Archive for July, 2026

Compromised npm packages are using blockchain transactions to hide their command-and-control 

Posted in Commentary with tags on July 29, 2026 by itnerd

Security firm Socket found that two Joyfill npm packages were compromised to deliver a remote access trojan that harvests browser data, crypto wallets, and Git and GitHub CLI credentials from developer machines. The malware resolves its command-and-control by chaining transactions across three separate blockchain networks, with a backup path to a hardcoded IP if that fails, letting the operators swap out their real infrastructure any time without ever republishing the malicious package.

Socket posted a write up about this here: Two Joyfill npm Beta Releases Compromised to Deliver DEV#POP…

Roman Sannikov, Global Research Coordinator, iCOUNTER

“The part of this that actually got my attention is the command-and-control setup. Chaining together transactions across three separate blockchain networks, with a fallback process that pulls a boot payload straight from a hardcoded IP if the primary chain fails, gives the operators a way to swap out their real payload infrastructure any time they want, without ever having to touch the npm package again. Persistence is really the whole game for a threat actor once they’re in, and this is one of the more ingenious ways I’ve seen someone build that in from day one. The credential harvesting tells the same story. Browser data, crypto wallet extensions, Git and GitHub CLI credentials, VS Code storage, basically anything a developer machine touches, that breadth isn’t what you build if you’re just trying to grab a batch of credentials to sell quickly. It’s what you build if you’re planning to operate inside these environments for a while. What I’d flag for defenders is that Socket still hasn’t nailed down how the packages got compromised in the first place, workstation, repo, CI pipeline, or stolen publishing credentials are all still open questions, and that answer is going to matter more than the malware itself, because it tells you where the next one comes from.”

Besides nailing down how these packages got compromised is an important step. But as a matter of course, software vendors of all sorts need to know what’s in their software and where it came from as well as be accountable for that by a third party. That is when we will see real change.

Guest Post – The great AI disconnect: New data reveals friction between AI policy and employee reality

Posted in Commentary with tags on July 29, 2026 by itnerd

Organisations are pouring investment into AI. But new data from the SAP Concur annual Global Business Travel Survey reveals that nearly three-quarters (70%) of Canadian business travellers have or would make use of unapproved AI tools, also known as ‘shadow AI’ for business travel.

The survey’s findings provide insight into how business travellers are using AI, where a lack of official tools leaves companies missing out, and what employers can learn from this disconnect.

Which business travellers are using shadow AI
Why do travellers turn to shadow AI? For 38% of respondents, it’s a matter of preference. They favour different tools over their company’s approved options. For another 32%, it’s about availability: their employers do not offer any AI tools for planning or booking travel. 

Demographics and work arrangements play a big role in who relies on unauthorised tools. Consideration steadily declines by generation: while more than three-quarters of Gen Z (79%) and Millennial (76%) travellers are open to using shadow AI, this falls 62% for Gen X and 49% for Boomers.

Workplace flexibility is another key differentiator, with remote workers (81%) saying they would turn to unapproved AI tools significantly more often than fully on-site employees (71%).

Whether employees travel for business internationally seems to make a difference, too. 75% of those who travel internationally have or would use shadow AI tools, compared to 63% of domestic travellers. 


The main ways travellers use AI-powered tools

Three-quarters of travellers (70%) say they have used AI-powered tools to support elements of business travel. The most popular use cases they report include planning their trip agenda (29%), tracking expenses during the trip (24%), and assessing the risks of the trip (20%).

Around a fifth (18%) use AI tools to rebook or make changes to their trip, as well as curate travel options during booking. A similar percentage (18%) use them to complete their expense report after the trip.


The shadow AI risk

These findings tell a cautionary tale: if there’s a gap between the AI tools employees want to use and what’s on offer, they’re likely to source their own alternatives.

“It’s a huge worry for business leaders. 96% of CFOs say they’re concerned by shadow AI in business travel”, says Brian Veloso, Managing Director at SAP Concur Canada. “As consumer AI tools proliferate, they open the door for employees to use unsanctioned systems for booking or planning business travel. Unfortunately, this shadow AI can create security risks, particularly when employees input sensitive data or connect business systems to unauthorised software. Leaders must educate workers on the risks and provide T&E tools that deliver the desired level of AI support.”


The AI features travellers really want

One way for businesses to keep AI usage on track is to understand how employees want to use AI in travel – and provide tools that suit those needs.

When asked, 38% of employees said they want AI integrations in other parts of the workflow (e.g. PowerPoint and their calendar). One in three employees (26%) said they would like AI embedded specifically into communication software (e.g. Teams, Slack), and another 26% want proactive AI that notifies them to book through push alerts or reminders.

Around a quarter of employees (22%) want chatbot interfaces within current booking tools, while 23% would like integrations in role-specific tools (e.g. CRM).

AI is already out on the road with business travellers. Now, it’s up to leaders to ensure corporate governance by offering approved, AI-powered tools that deliver what travellers actually want.

FCC proposal could force tech suppliers into equipment authorization rules

Posted in Commentary with tags on July 29, 2026 by itnerd

The FCC is considering a major expansion of its “Equipment Authorization Program” that could draw software developers, firmware providers, design houses and other technology suppliers into the agency’s regulatory system for the first time.

Under a Third Further Notice of Proposed Rulemaking adopted July 22, applicants could be required to submit signed hardware and software bills of materials (SBOMs) covering the hardware, software and firmware in a device. The disclosure would be required to identify: the  component producer, where components were designed, developed or manufactured, and the percentage of component value associated with each production location. Grantees could also be required to update the information within 30 days of material changes.

Because the FCC’s proposed definition of production includes design and development, the information may need to be collected from suppliers far removed from the company filing the application, including design houses and IP licensors with no direct relationship to that applicant.

Eric Greenwald, General Counsel, Finite State had this comment:

   “The FCC’s proposal would turn equipment authorization from a product review into a supply-chain transparency exercise. Applicants would file a signed HBOM and SBOM covering every component, including hardware, software and firmware, along with information about each component’s producer, place of production and share of value.

   “The applicant would be responsible for the filing, but the information would have to be collected from dozens of suppliers, including design houses and IP licensors with no direct relationship to the filer. That process would be onerous, and the results would not necessarily be reliable. Anyone submitting an application for FCC certification will need a way to verify independently what is actually in the device, down to the firmware.”

This is a good start, but this needs to be enforced strictly. Only then will we see meaningful changes.

UPDATE: Justin Beals, CEO & Founder of Strike Graph, an AI-native GRC and compliance automation platform adds this comment:

“Updated SBOM guidance is necessary, but guidance isn’t the hard part—verification is. Plenty of organizations can produce an SBOM document. Far fewer can prove the components listed in it are still accurate six months later, or that a control mapped to a framework requirement is actually being enforced in production.

This is the same gap we see across CMMC, FedRAMP, and every other framework leaning on SBOMs right now: a static list, filed once, treated as proof of ongoing security. It isn’t. It’s a snapshot.

The organizations that get ahead of this will be the ones building continuous validation into their SBOM process—not just generating the document to check a box, but proving its contents stay true over time. That’s the difference between attestation and evidence.”

Fortra Announces Expansion of Cloud Email Protection to Europ

Posted in Commentary with tags on July 29, 2026 by itnerd

Fortra today announced the expansion of its transformative Cloud Email Protection solution into Europe, enabling organizations to defend against advanced email threats while meeting European Union data residency requirements. 

Purpose-built for modern cloud environments, Fortra’s Cloud Email Protection stops threats that bypass traditional defenses using a combination of AI-powered detection, global threat intelligence from the Fortra platform, and automated remediation. As one of the industry’s early cloud-native email security platforms, Cloud Email Protection was created with machine learning and AI models as its core, helping organizations simplify and scale email protection while stopping threats like business email compromise, spear phishing, and targeted social engineering.   

Organizations across Europe increasingly require security solutions that allow sensitive email data to remain within European jurisdictions. Fortra’s European deployment in ISO27001/SOC2 datacenters enables customers to keep their data in-region, supporting local compliance requirements while maintaining enterprise-grade protection. 

Built with privacy-by-design principles, the platform minimizes the collection of personal information while protecting email communications through layered security controls including encryption, access management, and comprehensive auditing.   

Customers retain control of their data while benefiting from enterprise email security. Administrative access, data handling practices, and regional hosting support organizations’ strict sovereignty requirements.  

Learn more about the market’s most comprehensive cybersecurity platform at fortra.com

Road Trips, Remote Destinations and Reliable Connectivity Top Summer Travel Priorities Says Rogers

Posted in Commentary with tags on July 29, 2026 by itnerd

From road trips and cottage weekends to camping and backcountry escapes, most Canadians are embracing closer-to-home travel this summer. And according to a new survey, not being able to contact someone in an emergency is a trip dealbreaker for many.

The new Rogers survey, conducted using the Angus Reid Forum, found that three-quarters of Canadians said they planned to travel within Canada rather than far-away destinations. Among these travellers, road trips top the list with two-thirds saying they plan to hop into the car for their summer adventure. About four in 10 Canadian travellers plan to go to remote or off-the-grid areas.

But even as some travellers look to unplug, eight in 10 say they still expect connectivity when it matters. Not being able to contact someone in an emergency is a dealbreaker for trips for two-thirds of travellers.

Maps, Weather and Emergencies Matter Most

The survey found staying connected to practical tools tops entertainment and social media, with maps and navigation ranked as the most important (78%), followed by texting and messaging (62%), emergency services (60%), phone calls (55%) and weather apps (55%).

With Rogers Satellite, a first of its kind satellite-to-mobile service in Canada, travellers can use text-to-911 services as well as satellite-ready apps including WhatsApp, Messenger, Google Maps, X and AccuWeather in areas outside of traditional cellular coverage.

Connectivity Is Shaping Domestic Travel Decisions

Only 18 per cent of the country is covered by traditional wireless networks, including stretches of highways. Rogers Satellite helps give Canadians an extra layer of connectivity beyond the reach of these networks.

When travellers think about travelling to areas outside traditional cell coverage, connectivity is increasingly part of the plan:

  • 49% say reliable connectivity would make them more likely to explore remote destinations
  • 65% expect basic, reliable connectivity for calls, texts and navigation when travelling in rural or remote areas
  • 85% say reliable connectivity would make them feel safer in remote areas

To see where Rogers Satellite connectivity is available and to learn more about getting Rogers Satellite for $0 with new Rogers 5G+ mobile plans, visit rogers.com/satellite.

About the Survey 

The online survey was conducted by Rogers using Angus Reid Forum between June 17 and June 23, 2026, among 1,015 Canadians planning to travel within Canada during summer 2026. The survey was conducted nationally in English and French.  

Hacker mistake reveals ongoing attack on semiconductor company

Posted in Commentary with tags on July 29, 2026 by itnerd

Cybernews researchers uncovered an active ransomware campaign against multinational semiconductor company V-Silicon after discovering an exposed hacker server.

Here’s a timeline of the findings:

  1. Cybernews researchers discovered an exposed web directory that functioned as a staging server for a ransomware attack.
  2. A subsequent investigation linked the discovered infrastructure to an attack against V-Silicon, a multinational semiconductor company that develops chips used in smart TVs and display devices.
  3. The campaign was attributed to INC Ransomware, a ransomware-as-a-service (RaaS) operation that has been active since 2023.
  4. We alerted V-Silicon to the exposed data on July 17th. 
  5. One day later, the INC ransomware group published V-Silicon on its leak site, claiming responsibility for the attack.

What was found on the internal hacker server?

  • “The artifacts found on the exposed server indicate that during network enumeration, third-party infrastructure and data could have also been compromised”, Cybernews researchers explain.
  • The ransomware was built to run on a wide range of computer systems, suggesting that the attackers may have intended to encrypt embedded controllers, industrial systems, or older semiconductor manufacturing equipment.
  • Researchers noticed coding patterns that suggest some scripts may have been generated with AI.

For more information, here’s the full report: 

https://cybernews.com/security/hackers-exposed-ransomware-attack-v-silicon

Cybercrime victims lose an estimated $1.24 trillion a year 

Posted in Commentary with tags on July 29, 2026 by itnerd

Comparitech researchers have published an update to their 2023 study on the cost of cybercrime globally. The new study sees a significant increase in the annual estimated monetary impact of cybercrime — now at $1.24 trillion versus 2023’s figure of $714 billion. 

Key findings include: 

  • 103.9 million people fall victim to cybercrimes globally each year, or more than 1,577 victims per 100,000 people
  • The average victim loss is $9,468 per crime
  • Victims lose an estimated $1.24 trillion to cybercrime annually
  • The United States showed the biggest estimated losses at 6.7 million victims losing an estimated $138.9 billion

For full details, click here.

SIOS Technology Announces LifeKeeper v10.1 with AIOps-Ready Automation

Posted in Commentary with tags on July 29, 2026 by itnerd

SIOS Technology Corp today announced the availability of LifeKeeper v10.1. The latest release introduces AIOps-ready automation capabilities that help organizations streamline the deployment and management of HA/DR environments while strengthening cloud security and expanding support for modern enterprise infrastructures. LifeKeeper v10.1 includes a new Windows command-line interface for automated cluster management, support for Microsoft SQL Server 2025, and enhanced integrations for AWS and Oracle Cloud Infrastructure (OCI).

New in SIOS LifeKeeper v10.1:

Streamlined Operations & Deployment

  • Consistent deployment Automation via new Windows LKCLI interface: The introduction of this robust Interface for Windows, gives IT teams the ability to fully deploy, operate, and script multiple LifeKeeper clusters in a consistent, highly automated manner. By supporting JSON output and direct API key management, this update also establishes a standardized, machine-readable foundation for future AI-driven operations (AIOps).
  • Centralized Log Viewing and Enhanced Web GUI: The updated Web GUI (LKWMC) introduces direct log viewing for faster troubleshooting, supports multitarget mirror management, displays cluster-wide licenses, and adds German and Korean localization.
  • Scriptless Resource Creation for HULFT: The new HULFT Recovery Kit eliminates manual scripting.

Enterprise Databases & Multi-Cloud Infrastructure Support

  • Broader Enterprise Database Compatibility: This release expands infrastructure flexibility by introducing support for the enterprise-grade SLES 16 platform. For Windows environments, the update delivers fully validated, out-of-the box high availability protection for Microsoft SQL Server 2025.
  • Advanced Database Protection for Oracle: The new SIOS Oracle Recovery Kit allows enterprises to protect complex, multi-instance database topologies and to dramatically simplify routine maintenance through support for listener resources and multiple System Identifiers (SIDs and protection for the Oracle Vss Writer service.
  • Improved Cybersecurity in OCI and AWS through native support for Oracle Cloud Infrastructure IMDSv2, complete with built-in retry logic to mitigate transient access failures provide support for complex, multi-VPC topologies in Amazon Web Services (AWS): LifeKeeper v10.1 enables unique AWS Profiles to be assigned to individual Recovery Kits for enhanced deployment flexibility. This release also enhances Route 53 resource handling across identical public/private hosted zones and updates the AWS Transit Gateway integration to seamlessly support complex, multi-VPC topologies.

Availability

SIOS LifeKeeper version 10.1 is now available.

MIND Announces AI DLP Agents for Autonomous Data Security

Posted in Commentary with tags on July 29, 2026 by itnerd

MIND today announced MIND AI DLP Agents with capabilities focused on classification, investigation, policies, remediation and exception management. It also includes a Model Context Protocol (MCP) interface that enables security teams to direct data security work through any MCP-connected client using natural language.

AI has fundamentally changed the speed and scale at which sensitive data moves. GenAI applications, Agentic AI and autonomous workflows create and move data faster than security teams can manually govern it. Yet many data security teams report spending the bulk of their time on building classifiers, investigating issues, tuning policies, monitoring exceptions and remediating exposure.

Data now moves with unprecedented speed. Data security must as well.

Instead of requiring security teams to operate DLP day-to-day, the MIND AI DLP Agents perform the work that has traditionally consumed data security programs. They work alongside security teams as a force multiplier, increasing their effectiveness and scalability while freeing them to focus on reducing risk and enabling both business and innovation.

The MIND AI DLP Agents specialize in the most time-consuming work our customers identified:

  • Custom Classifier Agent automatically builds business-specific data classifiers at both the document and data-specific level, consults a judge for false-positives and self-improves.
  • Policy Producer Agent suggests, creates and continuously refines policies from observed behavior and natural language instructions.
  • Issue Investigator Agent analyzes incidents, uncovers patterns, explains risk and suggests remediation actions
  • Rapid Response Agent executes remediation actions and escalates when human approval is required.
  • Reason Reviewer Agent evaluates user override justifications against organizational policy guidance in real time.

MIND also introduced an MCP interface that will make the AI DLP Agents available through MCP-compatible AI clients. Security teams can assign work in plain language, request investigations, draft policies and initiate remediation workflows without navigating multiple consoles or manually performing repetitive operational tasks. By combining conversational workflows with MIND’s automation and context-aware data security platform, organizations will be able to operate data security with greater speed, consistency and scale.

Organizations using MIND report an 80% reduction in DLP program effort, near-zero false positives and 50 percent less investigation time per incident. Customers also report deploying the solution in minutes, taking specific action to lower data security risk within a few hours and operating at scale without operational disruption.
MIND is also the first data security company to achieve ISO/IEC 42001 certification for responsible AI and to be accepted into Anthropic’s Cyber Verification Program.

Attendees of Black Hat USA 2026 can see live demonstrations at the MIND booth #4527.

Freehand Raises $75M to Scale AI Teams Managing Supply Chain Spend for Fortune 500 Companies

Posted in Commentary with tags on July 29, 2026 by itnerd

Freehand, whose AI agents manage supply-chain spend for Fortune 500 enterprises, today announced $75 million in funding co-led by Battery Ventures and NewRoad Capital Partners, with participation from former U.S. Commerce Secretary Penny Pritzker’s venture capital PSP Growth, Nexus Venture Partners and others. 

American companies spend more than $20 trillion a year on the raw materials, logistics, data centers and services that power the U.S. economy, according to the Bureau of Economic Analysis. For decades, supply chain spend has been managed on legacy software and armies of outsourced labor. Freehand replaces this machinery with autonomous AI Teams that make decisions and take action to negotiate rates, enforce contracts, manage suppliers, process payments, and reconcile data within enterprise systems.

This financing round follows Freehand’s recent emergence from stealth with global deployments at Meta, Unilever, Johnson & Johnson, Pfizer, Dunkin’ and Cardinal Health, as tariffs, taxes and immigration policies put increasing strain on the outsourcing model that has historically run global supply chains. Across early deployments, customers have recovered 5-10% of spend in complex categories, completed workflows 5–7x faster, and reduced procure-to-pay cycles by more than 70. As a result, organizations are redeploying their employees to higher-value work while reducing traditional outsourcing and BPO contracts.

Freehand solves one problem exceptionally well: replacing the outsourced labor and legacy software used to audit and pay invoices across the supply chain. Its AI agents run the entire workflow – reading contracts, negotiating with suppliers, identifying leakage, processing payments and closing the loop with procurement – replacing outsourced teams and legacy tools that cost organizations tens of millions a year. 

Freehand’s central IP is its Category Context Graph, which captures every decision, transaction and exception across a spend category. By unifying the unstructured data buried in documents and communication channels with the structured data in enterprise systems, it gives the agents the situational knowledge of a tenured supply-chain expert, along with an audit trail explaining every decision. Every AI agent Freehand deploys is built on and continuously enriches the graph, creating a compounding intelligence effect where each decision improves the accuracy, context autonomy of the next.