Archive for July 6, 2026

Toronto’s Little Portugal Has the Perfect Spot for Fans to Immerse Themself in Every Footy Moment, Courtesy of LG

Posted in Commentary with tags on July 6, 2026 by itnerd

With the Portugal vs. Spain game taking place today, football fans in Little Portugal are eagerly in one place — Amigos da Dundas, a local community footy hub highlighted in the latest episode of LG Canada’s Match Day Heroes video series. The series celebrates four local footy hubs creating unforgettable match day memories for Canadian fans this summer, with LG technology upgrades to make each moment even better.

Tucked into the heart of Toronto’s Little Portugal neighbourhood at 1570 Dundas St. W., Amigos da Dundas has long been the go-to gathering spot for Portuguese football fans – a natural fit to be one of LG’s Match Day Heroes.

LG is inviting fans to visit LG Canada’s Sponsorship page on LG.ca to nominate their own favourite local footy hub to win the ultimate LG Match Day upgrade, valued at up to $10,000

·      Eligible nominations include neighbourhood sports bars, cafés, restaurants, community gathering spaces or even a backyard where fans come together to watch and celebrate the game.

  • As long as the footy hub consents to participating, submit at least 2 photos (up to a max of 6) showing off what makes your hub unique – think match day traditions, screens, seating, decorations, rituals and the crew you watch the game with.

You can watch the full Amigos da Dundas video, as well as other local Toronto footy hubs highlighted in the Match Day Heroes video series, here.

Guest Post – Under Pressure: Insights from the 2026 Exposure Gap Report

Posted in Commentary with tags on July 6, 2026 by itnerd

Risk is concentrating. The 2026 Exposure Gap Report shows vulnerabilities claiming a larger share of critical exposure, and that shift has real implications for how security teams prioritize their response.

Two findings are central to this change. Vulnerabilities now represent a much larger share of critical exposure, and only a small percentage of vulnerability alerts are validated as exploitable. Together, these findings show why prioritization depends on context, validation, and a clear understanding of which exposures require action.

Exposure Is Shifting Toward Vulnerabilities

Vulnerabilities now account for 42.6% of critical exposure, up from 18.7% in 2025. This increase shows that weaknesses across systems and applications are playing a larger role in how critical exposure develops across connected environments.

A higher volume of vulnerability findings does not mean a higher volume of real risk. Security teams need to know which exposures matter in their specific environment so they can focus remediation where it counts.

Only a Small Portion Is Exploitable

Only 7.8% of vulnerability alerts are validated as exploitable and classified as Critical or High. This finding shows that the actionable portion of vulnerability exposure is much smaller than the full alert volume suggests.

A vulnerability becomes Critical or High when exploitability is viewed alongside context. The affected assets, business criticality, existing security controls, and evidence of active exploitation by threat actors all shape the level of risk. Looking at these factors together gives security teams a more accurate view of which exposures require immediate attention.

Exploitability validation helps teams narrow large volumes of findings into a focused set of priorities. When teams know which exposures can be used in practice, they can make faster decisions, plan remediation more effectively, and reduce the operational noise that slows response.

Having trouble determining which exposures can be used in an attack? Get a free Agentic Exposure Validation (AEV) scan to identify actionable exposure and filter out findings that already have security protections in place.

The Structure Beneath the Volume

The report points to a clear gap between what is detected and what requires action. Vulnerability findings may appear broad at scale, yet the validated risk pool is much smaller than the overall dataset.

This distinction shapes how teams operate. When workflows are guided by validated exposure, teams can move with greater focus and avoid spending time on findings that do not change risk in practice.

Closing the Exposure Gap

Closing the exposure gap starts with better filtering and more consistent validation. Security teams need to understand which exposures are present, which can be exploited, and which should be addressed first.

Teams that make these distinctions clearly can respond faster and prioritize with more confidence. As vulnerability driven exposure continues to rise, progress depends on moving from broad detection to focused action.

The 2026 Exposure Gap Report covers exposure composition by industry, remediation benchmarks, and what separates teams closing critical exposures in under an hour from those still working through the backlog.

You can download it here

AI-Powered “JadePuffer” Ransomware POC Is On The Streets

Posted in Commentary with tags on July 6, 2026 by itnerd

Researchers have demonstrated an AI-powered ransomware framework known as “JadePuffer” that automates multiple stages of the attack lifecycle, including target identification, database interaction, encryption, and ransom execution. While the project is intended as a proof of concept rather than evidence of an active ransomware campaign, it illustrates how AI could significantly reduce the time, expertise, and resources required to conduct cyberattacks. The research highlights growing concerns that AI may enable attackers to automate operational workflows, accelerating the speed and scale of future ransomware and cybercrime operations.

If you want an overview of “JadePuffer”, click here: JadePuffer: The First Successful LLM-Driven Ransomware Attack

John Watters, Chairman and CEO, iCOUNTER Cybersecurity Intelligence had this to say:

“The most important takeaway from stories like this is not whether a specific AI-powered ransomware framework achieves widespread adoption, but what it signals about the direction of cybercrime operations. Threat actors have spent years automating individual stages of the attack lifecycle. AI has the potential to connect those stages together, accelerating reconnaissance, target selection, and execution in ways that compress attacker timelines significantly.

As cybercriminal operations become more automated, defenders face a growing mismatch between machine-speed attacks and human-speed decision-making. Security teams can no longer rely solely on detecting malicious activity once it reaches their environment. They need operational intelligence that provides visibility into emerging adversary behaviors, infrastructure, and campaign activity before attacks reach execution.

This is ultimately an intelligence challenge as much as a security challenge. Organizations that can identify shifts in attacker tradecraft early and adapt their defensive priorities accordingly will be far better positioned than those waiting to respond after automation has already increased the scale and speed of an adversary’s operations.”

Consider this to be fair warning that AI is going to be used in all sorts of attacks, and ransomware will be no different. Thus this should be all you need to get your defences in order.

UPDATE: Ensar Seker, CISO at SOCRadarhas provided the following commentary:

“JADEPUFFER demonstrates that the most important change isn’t that AI created new attack techniques, it didn’t. The campaign relied on a known vulnerability and familiar post-exploitation methods. What changed is that an AI agent was able to autonomously chain reconnaissance, exploitation, credential discovery, lateral movement, and extortion while adapting to failures in real time. That dramatically lowers the operational cost of ransomware campaigns and allows attackers to execute far more operations simultaneously than a human team could manage.

The ability to analyze an error, modify its own approach, and continue the attack within seconds is particularly concerning. Security teams should expect future ransomware operators to use AI not because it makes attacks more sophisticated, but because it makes them faster, more scalable, and far more persistent.

Organizations shouldn’t focus solely on the ‘AI ransomware’ headline. This incident began with an exposed Langflow instance vulnerable to a publicly known CVE. The defensive priorities remain the same: aggressively patch internet-facing AI infrastructure, eliminate exposed administrative services, enforce least privilege, protect secrets stored within AI frameworks, and continuously monitor for abnormal behavior. AI is accelerating attackers, but it is still exploiting fundamental security weaknesses.”

UPDATE x2: More commentary was provided to me in relation to this story:

Justin Beals, CEO & Founder of Strike Graph:

“JadePuffer is the moment the industry has been warning about since agentic tooling showed up: an AI model that can chain reconnaissance, credential theft, lateral movement, and extortion without a human touching any single step. None of the techniques are new. What’s new is that a model strung them together end to end, in 31 seconds from failed login to working exploit.

That speed is the real story. Traditional third-party risk programs run on quarterly questionnaires and point-in-time attestations, but an autonomous attacker doesn’t wait for your next audit cycle. If your vendor risk posture is a snapshot, and the threat is continuous, you’ve already lost the race before the assessment period even starts.

Organizations need to stop treating AI agents as productivity tools and start treating them as identities with access that has to be governed, monitored, and continuously verified, not reviewed once and forgotten. The ones who build that muscle now will be the ones still standing when this pattern scales, and Sysdig is telling us it will.”

Andrew Obadiaru, CISO at Cobalt:

“What stands out about JadePuffer isn’t that an AI-generated malicious code. It’s that a model was able to string together reconnaissance, credential theft, lateral movement, and destruction into a working operation without a human directing any single step. That removes one of the last practical constraints on attacker scale: the need for an operator with deep expertise at each stage of an intrusion. We’ve spent years talking about AI lowering the barrier to entry for attackers. This is what that actually looks like in practice: adaptive, self-correcting, and fast enough to move from a failed login to a working exploit in under a minute. For defenders, the lesson isn’t really about Langflow specifically, though patching exposed AI orchestration tools matters. It’s that periodic testing cycles were never built for adversaries that iterate in real time. Continuous validation of Internet-facing infrastructure, and tighter controls around what credentials and API keys sit next to AI orchestration environments matter more now than they did a year ago. Attackers no longer need to be sophisticated. They just need a model willing to keep trying until something works.”

Will Baxter, Field CISO at Team Cymru:

“Whether or not JadePuffer represents the first fully LLM-directed ransomware operation, it reflects a broader trend toward AI orchestrating larger portions of the intrusion lifecycle. We’ve already seen AI accelerate individual stages of an attack; if it’s now coordinating workflows end-to-end, defenders should expect faster adaptation and shorter response windows. That doesn’t eliminate the value of indicators or signatures, but it does increase the importance of tracking the infrastructure and behavioral patterns that persist even as tooling changes. Organizations that can observe attacker infrastructure as it evolves, not just the artifacts of a single campaign, will be better positioned to detect and disrupt these operations before they progress from initial access to impact.”

FortiBleed Unmasked: A Joint Operation by Lynx and INC Ransomware Groups 

Posted in Commentary with tags on July 6, 2026 by itnerd

After announcing last week that SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Operations, today the SOCRadar Threat Research Unit (STRU) published its complete report that reveals exactly how INC and Lynx used a measurable, tracked spend on AI credits, an entire swarm of autonomous agents pointed at one target with a deliberate model-selection strategy (cheap model for high-volume scanning, a frontier model reserved for deep code review), and active jailbreak research to defeat model safety controls.

Today’s complete report also puts an identity and a profile behind the coordinating operator and lays out the full internal hierarchy by role.  

Key points:

  • Attribution: STRU assesses with high confidence that FortiBleed is a joint operation run by affiliates of the Lynx and INC ransomware groups.
  • How they know: an OPSEC failure exposed the group’s own artifacts, including a single Windows workstation used to access both ransomware panels and negotiate ransoms. A second exposed INC directory shared victims with FortiBleed target lists, and Lynx is widely believed to be an evolved variant of INC.
  • The operator: an actor we track as TOXMAN (also TOXFOX, and Greenprawn100 on the Exploit[.]in forum), with Russian-language tooling and activity in the UTC +3 time zone.
  • Organized like a business: an internal tracking file mapped 20+ affiliates in defined roles, backed by 450+ operational servers.
  • Scale: roughly 11,250 FortiGate portals scanned across 150+ countries, leading to 409 administrative accesses and 12 organizations encrypted for ransom.
  • Heavy AI investment: about $4,554 spent on AI model credits, including 14 autonomous AI agents pointed at a single target, jailbreak use to bypass model safety controls, and a likely zero-day now in responsible disclosure.
  • Quiet by design: default admin credentials and a VPN-to-management pivot turn one firewall login into full domain compromise, and because the logins are real they rarely trip a perimeter alarm.
  • Who is targeted: opportunistic, small-to-mid-market firms, with managed service providers and manufacturers prized for lateral access into their customers.

For full details, please see the new report: FortiBleed Unmasked: A Joint Operation by Lynx and INC Ransomware Group. A pdf of the report can be found here.  

Hammerspace to Showcase How Enterprises Can Dramatically Improve AI Infrastructure Efficiency at RAISE Summit 2026

Posted in Commentary with tags on July 6, 2026 by itnerd

Hammerspace today announced its senior executive team will participate in RAISE Summit 2026, taking place July 8–9 at the Carrousel du Louvre in Paris. At Booth 3B, Hammerspace will demonstrate how enterprises can win the AI infrastructure race before the first token by eliminating one of AI’s largest hidden constraints: data readiness.

As enterprise inference and RAG deployments accelerate, AI economics are not defined by GPU counts or storage performance alone. AI outcomes depend on how quickly environments become productive, how rapidly workloads gain access to the right data, and how efficiently infrastructure keeps GPUs generating useful output.

The Hammerspace Data Platform addresses these challenges by unifying the data estate on existing storage and automating data orchestration to make data available where GPUs need it without large-scale data migration or new storage procurement.

At RAISE Summit, attendees will learn how Hammerspace improves three metrics that determine AI success:

  • Time to Very First Token: Reducing the time required to make enterprise data AI-ready so projects can begin in days instead of months.
  • Time to First Token: Orchestrating and pre-positioning data so AI workloads can begin generating results faster.
  • Time per Token: Continuously supplying GPUs with the right data to improve utilization and lower the effective cost of AI operations.

Traditional AI deployment models often treat AI readiness as an infrastructure project, requiring organizations to acquire new storage, build new environments and migrate data before productive work can begin. Hammerspace’s Data Platform instead treats AI readiness as a data availability challenge, enabling organizations to use data in place across existing storage systems and cloud environments while creating a unified global namespace for AI workloads.

By continuously discovering, orchestrating and positioning data where AI workloads need it, Hammerspace reduces idle GPU cycles, minimizes unnecessary data movement and helps organizations improve productive GPU utilization while lowering cost per token.

Hammerspace’s Data Platform enables organizations to:

  • Activate enterprise data in place across existing storage systems and cloud environments
  • Eliminate storage procurement and migration delays that traditionally postpone AI initiatives
  • Unify distributed data through a global namespace without creating additional silos
  • Pre-position data before workloads require it, reducing time to first token
  • Continuously orchestrate active data throughout AI pipelines to maximize GPU productivity

Organizations using traditional storage-first AI data approaches may spend between 14 and 30 weeks acquiring infrastructure and migrating data before productive AI work begins. Hammerspace can reduce that timeline to as little as a few days to one week, representing acceleration of up to 70x.

Executive Speakers at RAISE Summit

David Flynn will present on the Main Stage on July 8, sharing how organizations can rethink AI infrastructure around the economics that matter most: speed to token generation, continuous GPU productivity and cost-efficient AI operations.

Molly Presley, Hammerspace SVP of Global Marketing, will present on July 9 on the Grace Hopper Stage in a session titled “The Data Problem: What AI Actually Runs On,” examining why data readiness, not infrastructure procurement, has become the defining challenge for enterprise AI.

For more information about Hammerspace at RAISE Summit 2026, visit:
https://hammerspace.com/event/raise-summit-2026/
 

Learn More: