Archive for July 15, 2026

Approov Expands Global Infrastructure to Counter the New Wave of Agentic AI Attacks on Mobile APIs

Posted in Commentary with tags on July 15, 2026 by itnerd

Attackers are no longer writing bots by hand. Agentic AI systems can now probe mobile APIs, mimic legitimate app behavior, and adapt to defenses in real time – at a scale no human-operated botnet could match. Today Approov, the leader in mobile app and API security, announced Approov 2026 3.6, a major global attestation platform upgrade built to meet that threat head-on, combining expanded global infrastructure with the deep, real-time visibility enterprise security teams need to detect and shut down AI-driven attacks as they happen.

The release arrives as Approov processes record attestation volumes for organizations whose mobile apps handle their customers’ most sensitive data – banks, healthcare providers, retailers, and automakers – billions of verifications confirming that every API request comes from a genuine, untampered app on a safe device. Agentic AI attacks rarely run inside the real mobile app; instead, they impersonate it, replaying its API traffic from scripts, emulators and server farms while masquerading as genuine mobile devices. Attestation cuts through that disguise by requiring each request to prove it originates from the authentic app on a real device – proof that a spoofed client running in a data center cannot supply.

New Global Infrastructure for Ultra-Low Latency

Approov has deployed new regional attestation infrastructure in Mexico, with a Milan region following shortly, expanding a global network that already spans North America, South America, Europe, and Asia-Pacific. The new regions cut response times for users across Central America, the southern United States, Southern Europe, the Middle East, and parts of Africa. The Approov attestation network runs across multiple independent cloud providers with automatic failover, using intelligent traffic routing to minimize latency worldwide. As attestation volumes surge, the expanded edge network keeps security checks invisible to legitimate users – protection without friction.

Real-Time Threat Intelligence, Straight into the SOC

Approov turns every protected API into a sensor for AI-driven attack activity, unlocking advanced logging and security use cases:

  • Direct SIEM integration. Backend systems can now decode Approov’s device and app threat signals locally – no extra round trip to Approov servers – and pass detection results directly into Splunk, Sentinel or any SIEM correlated with other request data.
  • Forgery detection. Message Signatures on each network request ensure the origin of the request data verified with a cryptographic key from the device.  Additional key and secret visibility allow verification of attestation ‘pass’ JWT tokens,validly signed ‘fail’ JWT tokens, and invalid or attacker-signed forged tokens – a critical signal when AI agents attempt to counterfeit credentials at scale.
  • Hands-off secret rotation. Setup automated retrieval and deployment of the secrets and keys that backend systems require to secure your mobile APIs, enabling fully automated secret rotation with no manual intervention and no maintenance window.

Deploy New Defenses Without Risking Real Users

Responding to a new attack pattern has always carried a hidden cost: a security policy that blocks attackers can also lock out legitimate customers. Approov 2026 replaces all-or-nothing policy updates with gradual rollouts. Security teams can deploy a new defense to a small slice of traffic, watch its real-world impact live, and expand with confidence – making it safe to respond aggressively to fast-moving AI threats.

Early Warning Before Incidents Escalate

An updated monitoring and alerting suite give both customers and Approov’s own engineers advance notice of trouble:

  • Customer-configurable alerts flag unusual spikes in failed verifications – whether caused by an emerging attack or a third-party network anomaly – so teams can act before failover systems are needed.
  • Global anomaly detection watches pass/fail patterns across Approov’s entire customer base. If multiple accounts show simultaneous failures, Approov’s on-call engineers are paged automatically, turning isolated signals into ecosystem-wide early warning.

Looking Ahead: HarmonyOS Readiness

The release also activates backend support for Huawei’s HarmonyOS platform, now in internal validation, positioning Approov to deliver enterprise-grade protection ahead of the platform’s full market expansion.

Availability

The Approov 2026 backend upgrade is rolling out automatically to all enterprise customers. Documentation for the new SIEM integration, gradual rollout, and automated secret rotation capabilities is available in the updated Approov CLI documentation. For more information, visit approov.com.

WH launches AI cybersecurity clearinghouse to coordinate vulnerability disclosures 

Posted in Commentary with tags on July 15, 2026 by itnerd

Tuesday on a call with reporters, the White House said it launched ‘Gold Eagle’, a cybersecurity clearinghouse that brings together leading AI developers and operators of critical infrastructure to share software and infrastructure vulnerabilities identified by advanced AI systems.

The initiative is intended to help organizations coordinate the discovery, validation, and remediation of security flaws before they can be exploited.

The clearinghouse includes AI companies and providers of essential services across sectors such as finance, healthcare, and energy.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Gold Eagle is directionally right, but it risks optimizing the wrong bottleneck. Every security team I have worked with was already carrying more remediation and hardening work than it had the capacity to complete before AI entered the picture. AI-accelerated discovery can pour more findings into a pipeline that is already backed up.

“A White House official described AI vulnerability discovery as a “step function change” in scale. That should make defenders uneasy. CISA’s Known Exploited Vulnerabilities catalog now contains more than 1,600 entries with mandatory federal remediation deadlines, yet federal audits continue to find exploited vulnerabilities remaining open past those deadlines. Gold Eagle may improve validation, deduplication and prioritization, but coordination does not create the engineers, maintenance windows or vendor resources required to deploy fixes.

“Treasury’s leadership suggests the administration views this primarily as an economic and systemic-risk coordination problem. CISA and the Department of War bring the operational capabilities, but policy coordination and vulnerability remediation move at very different speeds.

“Using Carnegie Mellon’s VINCE platform for intake is a logical choice, given the Software Engineering Institute’s decades of experience with coordinated vulnerability disclosure. The unresolved question is whether the government and participating vendors can remediate findings at anything approaching the rate at which advanced AI systems generate them.

“Gold Eagle should be paired with funded remediation programs, additional support for open-source maintainers and direct technical assistance for critical-infrastructure operators. Otherwise, it creates a faster funnel into the same clogged pipe.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Gold Eagle is a signal that the gap between vulnerability discovery and remediation, which most practitioners have been acutely aware of for a long time, has become too wide to ignore at the national level.

“When AI can surface flaws faster than organizations can act on them, validation is critical. The sectors included here, finance, healthcare, energy, are exactly where adversaries have been patient and deliberate for years. The real measure of this initiative will be whether the remediation side keeps pace with the discovery side. Sharing intelligence is the easier half. Acting on it, consistently and at scale, is where most programs lose ground.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

“Public-private partnerships for national cybersecurity, like Gold Eagle, are directionally the right model. Execution will determine whether it becomes transformative or merely another information-sharing program.

“Frontier AI is already changing the scale and speed of vulnerability discovery while accelerating offensive cyber operations. The real challenges are shifting toward coordination, prioritization, elimination of duplicate effort, and maintaining a defensive advantage when adversaries have access to many of the same capabilities.

“Gold Eagle offers a glimpse of how AI will reshape collective defense. The imperative is to move beyond human-speed workflows toward machine-speed, machine-scale detection, analysis, and coordinated response. Defenders cannot expect to compete if AI accelerates the offense while critical defensive processes remain measured in days or weeks.

“To succeed, Gold Eagle must earn the trust of its public and private partners, particularly in critical infrastructure where organizations depend on common hardware, software, and open-source supply chains. Participants need confidence that vulnerability discoveries will be protected appropriately, prioritized reliably, and translated into timely remediation. As AI makes vulnerability discovery increasingly abundant, the limiting factor will be the speed and effectiveness of coordinated response.”

I for one am skeptical of this program. But I am free to be proven wrong in terms of how effective this is.

UK adds cyberattacks on critical systems to National Risk Register

Posted in Commentary with tags on July 15, 2026 by itnerd

The UK government has added cyberattacks targeting data infrastructure, water systems and police networks to its 2026 National Risk Register, which outlines the most serious risks facing the country.

The updated register also includes “digital resilience failure” as a new risk, drawing on lessons from the July 2024 CrowdStrike outage. The government cited the increasing sophistication of artificial intelligence as one factor affecting the cyber threat landscape.

The UK plans to conduct its largest home defense exercise in decades in 2027, testing government and public-sector responses to hybrid threats including cyberattacks, disinformation and critical infrastructure sabotage.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “Seven new risks on the UK’s National Risk Register. The one that undermines the rest is “interference in democratic processes.” Every other addition, cyberattacks on water operational technology (OT), police networks and colocation data centers, has an identifiable technical failure state and a technical remediation path. Democratic interference does not. Once the integrity of the information environment becomes a national security risk, someone in government must decide what constitutes manipulation, disinformation, or an unacceptable influence operation. Those are political judgments, and the standards will change with the government making them.

   “Operation Albiston Shadow, the UK’s largest home defense exercise in decades, is supposed to test readiness for cyberattacks and infrastructure sabotage. To the extent the scenario requires officials to adjudicate information quality, it stops being a purely technical drills.

   “The technical risks themselves are overdue, though I’d feel better if the UK’s follow-through matched the announcements. In just over a week, the government released Cyber Shield’s blueprint for autonomous AI defense at machine speed, the Risk Register update and Albiston Shadow. Three announcements centered on identifying, modeling, and exercising risk, with no funded remediation commensurate with the risks being announced. The National Audit Office (NAO) reported in January 2025 that departments were running at least 228 legacy IT systems and lacked fully funded remediation plans for 120 of them, 53%.

   “Discovery is the easy part. Critical infrastructure teams too often avoid testing production OT because they lack the tooling or the risk appetite to touch systems that can’t go down. The vulnerability scan runs on the IT side, the OT side gets a paper assessment, and the exercise report says “tested.” That’s how exercises become security theater. Albiston Shadow runs in 2027, and without funded remediation, it risks testing many of the same weaknesses the government already knows about.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

   “The most significant development in the UK’s National Risk Register isn’t simply the recognition of growing cyber threats, it’s the recognition that digital resilience is now a national resilience issue. The strategic question is not whether we can prevent every cyber attack, it is whether society can continue functioning when digital systems fail.”

   “This is part of a broader international shift. In the United States, initiatives such as the June AI Executive Order, the Gold Eagle public-private cybersecurity partnership, and increasingly realistic resilience exercises all point toward the same conclusion: cybersecurity must evolve to address cyber civil defense. Governments don’t own most critical infrastructure, so resilience must be built through trusted public-private partnerships, shared situational awareness, and a collective defense which measures and addresses the exposures before a real crisis reveals them. Plans don’t build resilience. Realistic adversarial emulation, quantitative performance metrics, and OODA loops do.”

   “Artificial intelligence is accelerating this transformation for both attackers and defenders. Human-speed defensive workflows will increasingly struggle to keep pace with machine-speed offensive operations. The limiting factor is no longer finding flaws, but the speed and effectiveness of coordinated response. Ultimately, success should be measured not simply by whether attackers gained access, but by whether essential services remained available and recovered quickly when disruption occurred, and whether the attack remains contained, or affects adjacent infrastructures.”

Seemant Sehgal, Founder & CEO, BreachLock:

   “The UK government putting cyberattacks on the same list as floods and pandemics is a policy signal worth reading carefully.

   “What stands out to me about the UK’s approach is the inclusion of digital resilience failure as a distinct risk, because the CrowdStrike outage showed that the most disruptive events can originate inside your own trusted systems, not from an adversary at all.

   “The 2027 exercise is the right instinct, but the gap between planning for a scenario and actually being prepared for it is where most organizations need to focus on closing.”

The USA should copy the UK as clearly the UK are on the right side of history.

EnGenius Strengthens Cloud-Managed Layer 3 Switching Portfolio with New Core and Aggregation Switches

Posted in Commentary with tags on July 15, 2026 by itnerd

EnGenius today announced a new lineup of cloud-managed Layer 3 switches purpose-built for enterprise, system integrator, VAR, and MSP networks.

The new series includes three models: the enterprise-class ECS8830F and ECS8854F, along with the ECS6824F for SMB core, branch, and managed service provider (MSP) deployments. Together, the EnGenius Cloud-Managed Layer 3 Switches help organizations modernize network infrastructure with high-density 10G aggregation, 100G backbone connectivity, advanced Layer 3 routing, resilient design, and centralized cloud-based management across access, aggregation, and core.

As enterprise networks support more Wi-Fi 7 deployments, video analytics, edge applications, virtualized workloads, distributed services, and high-bandwidth east-west traffic, the network core can no longer be treated as a simple aggregation point. Modern IT teams need a core architecture that supports scalable routing, secure segmentation, operational resilience, and clear visibility across the network.

Enterprise-Class Core and Aggregation: ECS8830F and ECS8854F

The ECS8830F and ECS8854F are built for enterprise core and aggregation networks that require advanced Layer 3 routing, high availability, and scalable network operations.

The ECS8830F provides 24 × 10G SFP+ ports and 6 × 100G QSFP28 uplinks with up to 1.68 Tbps switching capacity, while the ECS8854F expands scale with 48 × 10G SFP+ ports and 6 × 100G QSFP28 uplinks with up to 2.16 Tbps switching capacity. Both platforms support up to 600 Mpps forwarding performance and wire-speed throughput to support high-performance enterprise network environments.

To support scalable network architectures, the platforms combine advanced Layer 3 routing and network virtualization capabilities, including OSPFv2/v3, BGP/BGP4+, IS-IS, ECMP, VRRP, Policy-Based Routing (PBR), BFD, and VXLAN EVPN. These capabilities enable resilient traffic forwarding, network segmentation, high-availability designs, and scalable multi-site connectivity while supporting interoperability across existing infrastructure investments. The result is simplified network operations, improved resiliency, and the flexibility to scale enterprise networks as business requirements evolve.

For maximum network resiliency and business continuity, the platforms support MC-LAG and VSF, along with 1+1 redundant hot-swappable power supplies and 3+1 redundant hot-swappable fan modules. This architecture eliminates single points of failure, enables seamless failover, and maintains service continuity, reducing service disruption and simplifying maintenance for enterprise network environments.

The series also supports a hybrid operational model. IT teams can use EnGenius Cloud for centralized visibility and monitoring while retaining local access through Web UI, CLI, SNMP, NETCONF, syslog, and related operational tools for configuration, troubleshooting, and day-to-day administration.

Right-Sized 10G Layer 3 Core for SMB and MSP Networks: ECS6824F

The ECS6824F delivers a high-performance 10G Layer 3 fiber core to growing SMBs, branch networks, and MSP-managed environments seeking greater scalability, security, and network control without the complexity of enterprise-class core platforms.

The 1U switch provides 24 × 10G SFP+ ports and 480 Gbps switching capacity, with Static Routing, RIP, and OSPFv2/v3 to help organizations segment departments, applications, surveillance systems, guest networks, and server zones more effectively.

For video-centric and multicast environments, the ECS6824F includes IGMP and MLD support to improve multicast traffic efficiency for IPTV and IP surveillance deployments. It also integrates core-layer security controls, including 802.1X authentication, ACLs, DHCP Snooping, IP Source Guard, ARP protection, Port Security, Storm Control, and DoS protection.

Dual internal power supplies add hardware resiliency, while EnGenius Cloud delivers centralized visibility, monitoring, and management for IT teams and MSPs.

Extending the EnGenius Portfolio from Access to Core

With the introduction of the new series, EnGenius extends its cloud-managed switching portfolio to address enterprise core, aggregation, and SMB core deployments. Together with EnGenius Cloud, the new switches combine cloud visibility with local control, enabling organizations, system integrators, VARs, and MSPs to deploy and manage networks through a consistent operational experience as their infrastructure grows.

Learn more about Cloud-Managed Layer 3 Switching Portfolio

ECS6824F: https://www.engeniustech.com/ecs6824f-cloud-managed-layer-3-fiber-switch.html
ECS8830F: https://www.engeniustech.com/ecs8830f-layer-3-stackable-switch.html
ECS8854F: https://www.engeniustech.com/ecs8854f-48-port-stackable-layer-3-switch.html

Cursor’s 7-month-old 0-day highlights the cost of silent AI-tool disclosure 

Posted in Commentary with tags on July 15, 2026 by itnerd

The Cursor 0-day highlights a difficult reality in AI security: an AI coding tool can hand an attacker full code execution before a developer does anything at all. Researchers found that Cursor searches for a git executable inside a project’s own root folder the moment it’s opened, and if a malicious git.exe is sitting there, Cursor runs it immediately, no click, no approval dialog, no warning that anything is about to execute, just opening a cloned repository that hands an attacker arbitrary code execution as the logged-in user, a flaw reported seven months ago that remains unpatched today.

You can get up to speed here: Cursor IDE 0-Day: Critical Code Execution Flaw Disclosed | AIToolly

Vali Valiyev, Principal Architectural Engineer, AI Infrastructure, Polygraf AI says this:

“As a software developer, what strikes me about this isn’t the specific vulnerability—PATH and working-directory precedence issues have been known for years—but what it says about how we should view AI-powered IDEs. They’re no longer just code editors with a chat interface; they’re applications capable of executing code, accessing local files, and interacting with external services. What’s even more interesting is that this exploit doesn’t rely on prompt injection or an AI agent at all. Simply opening a cloned repository can be enough, which means the underlying execution model is just as important as the AI capabilities layered on top. The fact that similar issues have surfaced across Cursor, Copilot CLI, Gemini CLI, and Codex suggests this is an industry-wide design challenge rather than a single product bug.

For me, the takeaway is that security-first design has to become the default for AI development tools. Sandboxing, least-privilege execution, strict path validation, and treating every cloned repository or external resource as untrusted shouldn’t be optional safeguards—they should be foundational. Until AI IDEs treat “opening a workspace” with the same security mindset that browsers apply to loading a webpage, these tools will keep exposing developers to avoidable risk. Until those assumptions become standard, developers should adopt safer workflows themselves: avoid blindly cloning and opening unfamiliar repositories, check for unexpected executables, and use isolated environments when evaluating untrusted code. AI assistants are transforming how we build software, but they also require us to rethink where our trust boundaries begin.”

Gidi Cohen, CEO & Co-Founder, Bonfy.AI:

“This isn’t a fringe bug but a wake-up call for how we think about the trust put in modern developer tools.

Opening a project should never quietly turn into executing code, yet that’s exactly what’s happening here when AI is part of the equation, and this is not just happening with one vendor. This is a broader industry pattern where everyday workflows like cloning a repo are being treated as inherently safe, when they clearly aren’t. Developers are constantly pulling in third-party code (often with AI in the loop), but assuming that it is safe is not something we can just assume.

What’s just as much of an issues is how the response is handled. Delays, downplaying the severity, and labeling issues as “informational” signals a gap in how seriously this type of risk is being taken. The technical flaw matters, but the lack of urgency around it matters even more.

For leadership, the takeaway is straightforward. Repositories should be treated as executable content. Trust boundaries need to be explicit and enforced, not implied. And how organizations respond to vulnerabilities is now a direct reflection of their credibility, not just their security posture.

This isn’t about Cursor or any single tool. It’s about an industry still catching up to the realities of AI-assisted development. Until “open” no longer implies “execute,” this gap will continue to be exploited, mostly unnoticed and unmonitored.”

I guess it is time to change the thinking of everyone. The industry needs to make sure that AI based code is sanity checked so that it is safeguarded accordingly.

OAuth Client ID spoofing lets attackers bypass security

Posted in Commentary with tags on July 15, 2026 by itnerd

There is a new Proofpoint report highlighting a credential theft operation involving OAuth Client ID spoofing, raising significant concerns about identity security:.

Key Takeaways

  • Proofpoint has observed OAuth client ID spoofing emerging as a novel technique, increasingly leveraged in cloud campaigns.
  • Microsoft Entra ID returns different responses depending on whether a supplied OAuth client ID is valid and whether it corresponds to a registered application.
  • This behavior enables account enumeration without a registered OAuth application and allows attackers to infer password validity or account state without generating a successful sign‑in event.
  • Researchers observed multiple campaigns at scale abusing spoofed OAuth application identifiers, with distinct tooling, infrastructure, and execution patterns indicating independent adoption by multiple threat actors.
  • To detect similar activity, defenders should monitor sign-in logs for events without an application name, which may indicate spoofed client IDs.

Kevin Surace, CEO, TokenCore had this comment:

Attackers submit stolen usernames and passwords to Microsoft’s OAuth endpoint while continually inventing fake client IDs. Differences in Microsoft’s error responses can reveal whether an account exists and whether the password is correct, allowing attackers to quietly identify working credentials before attempting account takeover.

Biometric assured identity stops this attack cold. Even when the attacker has confirmed the correct username and password, the account cannot be accessed without the authorized biometric, the registered physical Token device and the cryptographic credential stored inside it.

The danger is that attackers can validate enormous lists of stolen credentials without generating the successful sign in events that many security tools are designed to detect. Confirmed credentials can then be used to target email, cloud applications, administrative accounts, VPNs and other enterprise systems.

Biometric assured identity makes those credentials worthless. A correct password is no longer treated as proof of identity, so the attacker cannot complete the login, establish a foothold or move laterally through the organization.

Credential testing and password spraying are not new, but the use of constantly changing fictional OAuth client IDs is a clever new way to obscure the activity and exploit gaps in identity telemetry. It is an evolution of credential theft designed to make password validation quieter and more scalable.

The larger lesson is that any architecture still relying on passwords as meaningful proof of identity remains vulnerable. Biometric assured identity ends that dependency and stops the operation from progressing from credential validation to account compromise.

Organizations should immediately investigate unusual ROPC activity, unknown client IDs, blank application names and large numbers of OAuth errors across multiple accounts. They should disable ROPC and other password based legacy flows wherever possible, reset exposed credentials and require phishing resistant authentication throughout the environment.

Most importantly, enterprises should deploy biometric assured identity such as Token across their workforce. Token requires the authorized fingerprint, the registered hardware device, physical proximity and a valid cryptographic exchange with the legitimate service, leaving the attacker with nothing they can steal, spoof, relay or reuse.

This attack demonstrates why passwords and legacy MFA are no longer defensible for protecting valuable enterprise systems. Attackers may be able to determine that a password is correct, but biometric assured identity ensures that the password still gets them nowhere.

Now is a good time to move to passwordless authentication solutions. Failing that, modern MFA solutions is another option to protect organizations from threats of all sorts.

CData Extends Connect AI to HIPAA-Regulated Healthcare

Posted in Commentary with tags on July 15, 2026 by itnerd

CData Software today announced that CData Connect AI now provides a governed AI data layer built for HIPAA-regulated environments, enabling healthcare providers, payers, life sciences organizations, and healthcare technology companies to securely connect AI applications and agents to protected health information (PHI).

Healthcare organizations are moving AI into clinical, operational, and administrative workflows, and most hit the same wall: getting AI to access and act on sensitive data while holding the security, governance, and compliance that HIPAA requires. Connect AI addresses this by providing a governed access layer that connects AI applications directly to live enterprise systems, without replicating or exposing sensitive data.

CData Connect AI provides the governance capabilities organizations need to confidently deploy AI applications that interact with PHI, including:

  • Secure, credentialed access to live healthcare data without replication or unnecessary data movement.
  • Comprehensive audit logging that tracks every AI query and user interaction.
  • Identity-aware access controls that enforce existing user permissions.
  • Support for Business Associate Agreements (BAAs) for eligible customer deployments.
  • Centralized governance across AI assistants, applications, and autonomous agents.

The platform lets healthcare organizations deploy AI-powered use cases such as clinical decision support, operational assistants, patient service automation, revenue cycle optimization, and healthcare analytics while holding strict governance over sensitive data.

Unlike approaches that require organizations to move healthcare data into separate AI platforms or custom pipelines, Connect AI keeps data in place and provides a controlled layer that lets AI interact with the enterprise systems where the data already resides. CData already delivers this connectivity to regulated, audit-heavy organizations, including life sciences leader GSK, giving healthcare teams a proven foundation for governed AI.

CData Connect AI is available immediately. Organizations interested in deploying HIPAA-compliant AI workloads can learn more about eligibility requirements and Business Associate Agreements at cdata.com.

Nudge Security Unveils AI Agents to Mitigate Escalating Risks from Hidden OAuth Grants and Browser Extensions

Posted in Commentary with tags on July 15, 2026 by itnerd

Nudge Security today announced new agentic capabilities to help security and IT teams find and remediate malicious and high-risk OAuth grants and browser extensions, two of the fastest-growing and hardest to manage attack surfaces in the enterprise.

The new agents continuously analyze OAuth grants and browser extensions discovered by Nudge Security, flag what’s risky, and automate remediation with human-in-the-loop decisions. The new agents join Nudge Security’s Vendor Risk Analyst agent, which automatically builds vendor security profiles for newly discovered AI and SaaS apps, cutting manual security review time by up to 90%.

Closing the gap between discovery and action

Modern enterprises have more apps, more extensions, and more third-party connections than traditional security programs can manually assess. As the breaches of Klue and Salesloft Drift illustrated, OAuth grants can provide broad, persistent access to sensitive data, which attackers are increasingly exploiting. Browser extensions can introduce supply chain risk directly into employees’ daily workflows. Shadow AI and SaaS sprawl mean new vendors and new exposures can appear faster than any ticket queue can keep up with.

Nudge Security’s agentic capabilities address sources of risk that have long outpaced manual human review:

  • OAuth Grant Risk Analyst analyzes OAuth grants, flags anomalies, and recommends specific revocations based on the organization’s security policies.
  • Browser Extension Risk Analyst surfaces risky and malicious third-party browser extensions installed on employee devices and helps prioritize remediation.
  • Vendor Risk Analyst (existing) automatically generates and maintains SaaS and AI vendor security profiles for every AI and SaaS app, including compliance attestations, security posture indicators and AI data privacy policy insights.

Built for defenders across the surfaces others still miss

Nudge Security uniquely combines multiple discovery signals across the browser, inbox, identity provider, and connected apps to provide the most complete and timely view of AI, SaaS, OAuth, and browser extension risk. This broader context helps the agents make higher-confidence recommendations and deliver targeted, policy-driven remediation guidance that reduces noise and increases throughput for overburdened IT and security teams.

Availability

Nudge Security’s new agentic capabilities are currently available to select customers.

Novel Attack Techniques Abuse Windows Virtualization Feature to Evade EDR & Security

Posted in Commentary with tags on July 15, 2026 by itnerd

Bitdefender have released research documenting three previously undocumented attack techniques that abuse a legitimate Windows feature called bind links to bypass endpoint detection and response (EDR) and built-in Windows defenses, including AMSI, AppLocker, Windows Firewall, and Sysmon.

The techniques abuse a virtualization feature built into Windows 10 RS4+ and Windows 11 to redirect trusted file paths to attacker-controlled files — without modifying files on disk.

Key findings:

  • Three novel bind link attack techniques (File-Binding, Process-Binding, and Silo-Binding) evade security detection at the kernel level
  • Silo-Binding, the most advanced of the three, splits the filesystem into two views so malicious code executes inside an isolated container while security tools outside see only clean, legitimate files
  • Bitdefender successfully verified the techniques in a live environment, bypassing EDR defenses with the infostealer Invoke-Mimikatz 

You can read the report here:https://businessinsights.bitdefender.com/bind-link-abuses-windows-feature-edr-evasion-technique.

Guest Post: Ransomware attacks up 20% year-over-year as The Gentlemen and Qilin battle for dominance

Posted in Commentary with tags on July 15, 2026 by itnerd

The latest findings from NordStellar, a threat exposure management platform, reveal that ransomware attack volumes remained high from April to June 2026, sustaining the elevated baseline. The analysis also points to an intensifying fight for dominance between the two most active ransomware groups, The Gentlemen and Qilin, as well as a notable shift in victim targeting.

According to findings from NordStellar, 2,581 ransomware incidents were recorded during April-June 2026. The number reflects a slight 4% decrease from 2,676 incidents recorded in Q1 2026. However, the attacks remain at a heightened baseline, indicating sustained threat activity.

“The slight decrease in attacks shouldn’t be a sign to relax just yet,” says Vakaris Noreika, cybersecurity expert at NordStellar. “Ransomware accelerated in the last quarter of 2025, reaching record highs, and although the number of attacks has been slightly decreasing every quarter this year, we are now seeing a new alarming baseline of about 2,500 attacks per quarter.”

A total of 5,257 ransomware attacks were recorded during January-June 2026. This marks a 20% increase from the 4,387 attacks recorded during the same period last year, signaling that the ransomware threat is growing despite quarterly fluctuations.

Rivalry between Qilin and The Gentlemen intensifies

Qilin emerged as the most active ransomware group in Q2 2026 with 299 attacks, followed closely by The Gentlemen with 284 attacks. Activity from other groups trailed significantly, with DragonForce ranking third at 147 attacks.

“While Qilin’s activity declined slightly from the previous quarter, The Gentlemen accelerated its operations with a 39% increase in attacks, further deepening the rivalry between the two groups,” says Mantas Sabeckis, senior threat intelligence researcher at Nord Security. “Even though DragonForce remains significantly less active than the top two, it is steadily scaling up — last quarter’s attack volume marked an all-time high for the group.”

According to Sabeckis, the fact that Qilin and The Gentlemen have managed to establish themselves as the two dominant ransomware groups and more or less maintain their positions highlights a concerning trend — the ransomware threat landscape is stabilizing and maturing.

“Established ransomware groups have refined tools, affiliate networks, and negotiation infrastructures. The more sophisticated and established a group becomes, the greater the threat it poses,” explains Sabeckis. “This competition between Qilin and The Gentlemen could potentially drive an even higher baseline of activity. Each group is likely ramping up operations and casting a wider net to come out on top, and as affiliates move between groups, the balance of power could shift in the coming months.”

He adds that in a landscape like this, smaller groups such as DragonForce are under growing pressure to scale. They’re more likely to accelerate their operations to prove themselves among more dominant players, further inflating the overall threat landscape.

Q2 ransomware victims: SMBs dominate, but attackers are shifting their gaze to enterprises

NordStellar findings reveal that small and medium-sized businesses (SMBs) — those with up to 200 employees and revenues under $25 million — bore the brunt of ransomware activity. However, attacks against large enterprises with revenues exceeding $1 billion surged by 74%, rising from 23 incidents in the first quarter to 40 incidents during the second.

“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack. This recent spike in enterprise targeting is unusual and may be a temporary fluctuation,” says Noreika. “This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground.”

The data also reveals that ransomware actors continue to primarily target companies in the US, with 769 recorded ransomware cases in Q2 2026. The US was followed by Canada with 97 cases, then Germany with 83 cases, the United Kingdom with 74 cases, and France with 51 cases.

As seen in previous quarters, companies in manufacturing were hit the hardest, making up for 19.5% of all attacks. The information technology sector came second (10.7% of attacks), followed by professional, scientific, and technical services (8.3%), construction (7%), and healthcare (6.2%).

“Companies in the US experienced a slight decline in attacks compared to the previous quarter, while attacks on companies in Canada increased by 13%, suggesting that attackers might be shifting their geographical focus,” says Noreika. “Businesses operating in the manufacturing and information technology sectors continue to be hit hardest by the attacks. However, the healthcare industry recorded the smallest quarterly decline among major sectors, signaling that ransomware actors continue to prioritize it due to its high-value data and the operational sensitivity of critical services, where even limited downtime can create intense pressure to restore systems quickly.”

Safeguarding against ransomware in a sophisticated threat landscape

According to Noreika, the increasing maturity of the current ransomware landscape calls for companies to stay on high alert. Businesses can expect more refined and complex attacks, making it critical to identify and patch vulnerabilities before attackers can exploit them.

“The current ransomware ecosystem is growing and expanding. Groups like Qilin and The Gentlemen don’t operate like amateur hackers — they operate like well-structured organizations,” says Noreika. “They have extensive resources that allow them to scale their operations, broaden their victim pool, invest in more efficient initial-access methods, and escalate pressure tactics such as double and triple extortion.”

Previous findings from NordStellar reveal that ransomware actors utilize various schemes to coerce victims into payment, with 76.8% of ransomware negotiations including threats to publish or leak the data, and limited-time price discounts being offered in 45.5% of the negotiations.

“As leading ransomware groups compete for dominance and scale their operations, no company is immune. Abandoning the ‘it won’t happen to us’ mindset has never been more critical,” says Noreika. “Companies should strengthen their defenses by focusing on basic cyber hygiene, which is too often overlooked. This includes enforcing multi-factor authentication, implementing strong password management policies, regularly patching systems and applications, and adopting a zero trust approach to limit lateral movement.”

Noreika emphasizes the importance of early threat prevention and detection — ransomware actors can use data leaked on the dark web to gain initial access, and catching these leaks early alerts the organization to take action by resetting passwords and revoking access keys before it’s too late. He adds that backing up critical data is crucial to reduce downtime in the event of a successful ransomware attack, while having a recovery plan in place is essential to speed up incident mitigation.

Methodology

NordStellar continuously monitors over 200 blogs run by ransomware groups. Analyzing the listings published by attackers, NordStellar discovered 2,581 ransomware attacks during April-June 2026. The full methodology can be found in the report, located here: https://nordlayer.com/intelligence/ransomware-statistics/.