Archive for June, 2026

Canada is Winning for Canadians

Posted in Commentary with tags on June 25, 2026 by itnerd

Canada’s success at the FIFA World Cup 2026™ is turning into savings for people wanting to upgrade their television.

With Canada advancing to the Round of 32 for the first time ever, Hisense Canada’s Win With Canada promotion has kicked up to a $600 rebate for people who buy qualifying Hisense products. If Team Canada wins this match and moves on to the Round of 16, Canadians who participated in the promotion are eligible receive up to $1,000 cashback on their purchase — and to match Canada’s success Hisense is extending the promotion to apply to qualifying Hisense products purchased by June 27th.

The promotion allows Canadians who purchase eligible Hisense televisions, laser TVs and select refrigerators to earn cashback tied directly to Team Canada’s performance at the FIFA World Cup 2026™. What began as a guaranteed $150 rebate has steadily increased as Canada has advanced through key tournament milestones — $200 when Canada scored its first goal, $400 when it won its first match, and now $600 for advancing beyond the group stage.

The Win With Canada promotion is part of Hisense Canada’s broader celebration of FIFA World Cup 2026™, a tournament that has Canada co-hosting matches for the first time and bringing unprecedented excitement to soccer fans across the country.

For more information, please visit winwithcanada.ca

About Win With Canada

Win With Canada is a Hisense Canada promotion that rewards consumers when Team Canada succeeds at FIFA World Cup 2026™. Purchasers of eligible Hisense televisions, Laser TVs and select refrigerators can qualify for cashback rebates tied to Team Canada’s tournament performance, with a maximum potential rebate of $1,000. Product must be purchased before June 23rd to qualify.

Consumers can visit WinWithCanada.ca for complete contest rules, eligibility details and cashback redemption information.

Bitdefender Launches RealCheck

Posted in Commentary with tags on June 24, 2026 by itnerd

Bitdefender, a global cybersecurity leader, today announced the launch of Bitdefender RealCheck, a standalone solution that helps consumers evaluate the authenticity of video content circulating across digital platforms and whether it carries malicious intent — such as financial fraud, credential theft, or defamation. As deepfakes proliferate across social media at an unprecedented pace, Bitdefender RealCheck gives consumers a powerful and accessible tool to separate fact from fabrication before they trust, share, or act on what they see.

Deepfakes have become one of the most effective tactics in a cybercriminal’s playbook. Deloitte predicts generative AI could drive fraud losses to $40 billion in the U.S. alone by 2027. According to a Bitdefender global survey of 7,000 consumers, AI-powered deepfake scams ranked as the top security concern — and social media has now surpassed every other channel as the leading medium for successful scams. The same survey found that consumers correctly identify high-quality deepfakes only 24% of the time.

Bitdefender RealCheck is a standalone solution for Android and iOS devices. Once installed, users simply submit a video link or upload a file for analysis. Bitdefender RealCheck conducts a structured, multi-layered analysis, recognizing that not all synthetic or altered videos are malicious (some are clearly satirical or entertainment-driven) and delivers a detailed report covering manipulation likelihood, deceptive intent, and transcript-level indicators. Rather than a simple yes-or-no verdict, Bitdefender RealCheck arms consumers with the context they need to make informed decisions.

Key features and benefits include:

  • Validate deepfakes across all major social media platforms — Bitdefendeer RealCheck assesses video content from local uploads, web-hosted videos, and posts across X, YouTube, Instagram, Facebook, and TikTok. It also identifies public figures, including celebrities, well-known business executives, and politicians, who are currently being impersonated or misused in active deepfake campaigns.
  • In-depth analysis and actionable reports — Bitdefender RealCheck delivers a thorough, multi-layered analysis of video content and associated audio, assessing manipulation likelihood and deception risk at the transcript level — evaluating speech segment by segment to pinpoint exactly where manipulation may have occurred. Rather than a simple yes-or-no result, consumers receive a detailed, structured report telling them what they are looking at and whether it was designed to steal their money, credentials, or personal information.
  • Protect the people you care about — Bitdefender RealCheck analysis and reports are shareable and can be sent to family and friends, even if they don’t have an account. In a world where a single convincing deepfake can spread quickly through a family group chat, the ability to share verified findings is a meaningful line of defense.

Availability: Bitdefender RealCheck is available now for Android and iOS devices in English across 14 countries, including the U.S., U.K., Australia, Canada, Germany, Italy, Spain, and France. Support for additional languages is planned for future releases.

Guest Post: Anatomy of a DevOps Breach: How Global Brands Became Cyber Targets

Posted in Commentary with tags on June 24, 2026 by itnerd

According to the DevOps Threats Unwrapped Report 2026, technology and software organizations remained the sectors most targeted by cybercriminals. 

Highlighting persistent vulnerabilities in enterprise DevOps environments, the report points to recent breaches at companies like Orange, Red Hat, Jaguar Land Rover, and Nissan – confirming that the software supply chain remains a prime target.

The scale of these attacks is growing rapidly: incidents across top DevOps platforms rose by 21%, while total disruption time nearly doubled to 9,255 hours. Additionally, vendors patched 236 vulnerabilities in 2025 alone, with 59% rated as high or critical threats capable of enabling unauthorized access, privilege escalation, or system compromise.

Technology and Software are Primary Targets

Organizations operating in the technology and software sectors continue to be the primary targets for cybercriminals, largely because they hold valuable intellectual property, source code, and privileged access to downstream networks. Closely following them are the telecommunications and automotive industries, which experienced a sharp increase in malicious activity throughout 2025. Notably, many of these incidents were driven not by direct attacks, but by security breaches occurring within trusted vendors and third-party partners. 

Rounding out the top three most targeted sectors are retail and consumer businesses, which remain highly vulnerable due to the massive volumes of customer data they process and the deeply interconnected nature of their digital ecosystems. 

Key Incidents, Data Exposure & Lessons Learned

Jaguar Land Rover: Old Credentials, New Consequences

Attackers breached Jaguar Land Rover’s Atlassian Jira environment using years-old credentials previously stolen by infostealer malware. The actors exfiltrated 350 GB of data, including internal documents, source code, and employee information. Later in the year, a subsequent incident disrupted manufacturing operations for over a month, leading to financial losses exceeding $890 million.

Stale credentials remain a ticking time bomb, capable of causing delayed but catastrophic operational and financial fallout.

Red Hat: Third-Party Infrastructure Under Attack

Threat actors gained unauthorized access to a self-hosted GitLab environment used by Red Hat’s consulting division. The attackers accessed approximately 28,000 repositories, compromising customer engagement reports that contained architecture information, configurations, and credentials.

Environments perceived as “non-critical” frequently harbor highly sensitive assets that attackers can leverage for broader enterprise intrusion.

Orange: Back-Office Applications as Entry Points

In February 2025, the HellCat ransomware group exploited a non-critical back-office application at Orange Group. Maintaining access for over a month, they exfiltrated 12,000 files (~6.5 GB), including internal documents, source code, contracts, and employee emails.

Attackers are shifting focus toward secondary, less-monitored systems that organizations mistakenly classify as low risk.

Nissan: Collateral Supply-Chain Damage

Following the Red Hat incident, Nissan disclosed that data belonging to 21,000 customers had been exposed. The leak originated entirely from the compromised Red Hat-managed GitLab environment used to develop Nissan’s customer platform.

Security is only as strong as the weakest link; a breach at a trusted vendor instantly transforms into a supply-chain crisis for downstream customers.

Disney: AI-Themed Social Engineering

An employee inadvertently downloaded a malicious AI tool disguised as legitimate software. The embedded spyware captured corporate credentials, granting attackers access to Disney’s internal Slack. This resulted in the theft of 1.1 TB of data, including 44 million messages, source code, salaries, and unreleased projects.

The rise of AI-themed social engineering means a single compromised credential can lead to the wholesale exposure of internal communication and critical IP.

Microsoft, Google, IBM, PayPal, Tencent: Systemic Developer Tool Risks

A caching vulnerability in Microsoft Copilot led to the exposure of over 20,000 private GitHub repositories belonging to global tech giants like Microsoft, Google, IBM, PayPal, and Tencent. The flaw leaked sensitive assets, including API tokens, internal packages, and proprietary code.

AI-driven development workflows embed severe supply-chain risks, proving that a single anomaly in a widely adopted tool can instantly compromise thousands of organizations.

Key Takeaways: What the Data Shows

The most targeted industries in 2025 were not necessarily the least secure. They were the industries most dependent on software development, cloud infrastructure, automation, and third-party ecosystems.

Across all sectors, we can see the same pattern:

  • trusted platforms became attack vectors.
  • development environments became high-value targets.
  • third-party relationships amplified risk.
  • long-lived credentials enabled persistent access.
  • supply-chain dependencies increased the blast radius of incidents.

The lesson for 2026 is clear… Organizations must move beyond traditional perimeter-focused security and invest in identity protection, DevOps resilience, supply-chain security, and rapid recovery capabilities. Because in today’s threat landscape, attackers are no longer simply exploiting vulnerabilities. They are exploiting trust.

To download the full report, visit GitProtect.io.

About GitProtect.io

GitProtect.io by Xopero Software is an automated and manageable backup and recovery solution for all Jira, Bitbucket, GitHub, GitLab, Azure DevOps, and more DevOps stack data. It ensures data accessibility and seamless workflow for Jira Admins, DevOps, and Security Teams. Trusted by Security Teams, it helps to meet the Cloud Shared Responsibility Model, comply with security standards, and empower them with audit-ready governance, advanced reporting, and best-in-class security controls. The company’s solutions are used in over 60 countries by more than 2,000 organizations, including Fortune 500 companies.

Tata investigates breach claims involving Apple and Tesla

Posted in Commentary with tags on June 23, 2026 by itnerd

Tata has apparently been pwned and the victims are Apple and Tesla.

The individual claimed to have stolen approximately 730,000 files, including engineering documents, presentations, spreadsheets, and other internal records associated with Tata Electronics’ manufacturing operations. The alleged breach comes months after Tata Electronics disclosed a separate cyber incident that temporarily disrupted some IT systems. 

Tata Electronics is a key supplier within the global electronics supply chain, producing components and assembling products for major technology companies including being one of Apple’s most significant manufacturing partners outside of China, accounting for roughly a third of its iPhone production in India.

John Strand, Owner, Black Hills Information Security, Inc.:

   “Whenever a breach becomes public because stolen data appears on the dark web, it raises a larger question: how many similar operations, especially those conducted by nation-state-level adversaries, are still operating undetected? The attacks that make the news deserve attention, but the greater concern is the reuse and evolution of the same tactics, tools, and infrastructure across campaigns that never become visible.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this to say:

   “Apple escaped supplier concentration in China and recreated it in India under one corporate roof. A third of India’s iPhone output, one conglomerate. Single point of failure, different mailing address.

   “Vendor cybersecurity review has to cover the whole corporate family. Second cyber incident at Tata Electronics in months. TCS and JLR were hit by different attackers in the past year. Subsidiaries share IT vendors and security culture, so a breach at one should trigger immediate review of every entity holding sensitive client IP.

   “When you hand trade secrets to a contract manufacturer, the cybersecurity terms in that vendor agreement need to reflect what’s being transferred. Continuous monitoring, audit rights, and breach notification requirements should be baseline for a supplier holding IP at this sensitivity level. A questionnaire at onboarding doesn’t cut it. 630 gigabytes on a leak site shows what happens when vendor oversight doesn’t match the exposure.”

John Carberry, Solution Sleuth, Xcape, Inc. adds this:

   “This breach underscores a critical distortion in enterprise risk management where the actual containment of a data exposure plays second fiddle to managing the commercial boundaries of the cyber insurance policy. While the immediate operational crisis centers on leaked schematics for Apple and Tesla, the true systemic damage occurs when organizations prioritize check-the-box compliance to preserve underwriting limits rather than addressing the root cause of third-party aggregation risk.”

   “Critical Takeaways

  • Enterprise security teams must shift from static vendor compliance questionnaires to continuous, automated data lineage tracking across all external manufacturing partners.
  • Risk officers must audit existing cyber insurance policies to ensure coverage limits explicitly account for interconnected, multi-party supply chain liabilities rather than localized infrastructure losses.
  • Access architectures governing joint-venture environments must enforce strict zero-trust isolation to prevent lateral movement from compromised sub-contractor networks.

   “Look on the bright side: your competitors will finally find out how much it actually costs to manufacture your products.”

I think its a safe bet that if Apple and Tesla do not get the answers that they are looking for, that their contract manufacturing will be someplace else shortly.

Klue says hackers stole credential from 2022 that led to pwnage

Posted in Commentary with tags on June 23, 2026 by itnerd

Klue disclosed a cybersecurity incident affecting hundreds of customers including Recorded FutureTaniumHackerOneKudelski Security,Insurity, and Huntress, after attackers gained unauthorized access to data stored within the company’s environment. That you know. But you may not know is that the company may have used a credential that dates back to 2022:

Market research company Klue has confirmed that a credential dating back to 2022, which was part of a limited pilot, was used by hackers earlier this month to steal reams of data from its corporate customers, including several cybersecurity companies.

The new detail suggests that Klue may have had years to decommission the credential that was used for the pilot, raising questions about the company’s security posture and what actions it could have taken to prevent the breaches of its customers’ data.

Sunil Gottumukkala, CEO, Averlon had this to say:

   “This is the same pattern we saw with the Salesloft Drift attack, where stolen OAuth tokens were used to pull data from Salesforce and Google Workspace. This method is becoming the dominant way data leaves the enterprise: not through your perimeter, but through an approved SaaS integration.

   “A compromised legacy credential at Klue gave attackers OAuth tokens into hundreds of customers’ Salesforce instances, which they used to impersonate the app and exfiltrate competitive intelligence and customer data. Your security is now only as strong as the third-party apps you have granted standing access to your CRM, and most teams don’t actively track those integrations.

   “The immediate work is to inventory every OAuth integration into your SaaS, revoke what you don’t need, scope what you keep, and watch for anomalous token activity. And since the stolen data includes contact and sales detail, expect targeted phishing next. Warn your customers and employees before the attacker reaches them.”


John Strand, Owner, 
Black Hills Information Security, Inc. provided this comment:

   “This is just a preview of the coming SaaS apocalypse. As AI accelerates offensive cyber operations across threat actors, from nation-states to militias, the risk is no longer limited to organizations building new AI-driven SaaS applications. Attackers are increasingly turning existing SaaS platforms into centralized points of failure, allowing them to exploit multiple customers simultaneously.”

Denis Calderone, CTO, Suzu Labs added this comment:

   “Three Salesforce OAuth supply chain attacks in under a year, from two different threat actors, using the same playbook. Salesloft, Gainsight, and now Klue. Icarus is a brand-new extortion group, active since late April, and they executed the exact same technique that ShinyHunters ran through Gainsight back in November. Compromise the integration vendor, harvest OAuth tokens, query the Salesforce REST API with automated scripts, exfiltrate CRM data in bulk. At this point we have to accept that this particular attack pattern has been successfully commoditized.”

   “What’s got our attention is how many security vendors are on the victim list. Huntress, Recorded Future, Tanium, HackerOne, Kudelski Security, Snyk, Jamf. The data sitting in their Salesforce instances includes competitive battlecards, pricing strategy, customer contacts, deal sizes, and sales communications. We expect to see some highly targeted spear-phishing campaigns as a result of this data.  The attacker has access to real data that only an insider would know.

   “We feel it important to highlight the root cause here. Huntress traced initial access back to a single credential Klue created for a prototype third-party integration they never actually deployed. One forgotten API key got the attacker into Klue’s backend. From there, they pushed a malicious code update that harvested the OAuth tokens of all connected customers at once. So one dormant credential that nobody remembered existed opened the door to 300 organizations’ CRM environments in a single operation.

   “If you’re a Klue customer, rotate every OAuth token tied to that integration, and don’t limit yourself to Salesforce. Klue also integrated with HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack. The confirmed bulk exfiltration targeted Salesforce, but the token harvest covered all connected platforms.

   “If Klue had an OAuth connection into your Slack, your Google Drive, or anything else, treat those tokens as compromised and rotate them now. Every org needs to audit connected apps for dormant integration credentials and building automated alerts on abnormal API query volume from third-party services. If a connected app that normally syncs a few hundred records starts pulling thousands of queries in minutes, that’s your early warning.”

Damon Small, Board of Directors, Xcape, Inc. said this:

   “This third-party compromise highlights a severe operational risk where specialized business platforms become aggregate targets for corporate espionage, exposing the strategic playbooks of the cybersecurity sector itself. By exploiting Salesforce-linked integrations, attackers bypassed external perimeters to directly access sensitive competitive analysis, product intelligence, and customer data.

   “For security executives, this incident demonstrates that non-core software vendors often possess highly privileged pathways into primary data repositories. To contain this exposure, organizations must immediately catalog all API and OAuth integrations connected to their central Customer Relationship Management systems. Teams should prioritize revoking obsolete or over-privileged third-party tokens, implementing strict scoping boundaries on automated data access, and establishing anomaly detection baselines for bulk data exports conducted by integrated applications.

   “Critical Takeaways

  • Security leaders must immediately audit and inventory all active OAuth tokens and connected applications within their Customer Relationship Management environments to identify over-privileged third-party access.
  • Organizations should enforce strict data scoping and API restriction policies to limit the volume of proprietary competitive intelligence and customer telemetry accessible by integrated platforms.
  • Security operations teams need to establish baseline detection rules specifically tailored to identify anomalous, high-volume data exports or API queries originating from external business applications.

   “It is tough to sell threat visibility to your customers when your own corporate battlecards are exposed because you did not have a Klue.”

I guess that it is far past time for you to audit your environment to ensure that you’re not the next Klue. Because it is much easier to not be the next Klue that it is for me to write about you.

OpenAI’s GPT-5.5-Cyber expansion reflects AI’s shift from finding vulnerabilities to fixing vulnerabilities

Posted in Commentary with tags on June 23, 2026 by itnerd

OpenAI’s expansion of Daybreak with GPT-5.5-Cyber is another sign that leading AI companies are investing heavily in cybersecurity-focused models and programs.

For years, finding serious vulnerabilities required rare expertise, time, and deep familiarity with complex systems. Now, models can navigate large codebases, reason through attack paths, validate hypotheses, and surface security issues that might otherwise stay hidden. Defenders absolutely need access to these capabilities, and also need tools to fix what we can now find, before attackers do.

Vulnerability reports, on their own, do not protect anyone. The value comes from validating the issue, understanding its impact, developing and testing a patch, coordinating disclosure, and helping teams deploy the fix. We are investing alongside our partners to improve these latter steps, in order to turbocharge defenders and convert model capability into real-world risk reduction.

While much of the attention around AI has focused on offensive risks, announcements like this reflect growing demand for tools that can help defenders analyze vulnerabilities, support security research, and respond to threats more efficiently. As these capabilities continue to improve, the focus will increasingly shift from what AI can find to how effectively organizations can act on those findings.

Gidi Cohen, CEO & Co-founder, Bonfy.AI had this comment:

“OpenAI’s GPT‑5.5‑Cyber and ‘Patch the Planet’ underline a new reality: AI is now accelerating both vulnerability discovery and exploitation on timelines measured in days or even hours, not weeks. That’s welcome support for overburdened maintainers who need help finding and patching flaws across massive codebases and critical open‑source projects, but it also means organizations must assume that any internet‑facing weakness will be identified and weaponized very quickly.

To keep pace, enterprises need faster, AI‑assisted discovery and patching baked into their software development lifecycle—not treated as periodic clean‑up work after headlines hit. Just as importantly, even aggressive patching won’t be enough on its own. As models get better at navigating production environments, organizations will need stronger, data‑centric controls across email, SaaS, collaboration tools, and AI systems so that when a vulnerability is inevitably missed or exploited, the blast radius for sensitive data is tightly contained and core business operations remain resilient.”

Yusif Mukhtarov, Lead Data Scientist, Polygraf AI, Polygraf AI follows with this:

“We’ve reached the point in time where every major AI lab is now shipping its own cybersecurity model (Anthropic with Mythos, OpenAI with GPT-5.5-Cyber). They’re all coming from the same idea: finding vulnerabilities wasn’t the hardest part. The top models are clustered within a few points of each other, all on the high end of 80%. When everyone can find the bugs, finding bugs stops being the differentiator. The bottleneck today is validation, triage, patch dev – basically the parts that still run on human time.

That’s why Patch the Planet exists. Frontier models are drowning (cURL, Python, and the Go) projects in findings faster than volunteer maintainers can act on them, and they have to partner with those projects’ maintainers. A model surfacing a 23 year old problem is impressive, but every finding still needs a human to verify it, write the fix, and ship it without breaking the millions of systems depending on that code. In this case, patching scales with people and discovery with compute.

What I wouldn’t agree with is saying that this is a defensive win. The ability to generate a patch can also be used to generate an exploit. Offense in this case has the structural edge – a defender has to validate, test, and deploy across a fragmented install base, an attacker just needs the exploit to work once.  That imbalance is the problem of this moment, and no model release closes it.”

The one thing that I see as a problem is that more advanced AI models are turbocharging bad actors’ abilities to take advantage of security vulnerabilities, forcing the industry to plug the holes almost as soon as they are discovered. That however isn’t a bad thing as far as I am concerned.

Check Point to Embed OpenAI Frontier Cyber Capabilities into Check Point Security Products 

Posted in Commentary with tags on June 23, 2026 by itnerd

Check Point today announced the use of OpenAI’s frontier cyber capabilities into its customer-facing defenses. Through the OpenAI Daybreak Cyber Partner Program, open to only a select group of security vendors, Check Point can embed OpenAI models directly into the products, workflows, and managed services its customers rely on. 

It marks a meaningful shift, from using these models internally to embedding them directly inside the defenses that protect customers, carrying the safety controls, abuse-prevention standards, and scoped outputs that enterprise security demands. The aim is to sharpen threat prevention, faster remediation, and stronger security operations, delivered through the products and services customers already rely on. 

The threat landscape is being shaped by AI. Threat actors are using it to move faster, craft more convincing attacks, and find weaknesses at scale. Defenders need equivalent or stronger capabilities, delivered safely and within clear boundaries. The quality of the models powering defensive workflows has become a strategic variable, not a technical detail. 

Through this expanded partnership, Check Point is identifying the defensive security workflows and solutions where OpenAI’s trusted access for cyber models, paired with the right safeguards, can deliver measurable customer value.  

Check Point and OpenAI are working together to help define the standards for using trusted access frontier AI responsibly in security, building protections against misuse and the controls to catch and stop it. The rollout is deliberately gradual: it begins with carefully controlled defensive uses and widens only as those protections prove themselves. This disciplined approach reflects how Check Point brings AI into its platform across the board, with the rigor and responsibility enterprise security demands. 

Claude Reports Major Outage Across Multiple Models 

Posted in Commentary with tags on June 23, 2026 by itnerd

You may have noticed that Claude AI has had an outage today. 9to5Google reports the following:

Anthropic says it is aware of an outage and has rolled out a fix as recent as 10:53 a.m. ET. The company’s server status website indicates an issue affecting multiple models occurred at 10:19 a.m. ET.

The status update doesn’t detail which models were affected, though attempts to get a response from Sonnet and Opus returned nothing. Those models seem to be the most commonly used, especially as Fable 5 was recently pulled from user access.

The current outage did, however, affect those models across all platforms except for Claude for Government. That includes claude.ai, Claude Console, Claude Code, and Claude API. The total outage time comes close to an hour and stands out as one of the largest outages to hit Anthropic within the past 60 days.

Commenting on this news is Jamie Beckland, Chief Product Officer at APIContext

“Ready or not, AI inference is now production infrastructure. Enterprises are no longer using these systems only for experiments or side projects. They are putting AI into customer support, coding workflows, analytics, operations and decision support. When an inference endpoint slows down, throws errors or goes unavailable, that can now break a real business process.

Enterprises must run AI with the same discipline they apply to payments, cloud, APIs and other critical services. That means continuously monitoring inference endpoints for latency, error rates, model availability, response quality and regional performance. It also means having a tested failover plan before the outage happens.

Applications with one model provider hardcoded create a single point of failure. A more resilient approach is to design AI systems with fallback models, backup providers, graceful degradation and clear routing rules. Not every task needs the same model. If the primary model is unavailable, some workloads can move to another frontier model, some can fall back to a smaller model, and some should pause rather than return a bad answer.

Six months ago, these tools were enterprise experiments. Now, AI resilience is part of operational resilience.”

If you rely on AI as part of your business, then you need to plan for downtime. Why? Downtime is part of the game and you need to be prepared for it or bad things will happen.

TELUS named one of the world’s most sustainable companies

Posted in Commentary with tags on June 23, 2026 by itnerd

TELUS is grateful to have been recognized among the world’s sustainability leaders after being named to TIME Magazine’s World’s Most Sustainable Companies list and earning third place on Corporate Knights’ Best 50 Corporate Citizens ranking. The recognition reflects more than 25 years of integrating environmental stewardship, innovation and social purpose into the company’s core business strategy..

TIME Magazine and Corporate Knights evaluate thousands of companies across sustainable revenue, governance, emissions, innovation, transparency and social impact, making these among the world’s most respected sustainability benchmarks.

This recognition builds on TELUS’ exceptional track record of sustainability leadership, including earning inclusion in Newsweek’s World’s Greenest Companies, receiving a Schneider Electric Sustainability Impact Award for excellence in strategy, digitization, and decarbonization, and being listed on the Dow Jones Best-in-Class Indices for 25 consecutive years, a feat unmatched by any other North American telecommunications company, and inclusion in Corporate Knights’ Global 100 Most Sustainable Corporations.

Driven by its leadership in social capitalism, TELUS has made significant progress on its commitments to ambitious science-based greenhouse gas emission reduction targets, and is continuing to implement sustainable practices across its business including:

  • The achievement of its 2030 climate target of 46% reduction in Scope 1 and 2 emissions five years ahead of schedule
  • Launching its Climate Transition Framework to map its journey to net zero by 2040
  • Avoiding more than 1.4 million tonnes of CO₂e emissions through customer use of TELUS-enabled digital solutions
  • Continuing the expansion of digital health, smart energy, IoT, and precision agriculture technologies
  • Facilitating the ongoing retirement of copper infrastructure in favor of more energy-efficient fibre networks
  • 96% of its electricity – globally – comes from renewable or low-emitting sources
  • 26 million trees planted with our customers and partners, supporting ecosystem restoration across over 16,000 hectares of land
  • 18 million devices diverted from landfills and the launch of a new reuse and recycle program

Sustainable business practices continue to strengthen TELUS’ operational resilience, improve network efficiency, reduce emissions and create long-term value for customers, communities and shareholders.

To learn more about TELUS’ commitment to social capitalism and sustainability, visit telus.com/sustainability.

Peer Software Launches Latest Version of PeerGFS with Major Performance Gains and Enhanced Edge Data Management

Posted in Commentary with tags on June 23, 2026 by itnerd

Peer Software today announced PeerGFS v6.4, the latest version of its Global File Service platform. The new release delivers significant advancements in performance, scalability and operational flexibility for organizations managing large-scale environments and globally distributed file infrastructure.

Today’s enterprises, particularly in the semiconductor, healthcare and life sciences, AI/ML and other data-intensive industries, are facing exponential growth in data driven events and increasingly complex application workloads. As a result, organizations are distributing workloads across multiple locations, dynamically pursuing available compute resources, and leveraging cloud elasticity to scale capacity on demand.

PeerGFS v6.4 is purpose-built to meet this challenge, enabling seamless data orchestration and synchronization across on-premises and cloud infrastructure, so teams can move faster and operate at hyperscale without sacrificing cost efficiency or productivity.

PeerGFS v6.4 delivers broad performance advancements for real-time file synchronization and scheduled replication for large data sets, including:

  • Greatly improved performance for both scheduled scan and real-time replication for SMB and NFS workloads
  • Enhanced resilience for large file transfer resumption on connectivity breaks across distributed sites
  • Upgraded auditing of configuration and management activity
  • Improved performance, reliability, and manageability of edge data management in distributed and bandwidth-constrained environments.