Archive for June 17, 2026

SOCRadar Launches Free FortiBleed Exposure Checker & Publishes Most Extensive Dataset on the Fortinet Credential Leak

Posted in Commentary with tags on June 17, 2026 by itnerd

The SOCRadar Threat Research Team, among the first to identify and analyze the FortiBleed leak, has opened its research to the public, having already alerted thousands of customers and national CERTs — and invites every government cybersecurity agency to coordinate on the data.

Over the past 24 hours the company’s Threat Research team has reconstructed the full attack chain behind the campaign, validated the exposed records, and proactively notified thousands of affected customers as well as the local and national CERTs it works with. With those stakeholders already informed, SOCRadar is now making its analysis available to everyone.

SOCRadar also announced the public release of its free FortiBleed Exposure Checker, a tool that lets any organization instantly verify whether its IP Addresses or Domains appear in the FortiBleed dataset — one of the largest known collections of compromised Fortinet credentials.

To view the extended dataset and use the free FortiBleed Exposure Checker, have a look at this link: FortiBleed Exposure Checker 

Malicious JetBrains plugins show Al credentials are becoming a prime target

Posted in Commentary with tags on June 17, 2026 by itnerd

The discovery of malicious JetBrains Marketplace plugins designed to steal Al API keys highlight a growing reality for developers: attackers are increasingly targeting the tools and integrations that power Al-assisted software development. Rather than exploiting a vulnerability in the IDE itself, these plugins abused the trust developers place in third-party extensions and the valuable credentials they manage. Al API keys are quickly becoming high-value targets because they provide both access to powerful Al services and, in some cases, pathways to sensitive code, data, and development workflows.

You can get an overview of the campaign here: Multiple JetBrains IDE plugins caught stealing AI keys

Yagub Rahimov, CEO, Polygraf AI had this to say:

“These two stories are the two sides of the same coin. They have different attack surface, but the same target, which is the AI tooling people now trust by default. The plugins steal the keys that pay for the models, whereas the extensions steal what’s actually being said to them.

The plugin malware works because the plugin does everything it promises (chat, commit messages, code review, etc), which is why it’s not being paid attention to. The theft is invisible because the product is real. The “innovation” here is the resale part – stolen keys get sold back through a donation wall while the original developer keeps paying the bill.

The extension side is more invisible – both extensions had been legitimate ad blockers before the AI interception was slipped in through an update. The tool you vetted 2 years ago isn’t the tool running today. And what leaks isn’t something you can rotate, like a password. It’s the full content of what people paste into it.

Both attacks use the same blind spot. The market was always securing the network, the endpoint, the identity layer, but existing tools see an HTTPS request, not that a contract is being pasted into a chatbot or an API key is being forwarded to an unknown server. Nobody is watching the AI interaction layer at the semantic level. What actually flows into these tools and what comes back out. That’s what shaping our approach at Polygraf AI – governing the input and output of every AI interaction in real time, rather than assuming a tool is safe because it looked legit on install day”

Developers need to check their code to see if they are using plug ins that are untrusted. If they are lucky, someone will point it out to them. If not, then it is a safe bet that someone with totally pwn them.

UPDATE: Yogita Parulekar, CEO, Invi Grid is the first to add commentary:

   “The JetBrains Marketplace exposure illustrates a new category of business risk. Unlike a traditional breach, a stolen AI API key grants unauthorized access to billable infrastructure – attackers don’t just exfiltrate data, they resell your AI access while your quota depletes in real time. The financial impact accumulates silently, often weeks before any alert fires.

   “We see this pattern repeatedly: organizations with no visibility into AI spend consumption, blindsided by five-figure bills and compromised pipelines. The root cause is governance architecture that was never designed for AI – fragmented tools covering security, budget, and operations in isolation.

   “The organizations that navigate this threat successfully treat AI governance as a business continuity need and an end-to-end discipline that addresses the full surface: spend controls, kill switches, real-time alerting, and continuous security oversight – purpose-built for the way AI infrastructure actually operates.”


John Strand, Owner, Black Hills Information Security, Inc. adds this:

“Supply chain attacks are accelerating at a pace that should concern every security leader. Organizations need to strengthen change management processes and begin collecting network telemetry today. If you don’t have Zeek or similar visibility at the edge of your environment, you need a plan to get there quickly.

   “The ability to hunt for suspicious outbound communications and identify compromised software behavior is becoming critical. The future of defense cannot rely solely on endpoint protection. Without network visibility and threat hunting, organizations will increasingly find themselves blind to some of the most dangerous attacks they’re likely to face.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs has this:

   “Fifteen plugins stole AI API keys from the JetBrains Marketplace for eight months. Nobody was hunting developer workstations. Organizations run threat detection on production systems and leave developer tooling entirely out of scope.

   “The VS Code marketplace went from zero documented supply chain campaigns in 2024 to seven in 18 months. JetBrains was next in line. Marketplace review checks whether a plugin works, not where it sends your credentials. JetBrains tested binary compatibility and basic functionality; outbound network destination verification was never in scope.

   “Most organizations perform vendor reviews for SaaS platforms but let developers install IDE extensions with zero oversight. These plugins run with full access to source code, credentials, and AI API keys worth real money. Treat them like vendors: full inventory, allowlisting, zero-trust posture.

   “The safer path for AI coding capabilities is building them in-house rather than pasting API keys into every third-party plugin that claims to need them. Marketplace review was never designed to distinguish an HTTP POST to api.openai.com from one to an attacker-controlled server. Eight months of undetected exfiltration proves the point.”

Operation Escaneo: Inside a Cyber Campaign Targeting Mexico’s Government and Financial Sector 

Posted in Commentary with tags on June 17, 2026 by itnerd

Mexican government agencies, financial institutions and critical infrastructure are being targeted through a sophisticated intrusion campaign capable of exploiting perimeter devices, stealing credentials and maintaining long-term access inside compromised networks.

CloudSEK researchers have uncovered the attacker’s exposed staging server, providing a rare view into the infrastructure, tools and tactics behind Operation Escaneo.

The investigation revealed:

  • A custom reconnaissance platform called Kimera
  • Exploits targeting Fortinet, Ivanti, Cisco, SAP, Oracle and Windows systems
  • Evidence of more than 1.3 million PII records being extracted
  • Exfiltration of a 407 MB Active Directory dataset
  • Webshells, reverse tunnels and compromised routers used for persistent access
  • CloudSEK’s analysis identifies significant operational and tactical links between the campaign and MexicanMafia, also known as PanchoVilla.
     

The report shows how the campaign progresses from mass reconnaissance and exploitation to lateral movement, credential theft, data exfiltration and long-term persistence—posing a serious risk to public-sector and financial networks across the region.

Full report: https://www.cloudsek.com/blog/operation-escaneo-mexican-government-financial-institutions-cyberattack

As AI use rises, over four in ten consumers question whether messages are genuine says Exclaimer

Posted in Commentary with tags on June 17, 2026 by itnerd

Exclaimer today released new research revealing that UK and US adults are increasingly turning to AI to help them communicate on a daily basis, but the technology’s ability to create polished, professional content at scale is also making them more skeptical of the messages arriving in their inboxes and apps. 

The survey of 2,000 UK and US adults found that while over half (58%) now use AI in their daily communications, 41% have questioned whether a message they received was genuine or legitimate.  

The complexity of digital communication is being compounded by the sheer number of platforms people use. The average UK and US adult now juggles at least six communication channels each day, as messaging apps, workplace platforms, social media and email compete for attention and reshape how important information is shared. 

More than one in five (22%) have missed important information because it was sent on a platform they rarely check, while the same proportion have struggled to find an important message because it was sent on what they considered the ‘wrong’ platform for that type of information. A further 18% have lost an important message because a communication platform deleted it, an account was closed or they changed devices. 

Against this backdrop, consumers are becoming more deliberate about where important information is shared. Email emerged as the preferred channel for communications that matter, with over half (56%) of UK and US adults choosing it when they need to keep or refer back to information. More than a third (39%) have deliberately chosen email over another platform to create a permanent record, suggesting consumers increasingly value channels that provide a clear, accessible trail of important communications.  

The medium shapes the message 

The research suggests that where a message is sent is increasingly shaping how it is received. Nearly half of UK and US adults (48%) say the platform used affects how trustworthy a message feels, while 46% believe it influences professionalism and 37% say it impacts how seriously the recipient takes it. 

The findings also suggest the medium doesn’t simply shape the message; it can determine whether it is seen at all. Younger consumers are significantly more likely to miss important information because it was sent on a platform they rarely check, with 33% of 18-24-year-olds reporting this, compared to just 15% of those aged 55 and over. Older consumers, meanwhile, are far more likely to keep important messages for future reference, with 62% of those aged 65 and over saying they have done so, compared to 35% of 18-24-year-olds.  

The end of email? Absolutely not 

New platforms may have changed how people chat, share quick updates and make social plans, but when something has long-term value or consequences, many still turn to email. It remains the preferred channel for making formal complaints to a company (cited by 51% of UK and US adults), receiving important updates like benefits or HR updates from an employer (47%), applying for or discussing a job opportunity (32%), and receiving healthcare information or results (29%).  

That reliance on email for important information is placing a greater emphasis on trust. With phishing still the most common cyber threat facing UK and US businesses, and AI making fake messages harder to spot, consumers are looking for clear signs that an email is trustworthy. And older generations are the most sceptical: over half (53%) of those aged 65 and over say they have questioned whether a message was genuine or legitimate, compared to 26% of 18–24-year-olds.  

When judging whether an email is genuine, the top three trust signals UK and US adults look for are full contact details (45%), a professional company email address (44%) and a clear sender name (31%). Older consumers are more likely to rely on practical signals, with 53% of those aged 65 and over saying full contact details make an email feel trustworthy, compared to 38% of 18–24-year-olds. Gen Z, meanwhile, is twice as likely as the Silent Generation (28% vs. 14%) to view visual cues like company logos and branding as trust signals. Professional email signatures resonate most with working-age adults, with almost a third (31%) of 25-44-year-olds saying they increase trust.  

AI enters the chat 

The role of AI in everyday communication is expanding from editing words to managing impressions. More than half (58%) of UK and US adults now use AI in some aspect of their communications, most commonly to improve grammar and spelling (21%) or make their writing sound more professional (20%). Others increasingly use it to shape how they come across, with 14% using AI to sound more confident, 12% to soften difficult messages and 9% to avoid awkward conversations altogether. 

AI usage falls sharply with age. Just 30% of those aged 65 and over say they use AI in their daily communications, compared with 79% of 25-34-year-olds and 82% of 18-24-year-olds. Younger consumers are also more likely to use AI to navigate difficult social situations. One in five Gen Z consumers (20%) use AI to soften difficult messages, while a similar proportion (19%) use it to avoid awkward conversations, compared to just 5% and 2% of Baby Boomers respectively. 

You can access Exclaimer’s full When it Matters: How People Really Communicate study here: https://exclaimer.com/blog/how-people-really-communicate/ 

BlueKit’s P2P phishing infrastructure makes detection and takedowns harder says CloudSEK

Posted in Commentary with tags on June 17, 2026 by itnerd

Phishing platforms are no longer stopping at stolen passwords. CloudSEK researchers have uncovered how BlueKit is evolving into a full-scale criminal SaaS platform that can hijack active sessions, enrol attacker-controlled passkeys, change passwords and lock victims out of their accounts almost immediately.

The most significant finding is BlueKit’s migration to a peer-to-peer phishing-page rendering architecture, designed to conceal its backend infrastructure from browser developer tools and conventional network analysis. This makes reverse-IP tracking, infrastructure fingerprinting, automated scanning and traditional IOC-based detection considerably more difficult.

CloudSEK’s investigation also identified:

  • 87 ready-made phishing kits targeting banks, cloud platforms, cryptocurrency exchanges, enterprise services and global consumer brands
  • Automated post-compromise workflows for Google, Microsoft and Amazon accounts
  • Session-cookie theft that can undermine conventional MFA protections
  • A Google Ads workflow capable of adding an attacker as an account administrator
  • Ledger and Trezor templates designed to steal cryptocurrency wallet recovery phrases
  • BlueKit’s complete 29-table database schema, including victim records, operator accounts, reseller infrastructure and cryptocurrency payment data
  • A reseller and white-label model that allows other cybercriminal groups to rebrand and distribute the platform

While BlueKit has been previously documented, CloudSEK’s research provides a deeper view into its evolving architecture, internal database, commercial ecosystem and automated account-takeover capabilities.

Full report: https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas

SentinelOne Opens Purple AI Agentic Investigations to All Customers, Bringing Frontier AI Directly Into the SOC

Posted in Commentary with tags on June 17, 2026 by itnerd

SentinelOne today opened Purple AI Agentic Investigations to its customers and introduced Singularity Creditsa unified currency for running AI-powered work across the Singularity Platform. Starting this week, customers can opt into a complimentary trial of the newest capability from Purple AI, SentinelOne’s autonomous security reasoning for the agentic SOC. That capability — ‘zero-click,’ autonomously initiated investigations — detects, investigates, verifies, and responds to threats without human dependencies. When a threat crosses a defined threshold, Purple AI investigates, renders a verdict, and stops it at machine speed, while analysts keep full visibility and control.

The capability arrives as security teams confront a hard limit, not detection, but investigation capacity. Detections climb with every new tool and every expansion of the attack surface, alerts queue for attention, and verdicts wait on analyst availability, with coverage thinning on nights, weekends, and during surges. Frontier-AI-powered threats are poised to widen that gap further.

Why SOC Teams Are Adopting Purple AI Agentic Investigations

  • Seamlessly integrated — zero configuration, working from day one.

Purple AI is built into the Singularity Platform, not bolted onto it. Agentic Investigations run on telemetry already in the platform — across endpoint, identity, cloud, and third-party security data — inside the automated workflows customers already use. There is nothing to deploy, integrate, or tune, and no data leaves the platform. Activation is a single click.

  • A force multiplier for every analyst.

Purple AI does the investigation work — collecting evidence, correlating telemetry, and building the attack timeline — so analysts start at the verdict instead of the alert. It scales a team’s investigation capacity without scaling headcount, and frees analysts for the judgment, threat hunting, and response decisions that need a human. It is designed as an extension of the analyst: amplifying human defenders, not replacing them.

  • Fully audited — governed autonomy, no black box

Every verdict carries a complete, auditable evidence chain, so analysts can review each AI step and outcome with confidence. Customers set the degree of autonomy through an adjustable human-in-the-loop approach that scales to their confidence and SOC maturity — verdicts can trigger automated, policy-driven responses, or prompt an analyst with recommended actions. Activation is admin-controlled, role-based, and reversible at any time, and consumption guardrails keep usage and downstream cost in the hands of those with the right authority.

  • Built on the most advanced reasoning in security

Purple AI is the reasoning brain and interface for the entire Singularity Platform. It brings human-level reasoning from advanced frontier-AI models to bear through a multi-model approach — combining Anthropic’s Claude, OpenAI’s GPT, and SentinelOne’s proprietary “Ultraviolet” models — to compress investigations that once took hours or days into minutes and seconds. For critical threats, investigations trigger automatically and deliver verdicts that can be acted on autonomously or by an analyst.

The introduction of Singularity Credits

Singularity Credits are a flexible, unified currency customers draw down across AI-powered work in the Singularity Platform, including Purple AI Agentic Investigations. To start, SentinelOne is granting customers a complimentary allotment of Credits to trial the capability.

Delivering on the agentic SOC by amplifying defenders, not replacing them

Agentic Investigations advances SentinelOne’s vision of the agentic SOC: one where frontier-AI reasoning amplifies and scales human defenders rather than sidelining them. Purple AI acts as the brain and interface for the entire platform from simplifying querying, to recommending actions, to autonomously detecting, triaging, and stopping threats. Because it operates natively on AI, endpoint, identity, cloud, and third-party telemetry already in the Singularity Platform, it drives Singularity to be an agentic realization of the integrated security operations center (ISOC) category defined by Gartner.

Availability & access

The Purple AI Agentic Investigations trial is now available in Singularity consoles. New and existing Singularity customers can opt in and begin running agentic investigations immediately. Investigations consume Singularity Credits during the trial, but customers are not charged and no payment method is required. The complimentary trial is currently planned to run through August 15, 2026. After the trial, customers can purchase Singularity Credits through partners, direct billing, and eCommerce.

Arcitecta, GRAU DATA and COMBACK to Showcase End-to-End Data Intelligence and Archive Solution at ISC 2026

Posted in Commentary with tags on June 17, 2026 by itnerd

Arcitecta today announced that it will demonstrate its advanced Mediaflux® research data management platform integrated with GRAU DATA’s Metadata-Hub and XtreemStore, and COMBACK’s BDT ORION enterprise tape infrastructure at ISC 2026, June 22-26, 2026, in Hamburg, Germany, in Booth D39.

Arcitecta, GRAU DATA and COMBACK connect active data management, metadata-driven archive, and enterprise tape infrastructure into a single, scalable architecture. This combined solution helps organizations manage, preserve and extract value from massive datasets across active and archive storage tiers.

Key benefits of the combined Arcitecta, GRAU DATA and COMBACK solution include:
 

  • Manage large-scale datasets across active and archive environments
  • Maintain visibility and accessibility across the data lifecycle
  • Automate policy-driven data movement and retention
  • Reduce long-term storage cost and energy consumption
  • Scale sustainable archive infrastructure for petabyte- and exabyte-scale environments

“Data has become the foundation of AI, research discovery and high-performance computing, yet many organizations struggle to manage and capitalize on the massive volumes of unstructured data they generate and maintain,” said Jason Lohrey, CEO and founder of Arcitecta. “Together with GRAU DATA and COMBACK, we’re helping customers unlock the maximum value of their data through a modern approach that simplifies data management, improves preservation and accessibility, and accelerates insights. We look forward to demonstrating how these capabilities are enabling the next generation of AI and research breakthroughs.”
 

For more information, visit: https://www.arcitecta.com/events/2026/isc/.

To schedule a meeting at ISC 2026, visit: https://www.arcitecta.com/events/2026/isc/#meeting.

Resources

Switzerland extends its lead in the technologies reshaping the global economy 

Posted in Commentary with tags on June 17, 2026 by itnerd

The technologies now driving the global economy, from advanced computing to artificial intelligence and robotics, are built patiently, over decades of sustained investment and deep scientific groundwork. Increasingly that work traces back to a country a fraction of the size of the giants it competes with. 

Switzerland now directs a greater share of its venture capital to deep tech than any other nation, and commits more per head than any country in Europe, placing it among the top three worldwide. The finding anchors the Swiss Deep Tech Report 2026, published today by Deep Tech Nation Switzerland, Founderful, Kickfund, Startupticker.ch, and Dealroom.co, and launched at VivaTech in Paris. 

The report sets out where the next decade of frontier technology will be engineered. The world’s most valuable companies are built on data centers, artificial intelligence and robotic automation, and Switzerland is among the few countries worldwide where that work is researched and commercialized at the frontier. What has changed is that its companies now stay to scale, and the world has taken notice. “For the first time, the companies spinning out of ETH and EPFL are staying, scaling and attracting serious capital,” says Jean-Philippe Fricker, Co-Founder and Chief System Architect of Cerebras Systems. The country’s international standing now matches the strength of its ecosystem. 

Five findings that put Switzerland at the forefront of deep tech innovation

The pipeline is shifting toward the sectors that dominate global capital. AI and machine learning now account for one in four newly founded Swiss deep tech companies, more than double their previous share. Beyond startup creation, Switzerland has the highest density of AI researchers globally, twice that of the UK and the US. Robotics is moving even faster relative to peers: Switzerland has created 3.5 times more venture-backed robotics startups per capita since 2020 than the United States, and 5 times more than the UK. In Future of Compute, 2026 is already a record funding year, and Switzerland boasts 7 times more patents per capita than the European average, driven by its world-leading microelectronics and high-precision sensor industries. 

The world’s most deep-tech-focused venture market. 63% of all Swiss venture capital flows to deep tech, the highest share of any country, ahead of China and the United States and nearly double the share of Germany and the UK, and well ahead of France. 

First in Europe on intensity, top three globally. At $1,470 invested per capita, Switzerland commits more to deep tech per head than any country in Europe. Worldwide, that places it among the top three nations alongside Israel and the United States. 

Funding is accelerating. Swiss deep tech funding has grown roughly fivefold since 2015 to reach a record $2.6B in 2025. 

The strongest growth is still ahead. ETH Zurich and EPFL Lausanne are Europe’s leading universities for new deep tech spinouts. Building on a leading position, the two have extended their lead since 2023, and that cohort is only now reaching the seed-to-Series-A window, the stage at which company value and capital raised compound most sharply. 

Where the opportunity sits 

Foreign investors supply 88% of Swiss deep tech funding at rounds of $100M and above, against 75% across Europe, while domestic capital falls to just 12% at late stage. In a top-ranked ecosystem, late-stage capital remains underweight relative to the quality of the companies being built, leaving clear room for new investors to enter early. 

What happens next 

The seed-to-Series-A cohort now moving through the ecosystem is the largest Switzerland has produced, and it is only now reaching the stage where company value and capital raised compound most sharply. Deep tech funding has already grown roughly fivefold since 2015 to a record $2.6B. The companies are staying, and the funds are arriving on their own. The report sets out, sector by sector, the leaders and the startups most worth watching, and invites the investors who would rather arrive early than late. 

The full report is available for download here: https://deeptechnation.ch/resources/swiss-deep-tech-report-2026  

24 billion records leaked online, including usernames and passwords: billions at risk of account takeover 

Posted in Commentary with tags on June 17, 2026 by itnerd

On June 12th, the Cybernews research team discovered a data leak involving 24 billion records, making it one of the largest leaks ever found. The leak included tens of billions of login credentials from 36 sources, ranging from Telegram channels to combined data collections of previous data breaches. The Cybernews team says the leak is most likely an infostealer log database.

Here are the key findings:

  • The records were stored on a publicly accessible Elasticsearch cluster, a group of interconnected search servers. The total volume of information in the cluster exceeded 8.3 terabytes.
  • The leaked data included login credentials in raw format, with each login detail saved separately, including email addresses, usernames, and passwords in plaintext. Researchers also identified URLs that the leaked credentials are supposed to grant access to.
  • The data was collected from numerous sources, with over 1.7 billion records taken from hacking-oriented Telegram channels.
  • The data is no longer publicly exposed, and so far, Cybernews cannot identify the owner of the leaked credentials. 
  • Cybernews is unable to accurately say how old or new the leaked data is. Based on a February 2026 news article contained in the leak, it appears the data owner regularly updates the cluster with new information.

The leak highlights the danger of infostealing malware, as nearly all exposed records were infostealer logs. Users may accidentally download infostealer malware through pirated software, infected PDFs, or other compromised files. Once infected, the malware may then secretly extract passwords, autofill details, credit card numbers, and even access to crypto wallets, often without the user realizing their device has been compromised.

The Cybernews research team monitors and analyzes various sources for leaked data to help people maintain and improve their online privacy and security.

For more information and screenshots of the leaked database, here’s the full report: https://cybernews.com/security/24-billion-credentials-data-leak