Archive for July 14, 2026

Department Of War just suspended CMMC Phase II

Posted in Commentary with tags on July 14, 2026 by itnerd

The Department of War’s suspension of CMMC Phase II is being covered as a compliance win for small and mid-size defense contractors, and in terms of bureaucratic burden, it is. But the third-party verification that Phase II provided doesn’t disappear without consequence; the DFARS clauses creating personal liability for affirming officials are still fully in force.

More details are here: Pentagon announces ‘immediate suspension’ of CMMC Phase II mandates – Breaking Defense

Justin Beals, CEO & Founder, Strike Graph, an AI-native GRC and compliance automation platform

“This isn’t a security stand-down. It’s a stand-down on who checks your homework. Phase I self-assessment stays in place, but the third-party verification that would catch a bad self-assessment doesn’t.

That matters because DFARS 252.204-7012 and 252.204-7021 didn’t go anywhere. Affirming officials are still personally exposed under the False Claims Act for a compliance claim nobody independently verified, the exact gap that produced the $4.6 million MORSECORP settlement.

Companies that treat this suspension as permission to stop building evidence will be the ones exposed when the Reform Task Force’s review lands in 60 days, or when an incident forces the question first. Self-attestation was never the finish line. It was always a claim waiting to be tested.”

This will be a #fail. I am calling it now as we need more cybersecurity not less. But I guess that the find out moment will come when people and organizations get pwned.

Grok Build’s silent repo uploads highlight growing risks in AI coding tools

Posted in Commentary with tags on July 14, 2026 by itnerd

The Grok Build leak (check this link out to catch up: Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read) highlights a difficult reality in AI security: a coding agent marketed as private can still quietly ship your entire codebase out the door. Researchers found that xAI’s Grok Build CLI uploaded entire git repositories, full commit history and untouched files included, to a Google Cloud Storage bucket xAI controlled, no exploit required, no unusual configuration, just a normal coding session that carried .env secrets and SSH keys out along with it.

Yusif Mukhtarov, Lead Data Scientist, Polygraf AI had this to say:

“To be very honest, Grok 4.5 seems to have solved one of the biggest barriers that previously limited its practical use: API cost. As an ML engineer, I personally found earlier versions too expensive to integrate into daily workflows and use consistently at scale. With Grok 4.5, that balance has changed. The model is capable, fast, and affordable enough to become part of real engineering operations. It is obvious that an enormous amount of effort went into building it, and considering the combination of its price and capabilities, I personally believe it is revolutionary to a certain degree. That is why this incident is particularly surprising and concerning. In my opinion, it exposes a major blind spot in how we currently evaluate agentic systems. We celebrate improvements in coding accuracy, task completion, cost, and latency, but these scores tell us very little about whether the surrounding product follows the principle of least privilege, exports only the context required for the task, or creates additional data flows that remain invisible to the user. A model can solve a task perfectly while the system built around it still collects far more information than the task requires. In this case, even auditing the model’s visible actions may not have been enough, because the reported repository upload occurred through a separate storage mechanism. This case also shows that evaluating only the model’s observable behavior is not enough, because critical data flows may be handled by the surrounding application infrastructure rather than by the model itself.

The problem is therefore deeper than the behavior of one model or one company. Whenever sensitive information is sent to an external provider, we are not only trusting that provider to act fairly and follow its privacy commitments. We are also trusting that every part of its infrastructure, software, storage configuration, access control, and internal process will continue to work correctly. Even a responsible company can suffer from a bug, a configuration mistake, an internal incident, or a security breach. Courts and regulators may later hold the responsible party accountable and compensate the victim, but they cannot reverse the disclosure or fully repair the damage once sensitive information has escaped. Personally, I see the solution as reducing the consequences of failure rather than assuming failure can always be prevented. Sensitive entities should be detected locally and replaced with neutral terms such as person, organization, location, or account before the data reaches any external model or agent. This does not make third party systems infallible. It makes their failures significantly less damaging because the original sensitive information was never available to leak in the first place. This is exactly the privacy approach we are developing at Polygraf AI.”

AI isn’t the magic bullet that you think it is. And anything controlled by Elon Musk must be treated as doubly suspect by default if AI is treated as suspect by default. Because anything AI can’t be completely trusted.

FusionAuth Launches Intelligent MFA in Latest Release as Demand Surges for Identity Infrastructure Customers Can Control

Posted in Commentary with tags on July 14, 2026 by itnerd

FusionAuth today announced the release of FusionAuth 1.68, introducing  Intelligent MFA, a risk-based authentication engine that evaluates every login against 10 configurable signals and challenges users only when risk is detected.

The launch comes as FusionAuth enters its new fiscal year with the strongest commercial momentum in company history. In the most recent quarter ending April 30, 2026, FusionAuth saw bookings double quarter over quarter, underscoring growing demand for identity infrastructure that gives organizations greater control over deployment, data, risk, and cost.

Intelligent MFA Without the Black Box

Unlike many risk-based MFA offerings that rely on opaque risk scoring inside a shared multi-tenant cloud infrastructure, FusionAuth Intelligent MFA is deterministic, rules-based, and designed to run inside the deployment model the customer chooses, including customer-hosted environments, dedicated FusionAuth Cloud deployments, on-premises infrastructure, and hybrid architectures. The result is adaptive authentication that doesn’t force organizations to trade away visibility, auditability, or infrastructure control.

FusionAuth Intelligent MFA evaluates login risk using 10 signals, including unrecognized device, untrusted device, blocklisted IP address, dormant account, recent password change, and impossible travel. Each login is assigned a low, medium, or high risk score. High-risk sessions trigger an MFA challenge, while trusted sessions can continue without unnecessary friction.

For security and compliance teams, the key difference is transparency. The signal names are visible, the scoring logic is rules-based, and the composite risk score is logged. That means teams can explain why a login was challenged, document policy enforcement, and reproduce decisions when needed.

Built for Customer-Controlled Identity Infrastructure

FusionAuth’s approach is especially relevant for regulated and security-sensitive organizations that cannot rely on shared-cloud assumptions for critical identity decisions. The company’s 2026 State of AI and Identity Report found that organizations using shared multi-tenant identity infrastructure reported confirmed security incidents at more than twice the rate of organizations using self-hosted or isolated deployments. The report also found that two-thirds of respondents experienced an AI identity-related security incident in the past year.

As AI agents, APIs, machines, partners, employees, and customers all require secure access to digital systems, identity is rapidly becoming the control plane for modern applications.

Commercial Momentum Reflects Market Shift Towards Control

FusionAuth’s momentum reflects that shift, demonstrating increased demand from both new and existing customers.

Intelligent MFA is available today in FusionAuth 1.68. FusionAuth can be deployed in FusionAuth’s cloud, an organization’s own environment, on-premises, or anywhere in between.

The Check Point AI Security Report 2026 Is Out

Posted in Commentary with tags on July 14, 2026 by itnerd

For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that goes further. AI has crossed from assistant to operator. Where it once helped attackers prepare, it now runs the operation.

Key observed findings

  • AI has crossed from development aid to live attack operator. It now does the hands-on work inside live intrusions, from China-nexus espionage campaigns to a criminal breach of multiple Mexican government agencies and has spread from nation states to ordinary cyber criminals.
  • AI now builds deployment-ready malware and attack suites. Its involvement is often invisible in the finished artifact: one developer used an AI environment to produce VoidLink, an 88,000-line command-and-control offensive framework, in under a week.
  • Attackers prefer commercial models, and now abuse them by exploiting the agentic architecture, not just single prompts. Most actors favor jailbroken mainstream models over self-hosted ones, and the durable bypass is now a planted configuration file an agent loads and trusts across sessions.
  • An AI-enabled criminal tooling market has matured. Phishing-as-a-service kits now embed a language model with the jailbreak built in, and conversational AI voice-agent services run vishing and one-time-passcode theft at scale.
  • Virtual Identity is no longer a reliable trust anchor. Voice, face, documents, and live video are now cheap to forge convincingly and are widely used in attacks taking multi-channel social engineering to a new level of integration.
  • AI itself is an expanding attack surface. Models cannot always separate data from instructions and content they process might influence the model’s behavior; the surrounding stack adds ordinary software vulnerabilities and supply-chain risk, all in a rapidly evolving ecosystem where security practices not always mature.
  • Indirect prompt injection is on the rise. Detections of longer malicious payloads increased sharply, rising roughly fivefold between March and May 2026 and approaching 1% of observed prompts in May. Longer payloads are more typical of content-borne and agentic attack paths, this pattern suggests that indirect prompt injection is becoming more operationally relevant.
  • Enterprise data leakage through GenAI is persistent and growing risk. High-risk prompts doubled from 2% to 4% during the last year, while organizations used an average of 10 AI applications each month, many without official approval.
  • Data exposure risks are not evenly distributed across the verticals. Sector-level analysis reveals that AI-related data exposure risks are not evenly distributed across the verticals, and correlate both with AI usage patterns and security maturity. Business Services recorded the highest rate of high-risk GenAI prompts at 5.91%, meaning nearly one in every 17 AI interactions carried a significant risk of sensitive data exposure.

To read the full findings, access the AI Security Report 2026 from Check Point Research here. 

A fake click was all it took to read your Gmail

Posted in Commentary with tags on July 14, 2026 by itnerd

An unpatched flaw in Claude for Chrome allows malicious browser extensions to trigger the agent using forged click signals, since it never verifies whether a click originated from a real user. Extensions exploiting it can silently pull Gmail, Google Docs, and calendar data, and Anthropic has shipped eight patches since the bug was reported in May without fixing it.

Security Week has details here: Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar – SecurityWeek

Gidi Cohen, CEO & Co-Founder, Bonfy.AI had this to say:

“Eight patches since May and this still isn’t fixed, which tells you something more interesting than the bug itself. Anthropic’s response was to lock Claude down to a fixed list of approved tasks. That’s a reasonable instinct, but it treats the symptom. The actual problem is that Claude has no way to verify that a click came from a person rather than a script pretending to be one. You can narrow what an agent is allowed to do all you want, and none of it matters if you can’t confirm who’s actually asking it to do that thing in the first place.

We’re going to keep seeing this exact pattern as browser-native AI agents roll out across the world this year. Every vendor is racing to ship autonomy features, ‘act without asking’ toggles, agents that read your calendar and draft your replies for you, and almost none of them have solved the much less exciting problem sitting underneath all of it, which is proving intent. Consent in a browser was built around the idea that a person physically clicked something. The moment an extension can fake that signal, the entire permission model built on top of it ceases to mean anything. That’s not a Claude-specific bug. That’s every AI agent shipping into a browser right now, and the industry is going to spend the next few months figuring that out in public, one disclosure at a time.”

You have to assume that AI is a #fail. Thus you need to do you own homework to make sure any AI anything is safe to use. Otherwise you are part of the problem.

Leaseweb Becomes New VMware Cloud Service Provider Pinnacle Tier Partner in the Broadcom Advantage Partner Program

Posted in Commentary with tags on July 14, 2026 by itnerd

Leaseweb today announced the company is now a VMware Cloud Service Provider (VCSP) Pinnacle tier partner in the Broadcom Advantage Partner Program in the United States, European Economic Area, and Singapore. Leaseweb will help mutual enterprise customers to innovate by adopting VMware Cloud Foundation (VCF) as their private cloud infrastructure. Leaseweb will offer VMware Cloud Foundation as new managed private or sovereign cloud services, supporting data residency and other jurisdictional controls. 

VMware Cloud Foundation (VCF) is the platform for the modern private cloud, supporting both virtual machine (VM) and container-based applications on a single unified infrastructure with consistent operations, governance, and controls. With VCF, customers are empowered with a consistent cloud operating model spanning data centers, edge, and managed cloud infrastructure from VCSP partners. VCF combines the agility and scalability of public cloud with the security, performance, architectural control, and total cost of ownership (TCO) benefits of an on-premises environment.

Pinnacle is the highest program level in the Broadcom Advantage Partner program. Pinnacle partners are Broadcom’s most invested and strategic partners, boasting extensive certifications, a track record of significant sales and service achievements, and broad international coverage. Holding Pinnacle status signifies a partner’s deep technological know-how and proficiency in addressing the most intricate customer issues.

After $3.6B (€3.1B) Valuation, Oxylabs Predicts Europe Shifting to Finally Unlock Its AI Potential

Posted in Commentary with tags on July 14, 2026 by itnerd

Oxylabs, now the world’s highest-valued web data infrastructure platform, received a $130M (€113.6M) investment from private equity firm Warburg Pincus, valuing the company at $3.6B (€3.1B). The Lithuania-founded company predicts that this investment will further encourage the European Union to use its competitive potential in AI and data infrastructure. 

The European Union has been criticized for rushed, inefficient regulation, as it lags behind other global markets in AI development. 

Oxylabs is also a player in mergers and acquisitions in Europe and globally, having acquired Silicon Valley’s Webshare Software Company in 2022 and the French company ScrapingBee in 2025.

Agentic AI is seen as a crucial area of innovation where Europe can still successfully compete as it shifts its digital regulation strategy.

Read more: https://oxylabs.io/blog/oxylabs-receives-investment

Fig Financial Surpasses $500 Million Lent as It Expands Its Financial Services Platform

Posted in Commentary with tags on July 14, 2026 by itnerd

Fig Financial backed by Ontario Teachers’ Pension Plan and Fairstone Bank, today announced it has officially lent more than $500 million to Canadians, marking a major milestone in the company’s growth and reflecting the trust Canadians have placed in its approach to borrowing.

Since launching in 2023, Fig has received more than 1.2 million loan applications from Canadians and earned more than 1,200 Trustpilot reviews with an average rating of 4.8 out of 5, reflecting growing demand for transparent financial products with clear terms, structured repayment, and a customer-first experience.

From the beginning, Fig has been committed to meeting Canadians where they are. Looking ahead, the company is deepening its investment in financial education, partnerships, and new financial products that help Canadians borrow, spend, save, and build with confidence.

Talking Finance With FinTalk

As part of this next chapter, Fig is officially launching FinTalk, its podcast dedicated to making money conversations simpler for Canadians.

Hosted by Chief Revenue Officer Monisha Sharma, FinTalk brings together Fig leaders and respected voices from across the financial industry for practical conversations about the financial topics Canadians care about most, including: 

Listen to FinTalk episodes on Spotify, YouTube, Apple and Amazon

Celebrating Financial Fitness

To celebrate the milestone, Fig has partnered with GoodLife Fitness to encourage Canadians to invest in both their financial and physical wellbeing.

The campaign reflects Fig’s belief that building healthy financial habits, much like building physical ones, takes consistency, support, and the right tools.

The contest is open until August 31, 2026. One grand prize winner will receive $7,500 CAD in cash, and two additional winners will each receive a one-year GoodLife Fitness membership (valued at $1,175 CAD) and $75 CAD in cash. Winners will be drawn on September 4, 2026.

Full contest details and official rules are available at https://fig.ca/documents/Gym_2026_EN.pdf.

To learn more about Fig Financial, visit https://fig.ca.

Polygraf Launches Meeting Guard

Posted in Commentary with tags on July 14, 2026 by itnerd

Polygraf AI today announced Meeting Guard, a real-time AI fraud detection solution for enterprise meetings designed to address a growing reality facing organizations: your meetings are no longer secure.

AI can now clone a voice, animate a face, and answer every interview question in real-time, making traditional trust signals obsolete across hiring processes, executive meetings, vendor calls, and enterprise collaboration. Organizations are increasingly facing AI hiring fraud, deepfake executive impersonation, live PII exposure, and nation-state infiltration attempts that exploit the trust built into video meetings.

Polygraf AI’s Meeting Guard joins virtual meetings as a visible participant and delivers near-real-time security analysis to every attendee. Built for enterprise and government environments, Meeting Guard serves as both a secure compliance assistant and an AI notetaker, detecting AI-generated content, verifying voices against deepfake threats, flagging potential PII leaks, and securely generating meeting notes and summaries without transmitting external data. Organizations benefit from custom security rules, organization-wide dashboards, automated compliance reporting, searchable transcripts, participant analysis, threat summaries, and inline threat highlighting across every meeting.

Meeting Guard requires no integrations and, unlike traditional fraud-prevention or video-verification tools, is active only during the meeting. For customers who choose local deployment, no meeting data is sent to external servers. The tool is powered by Polygraf’s AI Behavioral Control Plane, combining deepfake voice detection, AI-generated response flagging, live PII detection, audio redaction, and compliance audit trails to identify suspicious behavior and sensitive data exposure in virtual meetings in real time. 3 proprietary engines continuously scan every meeting participant for AI-generated content, deepfake voices, and PII leaks, providing instant alerts, participant-level threat scores, and minute-by-minute analysis of AI and deepfake voice indicators, giving administrators immediate visibility into suspicious activity and a detailed breakdown for further investigation.

Built on an encrypted SOC 2 Type II and ISO 27001 certified infrastructure with a strict No-Training policy, Meeting Guard Polygraf AI Meeting Guard delivers secure, real-time governance for Zoom, Google Meet, and Microsoft Teams meetings, giving organizations granular control over the full meeting data lifecycle. Standard cloud deployment can be completed in under 15 minutes, while hybrid and on-premises rollouts are typically completed within 1 to 2 weeks, with dedicated white-glove onboarding support.

Securing sensitive data with real-time AI enforcement is becoming increasingly critical as AI-assisted fraud scales globally. According to Polygraf AI research, organizations face an estimated annual exposure of $2.5 million to $71.4 million or more from AI meeting fraud vectors, including executive impersonation, hiring fraud, vendor impersonation, and financial scams. Gartner found that 62% of organizations have experienced a deepfake attack, including 37% involving video calls and 43% involving audio calls, and predicts that one in four candidate profiles worldwide will be fake by 2028, underscoring the growing enterprise risk from AI-enabled fraud, impersonation, and synthetic identity threats.

Meeting Guard is designed to operate entirely within customer infrastructure, giving organizations complete control, visibility, and auditability over highly sensitive meeting environments while protecting productivity and collaboration workflows.

For more information about Meeting Guard, visit: https://polygraf.ai/meeting-guard/

Halo Fund leads $70M investment into AI-Native Private Banking Platform Flex to accelerate the launch of Flex Global 

Posted in Commentary with tags on July 14, 2026 by itnerd

Flex today announced a $70 million Series B1, led by Ryan Smith and Ryan Sweeney’s Halo Fund with participation from Portage Ventures, Wellington, Crosslink Capital, 53 Stations, Titanium Ventures, Spice, Florida Funders, Spice, and others. The round comes just months after the company’s $60 million Series B in December 2025. Annualized revenue increased 3x since then as Flex accelerated private banking for high-net-worth business owners globally.

Halo Fund, co-founded by Utah Jazz and Utah Mammoth owner and Qualtrics founder Ryan Smith and Accel general partner Ryan Sweeney, brings a sports and entertainment platform spanning the NBA, NHL, and Formula 1. For Flex, the partnership pairs institutional depth with distribution into audiences that include millions of successful middle-market business owners and entrepreneurs, often in communities far beyond Silicon Valley, the exact customers Flex Global is built to serve.

With this round, Flex has now raised $180 million in total equity and $300 million in total debt for expansion across business finance, personal finance, payments, private credit, and ERP. Flex will double the team size from 110 employees today to more than 200 by year-end.

Silicon Valley built financial software for companies, and it built financial software for consumers. It largely missed the people who are both. In the US alone, roughly 350,000 high-net-worth business owners help drive 40% of private-sector payroll, yet most still run their financial lives through tools that treat the business and the owner as two separate worlds. Globally, an estimated 3 million such owners sit at the center of a meaningful share of private economic activity and nearly all of them are multi-entity, multi-currency, and multi-jurisdiction by default.

A business built for global owners

The high-net-worth business owner rarely operates in a single country or a single currency. Today, Flex is launching Flex Global. Building financial infrastructure for that reality:

  • Stablecoin payment rails and wallets in 100+ countries, settling cross-border payments in minutes
  • Institutional USD accounts for foreign business owners who need access to the world’s reserve currency
  • Multi-currency accounts across 76 countries, supporting 32 currencies from USD to RMB to INR to MXN, so owners can hold, send, and receive in the currencies they actually operate in
  • Private credit solutions in 20+ countries, extending Flex’s underwriting well beyond US borders
  • Cards issued to businesses operating globally, spanning entities and geographies under one platform

The result is a single financial home that follows the owner wherever their business takes them.

The company today

  • Flex has crossed $10 billion in annualized total payment volume, growing roughly 4x year-over-year at a nine-figure annualized revenue run rate
  • The average Flex customer now uses four or more products on the platform, a signal of the compounding relationship Flex is built to create, where each product deepens the value of the next
  • Flex’s three largest business categories by logo count are construction, wholesale, and multinational businesses

Why now

For two decades, fintech served two markets: mass-market banking for consumers, and corporate workflows for venture-backed startups and large enterprises. It largely bypassed the high-net-worth business owner, who operates across multiple entities, currencies, and jurisdictions, because the rails to serve them globally didn’t exist. Over the past eighteen months, they arrived. Stablecoin legislation in the US and Europe made the rails enterprise-ready, the world’s largest payment networks moved from pilots to production, and Visa’s stablecoin settlement volume reached a multibillion-dollar annualized run rate. Real-economy stablecoin payment volume roughly doubled in 2025, the majority of it B2B.

Flex’s bet is that the winners of this shift won’t be the companies that make owners think about stablecoins, they’ll be the ones that make the rails invisible. Flex Global embeds stablecoin settlement underneath a full private-banking relationship: an owner pays a vendor in Warsaw or Mexico City the way they’d pay one in Dallas, with AI helping them make decisions across their entire balance sheet. The customer never touches a wallet; their money simply moves in minutes.

What Flex is building

Flex is the AI-native private banking platform for high-net-worth business owners in the middle market globally, built around five pillars: private credit, a business-finance stack, a personal-finance stack, payments, and an agentic back office finance operating system built for middle-market companies. Today the platform brings together credit, banking, payment processing, bill pay, expense management, treasury, and enterprise finance AI agents including Beacon AI. Over time, Flex plans to expand its global banking, personal credit and rewards cards, treasury, travel, and mortgage offerings.