Authenticator app. Passwords and autofill features were moved to the password manager built into the Microsoft Edge browser (similar to how the Google Chrome manager works).

“At the end of February 2026, the company removed support for master passwords in the browser. While it was no longer possible to create a new master password, existing ones continued to function — until now. After June 4, 2026, legacy master passwords will stop working entirely, and users will be able to access the password manager via device authentication only.

“Such steps taken by Big Tech companies have likely helped reduce the number of passwords people juggle. Our recent research shows that the average number of passwords an individual manages dropped from 168 in 2024 to 120 in 2026, with work-related passwords seeing a similar decrease from 87 to 67.

“Users are increasingly opting for the convenience of logging in through single sign-on (SSO) with their primary account, such as Google, Apple, or Facebook. The growing adoption and promotion of password alternatives like passkeys, Apple Face IDs, Windows Hello, and WebAuthn are contributing to this long-awaited decline. Our own offering of passkeys may also have played a role in this trend.”

Passwords need to die. But whether it’s passwordless authentication or PassKeys, it time for the password to die and I am all here for it.