Archive for June, 2026

Operation Escaneo: Inside a Cyber Campaign Targeting Mexico’s Government and Financial Sector 

Posted in Commentary with tags on June 17, 2026 by itnerd

Mexican government agencies, financial institutions and critical infrastructure are being targeted through a sophisticated intrusion campaign capable of exploiting perimeter devices, stealing credentials and maintaining long-term access inside compromised networks.

CloudSEK researchers have uncovered the attacker’s exposed staging server, providing a rare view into the infrastructure, tools and tactics behind Operation Escaneo.

The investigation revealed:

  • A custom reconnaissance platform called Kimera
  • Exploits targeting Fortinet, Ivanti, Cisco, SAP, Oracle and Windows systems
  • Evidence of more than 1.3 million PII records being extracted
  • Exfiltration of a 407 MB Active Directory dataset
  • Webshells, reverse tunnels and compromised routers used for persistent access
  • CloudSEK’s analysis identifies significant operational and tactical links between the campaign and MexicanMafia, also known as PanchoVilla.
     

The report shows how the campaign progresses from mass reconnaissance and exploitation to lateral movement, credential theft, data exfiltration and long-term persistence—posing a serious risk to public-sector and financial networks across the region.

Full report: https://www.cloudsek.com/blog/operation-escaneo-mexican-government-financial-institutions-cyberattack

As AI use rises, over four in ten consumers question whether messages are genuine says Exclaimer

Posted in Commentary with tags on June 17, 2026 by itnerd

Exclaimer today released new research revealing that UK and US adults are increasingly turning to AI to help them communicate on a daily basis, but the technology’s ability to create polished, professional content at scale is also making them more skeptical of the messages arriving in their inboxes and apps. 

The survey of 2,000 UK and US adults found that while over half (58%) now use AI in their daily communications, 41% have questioned whether a message they received was genuine or legitimate.  

The complexity of digital communication is being compounded by the sheer number of platforms people use. The average UK and US adult now juggles at least six communication channels each day, as messaging apps, workplace platforms, social media and email compete for attention and reshape how important information is shared. 

More than one in five (22%) have missed important information because it was sent on a platform they rarely check, while the same proportion have struggled to find an important message because it was sent on what they considered the ‘wrong’ platform for that type of information. A further 18% have lost an important message because a communication platform deleted it, an account was closed or they changed devices. 

Against this backdrop, consumers are becoming more deliberate about where important information is shared. Email emerged as the preferred channel for communications that matter, with over half (56%) of UK and US adults choosing it when they need to keep or refer back to information. More than a third (39%) have deliberately chosen email over another platform to create a permanent record, suggesting consumers increasingly value channels that provide a clear, accessible trail of important communications.  

The medium shapes the message 

The research suggests that where a message is sent is increasingly shaping how it is received. Nearly half of UK and US adults (48%) say the platform used affects how trustworthy a message feels, while 46% believe it influences professionalism and 37% say it impacts how seriously the recipient takes it. 

The findings also suggest the medium doesn’t simply shape the message; it can determine whether it is seen at all. Younger consumers are significantly more likely to miss important information because it was sent on a platform they rarely check, with 33% of 18-24-year-olds reporting this, compared to just 15% of those aged 55 and over. Older consumers, meanwhile, are far more likely to keep important messages for future reference, with 62% of those aged 65 and over saying they have done so, compared to 35% of 18-24-year-olds.  

The end of email? Absolutely not 

New platforms may have changed how people chat, share quick updates and make social plans, but when something has long-term value or consequences, many still turn to email. It remains the preferred channel for making formal complaints to a company (cited by 51% of UK and US adults), receiving important updates like benefits or HR updates from an employer (47%), applying for or discussing a job opportunity (32%), and receiving healthcare information or results (29%).  

That reliance on email for important information is placing a greater emphasis on trust. With phishing still the most common cyber threat facing UK and US businesses, and AI making fake messages harder to spot, consumers are looking for clear signs that an email is trustworthy. And older generations are the most sceptical: over half (53%) of those aged 65 and over say they have questioned whether a message was genuine or legitimate, compared to 26% of 18–24-year-olds.  

When judging whether an email is genuine, the top three trust signals UK and US adults look for are full contact details (45%), a professional company email address (44%) and a clear sender name (31%). Older consumers are more likely to rely on practical signals, with 53% of those aged 65 and over saying full contact details make an email feel trustworthy, compared to 38% of 18–24-year-olds. Gen Z, meanwhile, is twice as likely as the Silent Generation (28% vs. 14%) to view visual cues like company logos and branding as trust signals. Professional email signatures resonate most with working-age adults, with almost a third (31%) of 25-44-year-olds saying they increase trust.  

AI enters the chat 

The role of AI in everyday communication is expanding from editing words to managing impressions. More than half (58%) of UK and US adults now use AI in some aspect of their communications, most commonly to improve grammar and spelling (21%) or make their writing sound more professional (20%). Others increasingly use it to shape how they come across, with 14% using AI to sound more confident, 12% to soften difficult messages and 9% to avoid awkward conversations altogether. 

AI usage falls sharply with age. Just 30% of those aged 65 and over say they use AI in their daily communications, compared with 79% of 25-34-year-olds and 82% of 18-24-year-olds. Younger consumers are also more likely to use AI to navigate difficult social situations. One in five Gen Z consumers (20%) use AI to soften difficult messages, while a similar proportion (19%) use it to avoid awkward conversations, compared to just 5% and 2% of Baby Boomers respectively. 

You can access Exclaimer’s full When it Matters: How People Really Communicate study here: https://exclaimer.com/blog/how-people-really-communicate/ 

BlueKit’s P2P phishing infrastructure makes detection and takedowns harder says CloudSEK

Posted in Commentary with tags on June 17, 2026 by itnerd

Phishing platforms are no longer stopping at stolen passwords. CloudSEK researchers have uncovered how BlueKit is evolving into a full-scale criminal SaaS platform that can hijack active sessions, enrol attacker-controlled passkeys, change passwords and lock victims out of their accounts almost immediately.

The most significant finding is BlueKit’s migration to a peer-to-peer phishing-page rendering architecture, designed to conceal its backend infrastructure from browser developer tools and conventional network analysis. This makes reverse-IP tracking, infrastructure fingerprinting, automated scanning and traditional IOC-based detection considerably more difficult.

CloudSEK’s investigation also identified:

  • 87 ready-made phishing kits targeting banks, cloud platforms, cryptocurrency exchanges, enterprise services and global consumer brands
  • Automated post-compromise workflows for Google, Microsoft and Amazon accounts
  • Session-cookie theft that can undermine conventional MFA protections
  • A Google Ads workflow capable of adding an attacker as an account administrator
  • Ledger and Trezor templates designed to steal cryptocurrency wallet recovery phrases
  • BlueKit’s complete 29-table database schema, including victim records, operator accounts, reseller infrastructure and cryptocurrency payment data
  • A reseller and white-label model that allows other cybercriminal groups to rebrand and distribute the platform

While BlueKit has been previously documented, CloudSEK’s research provides a deeper view into its evolving architecture, internal database, commercial ecosystem and automated account-takeover capabilities.

Full report: https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas

SentinelOne Opens Purple AI Agentic Investigations to All Customers, Bringing Frontier AI Directly Into the SOC

Posted in Commentary with tags on June 17, 2026 by itnerd

SentinelOne today opened Purple AI Agentic Investigations to its customers and introduced Singularity Creditsa unified currency for running AI-powered work across the Singularity Platform. Starting this week, customers can opt into a complimentary trial of the newest capability from Purple AI, SentinelOne’s autonomous security reasoning for the agentic SOC. That capability — ‘zero-click,’ autonomously initiated investigations — detects, investigates, verifies, and responds to threats without human dependencies. When a threat crosses a defined threshold, Purple AI investigates, renders a verdict, and stops it at machine speed, while analysts keep full visibility and control.

The capability arrives as security teams confront a hard limit, not detection, but investigation capacity. Detections climb with every new tool and every expansion of the attack surface, alerts queue for attention, and verdicts wait on analyst availability, with coverage thinning on nights, weekends, and during surges. Frontier-AI-powered threats are poised to widen that gap further.

Why SOC Teams Are Adopting Purple AI Agentic Investigations

  • Seamlessly integrated — zero configuration, working from day one.

Purple AI is built into the Singularity Platform, not bolted onto it. Agentic Investigations run on telemetry already in the platform — across endpoint, identity, cloud, and third-party security data — inside the automated workflows customers already use. There is nothing to deploy, integrate, or tune, and no data leaves the platform. Activation is a single click.

  • A force multiplier for every analyst.

Purple AI does the investigation work — collecting evidence, correlating telemetry, and building the attack timeline — so analysts start at the verdict instead of the alert. It scales a team’s investigation capacity without scaling headcount, and frees analysts for the judgment, threat hunting, and response decisions that need a human. It is designed as an extension of the analyst: amplifying human defenders, not replacing them.

  • Fully audited — governed autonomy, no black box

Every verdict carries a complete, auditable evidence chain, so analysts can review each AI step and outcome with confidence. Customers set the degree of autonomy through an adjustable human-in-the-loop approach that scales to their confidence and SOC maturity — verdicts can trigger automated, policy-driven responses, or prompt an analyst with recommended actions. Activation is admin-controlled, role-based, and reversible at any time, and consumption guardrails keep usage and downstream cost in the hands of those with the right authority.

  • Built on the most advanced reasoning in security

Purple AI is the reasoning brain and interface for the entire Singularity Platform. It brings human-level reasoning from advanced frontier-AI models to bear through a multi-model approach — combining Anthropic’s Claude, OpenAI’s GPT, and SentinelOne’s proprietary “Ultraviolet” models — to compress investigations that once took hours or days into minutes and seconds. For critical threats, investigations trigger automatically and deliver verdicts that can be acted on autonomously or by an analyst.

The introduction of Singularity Credits

Singularity Credits are a flexible, unified currency customers draw down across AI-powered work in the Singularity Platform, including Purple AI Agentic Investigations. To start, SentinelOne is granting customers a complimentary allotment of Credits to trial the capability.

Delivering on the agentic SOC by amplifying defenders, not replacing them

Agentic Investigations advances SentinelOne’s vision of the agentic SOC: one where frontier-AI reasoning amplifies and scales human defenders rather than sidelining them. Purple AI acts as the brain and interface for the entire platform from simplifying querying, to recommending actions, to autonomously detecting, triaging, and stopping threats. Because it operates natively on AI, endpoint, identity, cloud, and third-party telemetry already in the Singularity Platform, it drives Singularity to be an agentic realization of the integrated security operations center (ISOC) category defined by Gartner.

Availability & access

The Purple AI Agentic Investigations trial is now available in Singularity consoles. New and existing Singularity customers can opt in and begin running agentic investigations immediately. Investigations consume Singularity Credits during the trial, but customers are not charged and no payment method is required. The complimentary trial is currently planned to run through August 15, 2026. After the trial, customers can purchase Singularity Credits through partners, direct billing, and eCommerce.

Arcitecta, GRAU DATA and COMBACK to Showcase End-to-End Data Intelligence and Archive Solution at ISC 2026

Posted in Commentary with tags on June 17, 2026 by itnerd

Arcitecta today announced that it will demonstrate its advanced Mediaflux® research data management platform integrated with GRAU DATA’s Metadata-Hub and XtreemStore, and COMBACK’s BDT ORION enterprise tape infrastructure at ISC 2026, June 22-26, 2026, in Hamburg, Germany, in Booth D39.

Arcitecta, GRAU DATA and COMBACK connect active data management, metadata-driven archive, and enterprise tape infrastructure into a single, scalable architecture. This combined solution helps organizations manage, preserve and extract value from massive datasets across active and archive storage tiers.

Key benefits of the combined Arcitecta, GRAU DATA and COMBACK solution include:
 

  • Manage large-scale datasets across active and archive environments
  • Maintain visibility and accessibility across the data lifecycle
  • Automate policy-driven data movement and retention
  • Reduce long-term storage cost and energy consumption
  • Scale sustainable archive infrastructure for petabyte- and exabyte-scale environments

“Data has become the foundation of AI, research discovery and high-performance computing, yet many organizations struggle to manage and capitalize on the massive volumes of unstructured data they generate and maintain,” said Jason Lohrey, CEO and founder of Arcitecta. “Together with GRAU DATA and COMBACK, we’re helping customers unlock the maximum value of their data through a modern approach that simplifies data management, improves preservation and accessibility, and accelerates insights. We look forward to demonstrating how these capabilities are enabling the next generation of AI and research breakthroughs.”
 

For more information, visit: https://www.arcitecta.com/events/2026/isc/.

To schedule a meeting at ISC 2026, visit: https://www.arcitecta.com/events/2026/isc/#meeting.

Resources

Switzerland extends its lead in the technologies reshaping the global economy 

Posted in Commentary with tags on June 17, 2026 by itnerd

The technologies now driving the global economy, from advanced computing to artificial intelligence and robotics, are built patiently, over decades of sustained investment and deep scientific groundwork. Increasingly that work traces back to a country a fraction of the size of the giants it competes with. 

Switzerland now directs a greater share of its venture capital to deep tech than any other nation, and commits more per head than any country in Europe, placing it among the top three worldwide. The finding anchors the Swiss Deep Tech Report 2026, published today by Deep Tech Nation Switzerland, Founderful, Kickfund, Startupticker.ch, and Dealroom.co, and launched at VivaTech in Paris. 

The report sets out where the next decade of frontier technology will be engineered. The world’s most valuable companies are built on data centers, artificial intelligence and robotic automation, and Switzerland is among the few countries worldwide where that work is researched and commercialized at the frontier. What has changed is that its companies now stay to scale, and the world has taken notice. “For the first time, the companies spinning out of ETH and EPFL are staying, scaling and attracting serious capital,” says Jean-Philippe Fricker, Co-Founder and Chief System Architect of Cerebras Systems. The country’s international standing now matches the strength of its ecosystem. 

Five findings that put Switzerland at the forefront of deep tech innovation

The pipeline is shifting toward the sectors that dominate global capital. AI and machine learning now account for one in four newly founded Swiss deep tech companies, more than double their previous share. Beyond startup creation, Switzerland has the highest density of AI researchers globally, twice that of the UK and the US. Robotics is moving even faster relative to peers: Switzerland has created 3.5 times more venture-backed robotics startups per capita since 2020 than the United States, and 5 times more than the UK. In Future of Compute, 2026 is already a record funding year, and Switzerland boasts 7 times more patents per capita than the European average, driven by its world-leading microelectronics and high-precision sensor industries. 

The world’s most deep-tech-focused venture market. 63% of all Swiss venture capital flows to deep tech, the highest share of any country, ahead of China and the United States and nearly double the share of Germany and the UK, and well ahead of France. 

First in Europe on intensity, top three globally. At $1,470 invested per capita, Switzerland commits more to deep tech per head than any country in Europe. Worldwide, that places it among the top three nations alongside Israel and the United States. 

Funding is accelerating. Swiss deep tech funding has grown roughly fivefold since 2015 to reach a record $2.6B in 2025. 

The strongest growth is still ahead. ETH Zurich and EPFL Lausanne are Europe’s leading universities for new deep tech spinouts. Building on a leading position, the two have extended their lead since 2023, and that cohort is only now reaching the seed-to-Series-A window, the stage at which company value and capital raised compound most sharply. 

Where the opportunity sits 

Foreign investors supply 88% of Swiss deep tech funding at rounds of $100M and above, against 75% across Europe, while domestic capital falls to just 12% at late stage. In a top-ranked ecosystem, late-stage capital remains underweight relative to the quality of the companies being built, leaving clear room for new investors to enter early. 

What happens next 

The seed-to-Series-A cohort now moving through the ecosystem is the largest Switzerland has produced, and it is only now reaching the stage where company value and capital raised compound most sharply. Deep tech funding has already grown roughly fivefold since 2015 to a record $2.6B. The companies are staying, and the funds are arriving on their own. The report sets out, sector by sector, the leaders and the startups most worth watching, and invites the investors who would rather arrive early than late. 

The full report is available for download here: https://deeptechnation.ch/resources/swiss-deep-tech-report-2026  

24 billion records leaked online, including usernames and passwords: billions at risk of account takeover 

Posted in Commentary with tags on June 17, 2026 by itnerd

On June 12th, the Cybernews research team discovered a data leak involving 24 billion records, making it one of the largest leaks ever found. The leak included tens of billions of login credentials from 36 sources, ranging from Telegram channels to combined data collections of previous data breaches. The Cybernews team says the leak is most likely an infostealer log database.

Here are the key findings:

  • The records were stored on a publicly accessible Elasticsearch cluster, a group of interconnected search servers. The total volume of information in the cluster exceeded 8.3 terabytes.
  • The leaked data included login credentials in raw format, with each login detail saved separately, including email addresses, usernames, and passwords in plaintext. Researchers also identified URLs that the leaked credentials are supposed to grant access to.
  • The data was collected from numerous sources, with over 1.7 billion records taken from hacking-oriented Telegram channels.
  • The data is no longer publicly exposed, and so far, Cybernews cannot identify the owner of the leaked credentials. 
  • Cybernews is unable to accurately say how old or new the leaked data is. Based on a February 2026 news article contained in the leak, it appears the data owner regularly updates the cluster with new information.

The leak highlights the danger of infostealing malware, as nearly all exposed records were infostealer logs. Users may accidentally download infostealer malware through pirated software, infected PDFs, or other compromised files. Once infected, the malware may then secretly extract passwords, autofill details, credit card numbers, and even access to crypto wallets, often without the user realizing their device has been compromised.

The Cybernews research team monitors and analyzes various sources for leaked data to help people maintain and improve their online privacy and security.

For more information and screenshots of the leaked database, here’s the full report: https://cybernews.com/security/24-billion-credentials-data-leak

Anthropic’s Claude Fable 5 Pulled From The Market

Posted in Commentary with tags on June 16, 2026 by itnerd

Something that I missed last week is the fact that Anthropic who has had a testy relationship with the government has released Claude Fable has been released and then pulled shortly after release:

The AI lab said in a statement that the federal government told it Friday afternoon that it had become aware of a way of “jailbreaking” Fable 5, bypassing limits that Anthropic had implemented to reduce the risk the model could be misused. When Anthropic first announced Mythos, it released the software to only a select group of government agencies and technology professionals because of its ability to uncover cybersecurity vulnerabilities. 

The government imposed what are known as export controls on the products, which Anthropic said means it had to suspend access to the two models by any foreign national, whether inside or outside of the US. The only way it could do so is by shutting the models down entirely, the company said.

So what is Claude Fable 5. I will let the company itself explain:

Claude Fable 5 is a Mythos-level model built for your most ambitious, long-running projects. Try problems you weren’t able to solve with other models. Claude Fable 5 is thorough, proactive, and tests its own work.

Scary stuff. Chris Nyhuis, CEO of the cybersecurity company Vigilant had this comment including with the fact that Amazon was behind this:

A jailbreak is when someone gets an AI model to step around the safety limits its maker built in. In our work that matters because the same capability that lets a model find and fix a vulnerability in a client’s code is the capability that can hand an attacker a roadmap. It’s dual-use, like most powerful tools

Did a “jailbreak” even happen or did Amazon make it up? 

From my perspective it is not even clear a real jailbreak happened. What was demonstrated was a model being asked to read code and fix the flaws in it. That is not someone breaking the guardrails; that is the exact job we hire these tools to do. By the maker’s own account the vulnerabilities were minor and already findable with other models. We pulled a national defensive asset off the field over a finding that, on the public record, looks more like normal defender work than a weapon.

What are the ramifications from the White House to Wall Street to Main Street?

This was the first time a government pulled a commercial AI model off the market over a cyber capability. That sets a precedent every CISO, cloud provider, and investor now has to price in. When access to your best defensive tool can disappear in ninety minutes by directive, that is a board-level risk, not just an engineering one.

Has the White House overstepped and weakened cybersecurity nationally? 

The cybersecurity defender’s argument is straightforward. America’s adversaries are not waiting for an export license. If we slow the people defending American networks while the attackers keep moving, we have made the gap worse, not better. The honest version is that this is a genuinely hard tradeoff, and reasonable people in my field disagree on where the line sits.

How do we know what to trust from AI and if cybersecurity can protect us from hackers jailbreaking? 

Tools come and go, but the harder problem is the people. In the cyber world we hand a small number of people the keys to everything: the networks, the source code, the detection systems. As a nation we have to be far better at making sure the people in those seats are vetted, trusted, and genuinely on our side. That is not about where someone was born. It is about whether we have done the work to earn confidence that the person holding the keys is aligned with the mission. Right now we lean too hard on the technology and not nearly hard enough on the trust model around the people who run it.

Salesforce Acquires Fin

Posted in Commentary with tags on June 16, 2026 by itnerd

Something that I missed in my coverage yesterday is that Salesforce has acquired Fin. Here’s the details:

Fin’s core offering, its AI Agent, resolves complex customer queries end-to-end, across every channel, including live chat, email, WhatsApp, SMS, phone, and Slack. The AI Agent is powered by the company’s proprietary AI model, Apex, that is purpose-built for customer support and has demonstrated industry-leading resolution rates that outperform top commercially available frontier models.

 Anoop Dawar, Chief Strategy Officer (CSO) of Deepgram had this to say:

“This isn’t a one-off. In a single month we’ve seen Fin acquired, SpaceX pay $60 billion for Cursor, and OpenAI stand up a $10 billion deployment company – three very different bets on the same scarce thing: teams that can make AI agents work reliably in the real world, not just in a demo. That capability has quietly become the most valuable asset in software, because these are probabilistic systems that drift and have to be measured and monitored continuously to stay accurate. And it gets hardest in voice – real-time, unforgiving, no second take – which is exactly where the next phase of this race will be won.”

The deal is scheduled to close during Salesforce’s fiscal year 2027 and Salesforce will not impact Salesforce’s capital return program.

CloudBees Names Moritz Plassnig Chief Executive Officer

Posted in Commentary with tags on June 16, 2026 by itnerd

CloudBees today announced that Moritz Plassnig has been appointed Chief Executive Officer, effective immediately. Plassnig succeeds Anuj Kapur, who led the company through a defining chapter of operational transformation, bringing CloudBees to profitability and revenue growth, while serving global enterprise customers including Adobe, Bosch, Visa, Salesforce, and more.

Plassnig, founder of Codeship, the continuous integration and delivery platform acquired by CloudBees in 2018, returns with a rare combination: deep enterprise product instincts and a track record of building tools developers love. Most recently, Moritz served as Chief Product Officer at Immuta, a data security and governance platform, where he oversaw product, engineering and customer success. He will also join the CloudBees Board of Directors.

Plassnig assumes leadership at a pivotal moment for the software industry as AI is writing an increasing share of enterprise code. The enterprises CloudBees serves, including software and technology companies, financial institutions, governments, and critical infrastructure providers, want to embrace this shift. With agents now committing, testing, and deploying code autonomously, the bottleneck has shifted from generating code to governing what ultimately reaches production environments. 

Under Plassnig, CloudBees is moving immediately to be an AI-first company in the products it builds and ships, and in how it runs the business itself, with AI agents already embedded across CloudBees’ own engineering, marketing, and customer operations. The company’s open and flexible governance layer gives CIOs, CISOs, and platform leaders one place to set policy, manage risk, and maintain control over how software is built, secured, and released across every tool in their stack, not only CloudBees’ own. Every change, human or AI, becomes visible, auditable, and accountable, and the Global 2000 can adopt AI-driven development securely without replacing the tools and workflows their teams already rely on. Plassnig is already engaging with customers, and this will continue to be his priority in the coming weeks.