Archive for July 21, 2026

The Suno breach now affects 55.3M accounts

Posted in Commentary with tags on July 21, 2026 by itnerd

Have I Been Pwned has added the Suno data breach to its database, reporting that the AI music platform’s breach affected 55.3 million accounts.

The newly reported total substantially expands the known scale of the incident. According to Have I Been Pwned, the compromised information included email addresses, phone numbers and, in tens of thousands of Stripe-related records, names, physical addresses, purchase details and partial payment card information.

Have I Been Pwned can be found here: Have I Been Pwned: Check if your email address has been exposed in a data breach

The Suno breach can be found here: Have I Been Pwned: Suno Data Breach

Seemant Sehgal, Founder & CEO, BreachLock had this comment:

“When the disclosed scope of a breach grows this significantly in such a short period, it suggests that either the initial investigation was rushed or the organization lacked adequate visibility into its environment.

“The scale and variety of the exposed data raise serious questions about internal segmentation, security monitoring and incident readiness. Regulators and customers will spend less time focused on the 55.3 million figure than on what Suno knew, when it knew it and how it responded. Organizations that cannot establish what was accessed, when and from where within the first 72 hours will find their disclosure decisions harder to defend than the breach itself.”

Steven Swift, Managing Director, Suzu Labs follows with this::

“Customers have considerable breach fatigue after being notified repeatedly that their names, addresses, email addresses and other personal information have been exposed. At this point, individuals should assume that much of their personal information has already been compromised.

“The AI component is not necessarily the central issue here. There has been no public evidence directly attributing Suno’s security posture to its use of AI-generated code. However, rapidly growing AI companies may rely heavily on AI-assisted development, which can introduce security weaknesses when code is deployed without proper review and testing.

“Most breaches result from organizations failing to follow established security practices. Companies using AI in their applications, automation and infrastructure need a comprehensive security baseline and regular testing to confirm that their controls work. That should include at least annual penetration testing of hosted applications, services, internal networks and devices.

“Testing alone is not enough. Organizations also need to remediate the vulnerabilities that testing identifies. Too many companies conduct annual penetration tests only to receive the same findings year after year.”

Organizations need to consider that being pwned is the worst thing that can happen to them. If they do that, maybe then they will start to take information security seriously.

Estée Lauder’s ten-month gap between breach and disclosure is a #fail

Posted in Commentary with tags on July 21, 2026 by itnerd

Estée Lauder confirmed that an unauthorized party gained access to its Oracle E-Business Suite HR platform as far back as August 2025, but the breach wasn’t confirmed until June 2026, nearly ten months later, tied to the broader Cl0p ransomware campaign that has been mass-exploiting Oracle EBS across shared enterprise software, no targeted attack required, no unique vulnerability built just for Estée Lauder, just a shared platform that thousands of other companies were running too.

The breach notification can be read here: ELC – U.S. Individual Notification Letter.pdf

John Watters, Chairman and CEO, iCounter had this to say:

“Ten months between intrusion and disclosure at Estée Lauder isn’t a failure unique to this company, it’s Clop’s business model working exactly as designed. This group doesn’t break into companies one at a time. They find a vulnerability in software that thousands of organizations share, harvest data quietly across as many victims as they can before anyone notices, and then work through the extortion process at their own pace long after the initial compromise. By the time a company like Estée Lauder confirms what happened, Clop has already known the shape of that exposure for the better part of a year.

The organizations that catch this fast aren’t the ones with better firewalls, they’re the ones with threat intelligence mature enough to know, within days of a campaign like this becoming public, whether they were one of the platforms swept up in it, instead of waiting for a forensic investigation to tell them what an intelligence program should have flagged months earlier. And that intelligence work doesn’t stop once the campaign is public. Clop rolls out its victim list over time rather than all at once, which means every new name that gets published is a live signal, not old news. If your organization runs the same software as the companies showing up on that list, each new name should be treated as a countdown, not a headline about somebody else’s bad month.”

This is a #fail. There is no way that this amount of time should have passed before affected parties should have been notified. Normally I would say that someone should be punished for this. But I am pretty sure that this isn’t going to happen in this case.

FusionAuth Appoints Jamey Miller as SVP of Engineering and Technology

Posted in Commentary with tags on July 21, 2026 by itnerd

FusionAuth today announced the appointment of Jamey Miller to SVP of Engineering and Technology. He will be responsible for scaling engineering to support the company’s accelerated growth and increasing enterprise adoption, maintaining product quality and platform reliability, and positioning engineering for AI.

Miller has more than 25 years of experience scaling global SaaS R&D organizations across product, engineering, security, IT, and support, with deep experience in both cloud and self-hosted/on-premises deployment models. He has a proven track record of leading R&D in PE-backed and high-growth environments, including periods of rapid scaling, M&A integration, and operational transformation.

Most recently, Miller served as Chief Product & Technology Officer at global enterprise SaaS company Confience, where he improved delivery predictability and platform security while integrating the acquisition of Brazilian software firm LabSoft. Earlier, as EVP of R&D and Operations at Convercent, he helped guide the company to its acquisition by OneTrust, then went on to serve as VP of R&D Operations there, driving scale and cost efficiencies across a 400-person R&D organization.

Miller holds an MBA from the University of Portland, a M.S. in Marketing from the University of Colorado and a Bachelor of Science in Business Administration from Colorado State University. 

Leaseweb Acquires ITQ’s VMware VCSP Customer Base 

Posted in Commentary with tags on July 21, 2026 by itnerd

Leaseweb, a leading cloud services and Infrastructure as a Service (IaaS) provider, has announced the acquisition of the Broadcom VMware white label VCSP customer base of ITQ, a leading European Broadcom IT Services company. The move follows the recently announced strategic partnership between the two companies, under which ITQ selected Leaseweb as its infrastructure partner for VMware Cloud Foundation (VCF) services for its VCSP partners, in a significant expansion of Leaseweb’s VCF platform across Europe.

As part of the acquisition, 51 VCSP customers will transition to Leaseweb’s VCF platform, collectively accounting for approximately 35,000 cores. This brings Leaseweb’s core count to 65,000, positioning it as the largest VMware Pinnacle Partner in the Netherlands and reinforcing its position within the Broadcom partner ecosystem.

The acquired white label VCSP partners, previously operating under the Broadcom VMware Advantage Partner program, will be able to continue to market their proposition under Leaseweb’s Broadcom VMware VCSP Pinnacle Partner status. As an Authorized Pinnacle VCSP, Leaseweb transacts directly with Broadcom, providing these partners with a fully authorized and long-term platform for their VMware businesses. Partners will also continue to have access to ITQ’s VMware expertise as part of the ongoing partnership between the two organizations.

In addition to the acquired customer base, Leaseweb and ITQ are actively engaging with global non-renewing Broadcom VMware VCSP partners, offering a supported path forward for their VMware businesses under Leaseweb’s Pinnacle Partner infrastructure. Under the partnership, Leaseweb will act as provider for VMware VCF 9.x infrastructure, with ITQ serving as knowledge partner, bringing industry-leading VMware advisory and implementation expertise to support customers through migration and deployment

For more information, please visit: www.leaseweb.com

Liquibase Expands Global Partner Ecosystem

Posted in Commentary with tags on July 21, 2026 by itnerd

Liquibase today announced a major expansion of its global partner ecosystem and the appointment of Phil Robinson as Vice President of Global Channels and Alliances. The move builds on strong momentum for Liquibase Secure and growing enterprise demand for governed database change as AI, modernization, security, and compliance reshape software delivery.

Robinson brings more than two decades of channel, alliance, and enterprise open-source experience to Liquibase. Most recently, he served as Vice President of Global Channels at Digital.ai, where he helped redesign and relaunch the company’s channel program globally. Before that, he spent more than eight years at Atlassian, where he built and scaled global alliance programs with GSIs and Federal SIs, including Accenture, Deloitte, PwC, and Capgemini. His experience also includes leadership roles at Magento, Alfresco, and Hewlett Packard Enterprise across open source, cloud, systems integration, and enterprise software.

Trusted by 20 of the Fortune 100 and supported by a global community with more than 100 million downloads, Liquibase is investing in partners to help enterprises close the database delivery gap and build new services around Database Change Governance.

Robinson will lead Liquibase’s global partner strategy across partner recruitment, enablement, joint marketing, and partner-led services around Database Change Governance, while deepening the company’s engagement with cloud marketplaces and government partners.

AI is exposing the database delivery gap

Modern application and data delivery has accelerated in waves. Agile increased release velocity. Cloud spread applications, databases, and data platforms across more teams, tools, and environments. Enterprises responded by investing in CI/CD, automated testing, infrastructure-as-code, and security controls. But database change often remained governed through tickets, manual reviews, disconnected scripts, and processes that varied across teams, tools, and database platforms.

That disconnect has made the database one of the last major constraints on modern application and data delivery. Application code, infrastructure, and security increasingly move together, while database change is still treated as a separate process in many organizations. The result is fragmented governance, slower releases, and limited visibility into what changed, who approved it, and whether it is safe to deploy.

AI is not creating the database delivery gap. It is exposing it. As AI assistants and agents generate more software, they also increase the volume and speed of database change flowing through delivery systems that were never designed to operate at that scale. The challenge is no longer simply automating deployments. It is keeping database change synchronized with application code, infrastructure, and security before it reaches production.

The governance gap is widening. According to Liquibase’s 2026 State of Database Change Governance Report, 96% of organizations now have AI interacting with production databases, and 70% ship database changes weekly or faster. Yet only 28% enforce governance through automated controls and evidence, while 39% say they cannot reliably track what changed where.

For partners, this represents a significant opportunity to help customers modernize database delivery, govern AI-assisted development, strengthen compliance, reduce production risk, and bring database change into the same DevSecOps practices already established for application code. As enterprises look to scale AI safely, they need partners who can help modernize the processes that AI is exposing as bottlenecks.

Database Change Governance provides the control plane that keeps database change synchronized with application code, infrastructure, and security across the software delivery lifecycle. Liquibase Secure operationalizes that control plane across development teams, CI/CD pipelines, AI agents, and more than 65 database platforms, enabling enterprises to accelerate software delivery without sacrificing governance.

Why this is a partner opportunity now

For partners, this shift is a chance to become indispensable to their most complex customers. As database change outruns the ability to govern it, enterprises need a partner who can restore control at the exact point where developer velocity, compliance, and AI readiness collide. Liquibase provides an opportunity for partners to turn that challenge into a repeatable practice spanning advisory, implementation and managed services, reaching every environment a customer runs, from mainframe to cloud to lakehouse.

At the center of the opportunity is Liquibase Secure, which helps enterprises automate, secure, and govern database change across complex environments. With policy checks to deliver standardized change, advanced drift detection, structured audit trails, always-on evidence gathering, and more, Liquibase Secure gives developers, platform teams, security leaders, and compliance teams a governed path for every database change.

Liquibase already works with a robust group of consulting, cloud, public sector, and technology partners. Under Robinson’s leadership, the company plans to expand partner coverage both geographically and into specific industry sectors, creating clear paths for partners to build solutions and deliver Liquibase Secure, Database

Organizations interested in joining the Liquibase partner ecosystem can learn more at liquibase.com/partners.

Cascade raises $3.5M to help construction firms predict the future and win more projects

Posted in Commentary with tags on July 21, 2026 by itnerd

In construction, the most expensive projects are the ones a firm never sees. Somewhere right now, a bond has been filed, a site has changed hands, and the winner of a nine-figure project is already being decided, months before an RFP exists. Cascade, the AI pursuit platform for architecture, engineering and construction (AEC) firms, is changing that. Today, the company announced it has raised $3.5 million from Andreessen Horowitz Speedrun, Ada Ventures, Blitzscaling Ventures, Indico Capital, shuckerVC, G2C Ventures and Snowball VC.

The traction has come fast. In a few months, Cascade has signed AEC customers whose work spans some of the world’s most notorious projects – including JFK, LaGuardia, data centers and nuclear reactors. 

The signs arrive years before the bid

Long before an RFP, a multi million dollar project leaves traces. A bond filing is a project taking shape. A property changing hands is a developer moving. A line in a county capital plan is a building that does not exist yet, and a firm somewhere is going to win it. Cascade detects these events continuously across bond filings, permits, capital plans, property transactions, earnings transcripts, budget announcements and meeting minutes, and connects them to what they signal: where work is forming, what kind, and who is positioned to win it.

The tools the industry relies on read none of this. 

Cascade closes the gap. It anticipates projects as they form, scores each one for fit so firms pursue the work they are most likely to win, and surfaces warm paths in through relationships already sitting in Outlook and other software. Every customer makes the system sharper: each pursuit teaches it which signals matter, which firms are credible for which work, and where teaming opportunities exist.

Built by Amazon and Google operators, pulled in by the market

Cascade was founded by Hannia Zia and Joana Ferreira, two former Google operators who met at UnlikelyAI, the startup founded by the inventor of Amazon Alexa. There, Hannia served as VP of Product and Joana led the AI platform, building a knowledge graph of the world’s information and training LLM agents to navigate it.

Their route into construction was personal as much as commercial. Joana grew up in a Portuguese town built on construction and carpentry. Hannia’s father tried to start a construction business, but it failed. Hannia’s conversations with CFOs in New York produced Cascade’s first customer, Munoz Engineering, and a conference in Denver quickly brought the next. 

The funding will accelerate adoption and deepen Cascade’s network across the industry. Even building a house takes twenty companies coming together, and multimillion-dollar projects take an order of magnitude more. As more firms join, Cascade matches them to each other: partners to bid with, connections in new regions, teaming opportunities across the US. The platform gets stronger with every firm that joins, and so does every firm on it.

The team’s overall ambition runs the full arc of a project. Cascade intends to be there at the first trace of work forming, through the pursuit, the win and the build, until the day of handoff.

Teleport Establishes Agent Trust with New Identity Security Capabilities

Posted in Commentary with tags on July 21, 2026 by itnerd

Teleport today announced that it has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. Together, these capabilities give enterprises a foundational harness for identifying and preventing agent misalignment as autonomous agents take on greater responsibility inside production infrastructure.

The announcement follows Teleport’s recent white paper, From Zero Trust to Agent Trust, which argues that zero trust is necessary but insufficient to govern agents operating at scale. The paper extends the three core principles of zero trust into three corresponding principles of agent trust:

  • Verify explicitly → Enforce continuously.
    Agents need a unique, attestable identity and must operate inside a trusted runtime that architecturally enforces their operational, execution, and communication boundaries.
  • Use least privileged access → Bound collective autonomy.
    Individually authorized actions can still be collectively destructive when taken by a swarm of agents acting in parallel. Bounding collective autonomy means actions that are safe individually but risky in aggregate require escalation before they execute.
  • Assume breach → Assume misalignment.
    Agents can drift from their original objective through adversarial manipulation or through unintentional causes, like context shift over time. Enterprises must continuously monitor for that drift and be able to intervene in real time. Teleport’s new capabilities are delivered through Beams, Teleport’s trusted runtime for agents, working in concert with its Identity Security platform, now extended to address agentic behavior:
  • Beams Session Summaries are a summary of an AI agent’s actions: its identity, privileges, tool and API calls, LLM prompts, responses, and reasoning digested into a short human readable summary of what it was doing and what it was thinking. This establishes a behavioral baseline for evaluating agent activity against its declared objective.
  • Agentic Classifiers provide policy for humans, agents or groups of agents to be evaluated against company specific criteria, enabling agent behavior to be flagged that is inconsistent with an agent’s declared objective.
  • Risk Scoring automatically summarizes SSH, Kubernetes, and database sessions, classifies them by risk level and maps actions to the MITRE ATT&CK framework. Infrastructure and Security teams can now automate or manually search across sessions for specific commands, resources, or behaviors.
    Together, these three capabilities in concert with Beams lay the foundation for the agent trust principles: they give agents a cryptographic, continuously monitored identity; they make collective and individual risk visible before action is taken; and they give enterprises the tooling to detect and respond to misalignment as it happens, turning “assume misalignment” from a design principle into a running practice.

Availability

Teleport will preview these capabilities at Black Hat USA 2026 (August 4–6, Mandalay Bay, Las Vegas) at booth #5114. The capabilities will be available for hands-on customer experience this fall. Customers can request to join the technology preview here.

For a deeper discussion on the new Identity Security capabilities, read the blog.

Deepgram Delivers Real-Time Voice AI at the Edge for Use with Snapdragon

Posted in Commentary with tags on July 21, 2026 by itnerd

Deepgram today announced an initiative to bring enterprise-grade speech recognition directly onto PCs powered by Snapdragon® processors. By optimizing Deepgram’s Nova-3 speech-to-text model on the Qualcomm® Hexagon™ NPU in the Snapdragon X Series platform, Deepgram is enabling developers and device manufacturers to deliver real-time voice experiences with greater speed, privacy, and reliability, without relying on a cloud connection. This effort opens the door to further integration of voice into a new generation of intelligent applications across automotive, mobile, AI PC, XR, industrial edge, IoT, and wearable devices.

Many voice AI solutions have historically relied on a cloud-based architecture. Before a response could be delivered, each interaction required audio to leave the device, travel to the cloud, be processed somewhere else, and then return. With this approach, delays and privacy concerns are sometimes introduced, which limit where voice AI can realistically be deployed. Deepgram is fundamentally changing that model, enabling speech recognition to happen directly on the device itself. The result is an entirely new world of applications and user experiences that feel like a natural conversation, whether it is running in a vehicle, on an AI PC, inside an XR headset, or at the edge of a network where connectivity cannot be guaranteed.

Nova-3 advances Deepgram’s industry-leading accuracy, extending its capabilities to a broader range of real-world enterprise use cases and challenging audio conditions. It is the first voice AI model to offer real-time multilingual transcription. Deepgram is also the first to provide users with demonstrably effective and highly accurate self-serve customization – enabling instant vocabulary adaptation without model retraining. Superior accuracy: Nova-3 leads transcription accuracy with a 6.89% word error rate on real-world production audio, a 24.7% lower error rate than the next-best competitor.

To learn more, please visit: https://deepgram.com/partners/qualcomm.

Did BTS star j-hope just give fans a first look at Samsung’s next foldable?

Posted in Commentary with tags on July 21, 2026 by itnerd

Samsung has already confirmed that new Galaxy devices are on the way later this week. But some BTS fans think they might have spotted one in the wild already.

Videos from a BTS sound check in Paris are fueling speculation, as j-hope is seen using what appears to be an unreleased Samsung smartphone. Samsung hasn’t confirmed any product details, but that hasn’t stopped tech enthusiasts from dissecting the device’s size and shape, wondering whether the clips offer a first look at what’s coming next.

If you haven’t seen the videos yet, you can check them out here and here.

Black Kite’s 2026 Ransomware Report: Ransomware Accelerates 60% in Six Months and Shows No Signs of Slowing as New Ransomware Groups Emerge Weekly

Posted in Commentary with tags on July 21, 2026 by itnerd

Black Kite today released its newest report, 2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record, examining how ransomware is evolving, who is being targeted, and the externally visible risk signals organizations exhibited before they became publicly disclosed ransomware victims.

Black Kite identified 7,551 publicly disclosed ransomware victims between April 1, 2025 and March 31, 2026, up 24.9% over the previous reporting period. But the annual figure hides a sharper trend: after tracking close to the prior year’s pace through the first half of the reporting period, ransomware victim counts accelerated 60% in the second half, closing with 861 victims in March 2026 – the highest monthly total in four years.

The report identified three key trends that defined this year’s ransomware landscape:

  • Expansion at the bottom: More than 60 new groups entered during the reporting period, more than one per week, bringing the total to 146 active groups by June 2026.
  • Concentration at the top: Despite the influx of new entrants, the five largest actors still controlled 43.6% of all victims. Qilin alone claimed 1,300+ victims, nearly twice as many as its nearest rival.
  • Acceleration in the second half: While the first half tracked close to the prior year baseline, the second half outpaced it by 60%, closing with 861 victims in March 2026, the highest monthly total in four years of tracking.

Many of the year’s most consequential attacks moved through trusted vendor platforms, including SaaS integrations, enterprise applications, OAuth connections, and support workflows.

Black Kite’s before-and-after security posture comparison also found that exposure often remained after incidents were disclosed: stealer log exposure increased 175%, while 43.5% of victims still carried critical vulnerabilities in the latest assessment.

The report concludes that AI did not redefine ransomware during the reporting period. Instead, it lowered the cost of the work around the attack by making reconnaissance faster, phishing and vishing more convincing, victim research more scalable, scripts cleaner, translation easier, and extortion messaging cheaper to produce. While AI did not create this year’s acceleration, it lowered the barrier to entry enough that more actors could participate, suggesting ransomware operations could be scaling in anticipation of what comes next: AI-accelerated vulnerability discovery, faster exploitation cycles, and social engineering at scale.

Key findings from the report:

  • 7,551 publicly disclosed ransomware victims identified, up 24.9% year over year.
  • 60% acceleration in ransomware activity during the second half of the reporting period.
  • 146 active groups by June 2026, including 61 new groups entering during the reporting period.
  • Qilin claimed more than 1,300 victims, nearly two-times as many as its nearest rival.
  • 43.5% of victims still carried critical patch vulnerabilities in the latest assessment, 30.8% carried KEV exposure, and 18.5% carried FocusTag® signals.
  • 175% higher stealer log exposure in the before and after security posture comparison.
  • Oracle E-Business Suite (EBS) and Salesforce ecosystem integrations defined several of the year’s most visible supply chain incidents.

The report recommends prioritizing vulnerabilities known to be exploited in the wild, extending third-party cyber risk management beyond questionnaire-based assessments, and hardening the human layer against vishing and help desk impersonation. The report also recommends strengthening identity verification, help desk escalation paths, employee reporting, vendor verification, and executive impersonation controls.

To read the report, visit https://blackkite.com/reports/2026-ransomware-report/.

To learn how Black Kite’s Ransomware Susceptibility Index (RSI™) provides early warning of ransomware risk and helps organizations proactively identify susceptible third parties, visit https://blackkite.com/platform/ransomware-susceptibility-index

Methodology

The report covers the period from April 1, 2025 through March 31, 2026. The primary dataset includes 7,551 publicly disclosed ransomware victims identified through leak site monitoring and validated by the Black Kite Research Group™. Before and after security postures, current state exposure analysis, and post-period April-June 2026 activity are treated as separate scopes. Post-period data is used as supplementary context and excluded from primary year over year calculations.