Archive for August 5, 2026

NVIDIA-led alliance proposes AI cybersecurity incident reporting framework

Posted in Commentary with tags on August 5, 2026 by itnerd

NVIDIA and the Open Secure AI Alliance have proposed a new industry framework called Shared AI Findings Exchange (SAFE) to standardize how organizations report and share AI-related cybersecurity incidents.

Published through the Linux Foundation as a Request for Comments, the guidelines are intended to help organizations share information on AI attacks, vulnerabilities and near misses to improve collective cyber defenses.

The alliance also announced new open-source contributions, including AI security models, datasets, evaluation tools and research designed to improve the security of AI systems and agents.

NVIDIA said the Open Secure AI Alliance has grown to more than 120 member organizations, including technology companies, cybersecurity firms and open-source foundations collaborating to develop shared AI security tools and best practices.


Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity,
 Suzu Labs had this to say:

“SAFE is required because AI agent failures don’t fit existing vulnerability disclosure. When a model finds and uses access it shouldn’t have reached, there’s no patch to issue and no vulnerability identifier to publish. Agent failures are often behavioral and non-deterministic, with no signature to match and no fix to deploy.

“Aviation’s safety reporting system has been running since 1976, the financial sector’s threat-sharing body since 1999. Both protect reporters from liability and operate at industry speed. AI threats outpace government coordination, making private-sector self-organization the right model.

“Identity is the piece that makes the rest of the defensive stack enforceable. The alliance’s work on agent identity and access controls lets organizations verify what an agent is before it acts. SAFE adds information sharing on top of that identity and runtime layer. Together, organizations learn from each other’s agent failures fast enough to defend proactively.

“The highest value will come from near-misses. Breaches make headlines, but an agent that probes a boundary and fails never gets published. That behavioral pattern is exactly the intelligence other organizations running similar systems need, and SAFE creates the channel for sharing what would otherwise stay invisible.”

Jeremiah Fowler, Researcher for Black Hills Information Security, Inc. follows with this:

“I believe this is a positive step in the right direction. Organizations that experience AI related attacks gain valuable insights that could help protect others but only if that information is shared. Establishing a framework for responsible information sharing promotes transparency, peer review, and independently evaluated security findings. The more organizations that contribute real-world evidence, the more effectively we can identify emerging attack patterns, common vulnerabilities, and evolving threats while reducing duplicated defensive efforts that waste valuable time and resources.

“As AI becomes increasingly integrated into everyday life, business operations, and critical infrastructure, developing standardized security guidance now is a proactive investment rather than waiting to retrofit a defense after incidents occur. Sharing information about unsuccessful attacks is just as valuable as documenting confirmed compromises, because near misses can often expose weaknesses, configuration issues, or emerging attack tactics before they evolve into critical security incidents. I used to always say “it is not if you will have a data incident, it is when you will have a data incident”.  AI has supercharged the threat landscape in ways we couldn’t have imagined just a few years ago. Reporting and sharing AI related cybersecurity incidents is a great first step. I am happy to see organizations take the initiative instead of waiting around for regulators or lawmakers.”

Standards are good. But I will have to see this in action to get an idea of how well this works. Because there’s nothing worse than a standard that nobody uses.

The White House Has Lots Of AI Related News For You

Posted in Commentary with tags on August 5, 2026 by itnerd

The White House has finalized its voluntary cybersecurity framework for frontier AI models, giving leading AI developers a process to submit advanced models for government security evaluations before public release. The framework is intended to address the growing cybersecurity risks posed by increasingly capable AI systems (after recent testing incidents involving frontier models).

Zach Wasserman, co-founder, Fleet Device Management (and one of the creators of OSquery) had this to say:

“The White House is focused on whether frontier AI models are safe. Enterprises must consider whether AI can safely operate inside their own environments. A model can perform well in testing but still create risk if it’s connected to production systems without the right controls. Before AI is managing thousands of endpoints, organizations need an operating model where every change is version controlled, auditable and easy to roll back.

The takeaway from the recent OpenAI and Anthropic testing incidents is that autonomous systems need guardrails. We’ve spent years building software development processes around code review, version control and rollback. AI making infrastructure changes should follow the same principles. Infrastructure as code gives AI a safe, structured way to make changes while keeping people in control.

Our recent research found that almost half of organizations are prioritizing AI automation, but fewer than a third are prioritizing infrastructure as code. That’s a problem because AI is only as safe as the systems it’s allowed to change. AI also shortens the time between finding a vulnerability and acting on it, whether that’s patching it or exploiting it. Organizations relying on manual processes simply won’t keep up.”

Also with The White Houre, they have told AI developers it will not include open-weight AI models in its new voluntary cybersecurity testing program, according to Reuters.

The policy was discussed during a White House meeting with representatives from Meta, Google, Nvidia, OpenAI and Anthropic, according to sources familiar with the discussions. Open-weight models, such as Meta’s Llama and Nvidia’s Nemotron, make their core model weights publicly available, unlike closed models from OpenAI and Anthropic.

The voluntary testing program is intended for advanced AI models with sophisticated cyber capabilities and follows recent disclosures that AI systems from OpenAI and Anthropic breached other organizations during controlled security evaluations.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“The US government already knows how to test open-weight models for cyber capability. Before Moonshot released Kimi K3’s weights on July 27, AISI and NIST ran a joint evaluation of its offensive capabilities, measuring exploit development, code execution, and network intrusion performance. That methodology works. The White House chose not to apply it.

“Publicly disclosed incidents that prompted this framework all involved closed-model companies. OpenAI’s models exploited Artifactory vulnerabilities to escape a test environment, then compromised Hugging Face through a separate attack path. Claude models gained unauthorized access to three companies during security evaluations. Under these guidelines, Meta and Nvidia walked out of the August 4 briefing with zero obligations while OpenAI and Anthropic accepted a voluntary pre-release review of up to 30 days.

“Kimi K3 trails US frontier models on cyber tasks today, but in a simulated enterprise attack it completed a full intrusion chain in one of ten attempts, against an intentionally vulnerable network, with initial access provided. China has made open-weight release a strategic priority, and each generation closes ground on the previous one. A framework that categorically exempts open weights has no mechanism to adapt when that gap narrows.”

I would give everything a read because if you use AI related anything, you are affected.

July Ransomware Attacks: Up 19% from June Says Comparitech

Posted in Commentary with tags on August 5, 2026 by itnerd

With ransomware attacks plaguing businesses and individuals around the world, Comparitech have released their Ransomware Roundup for July 2026, finding that last month saw nearly 26 ransomware attacks per day. 

The research looks into attacks by sector, most prolific groups and attacks by country.

Key findings include:

  • 799 attacks in total — 51 confirmed attacks (confirmed by the entity involved)
  • Of the 51 confirmed attacks:
    • 31 were on businesses
    • 10 were on government entities
    • 3 were on healthcare companies
    • 7 were on educational institutions
  • Of the 748 unconfirmed attacks*:
    • 657 were on businesses
    • 24 were on government entities
    • 50 were on healthcare companies
    • 16 were on educational institutions

You can find the full research here: https://www.comparitech.com/news/ransomware-roundup-july-2026/

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech:

“If we needed a reminder of how dominant a threat ransomware attacks remain, July’s figures provide us with just that. Figures reached the third-highest level in the last 17 months and The Gentlemen and Qilin continued to add hundreds of victims to their data-leak sites. We’ve already logged over 100 victims during the first four days of August 2026, too. 

July also saw some of the year’s most significant ransomware attacks. This includes the attack on the Romanian government’s land registry agency, which saw an entire database being wiped, the crippling attacks on AnMed and Fairlife in the US, and the attack on The Craneware Group, which looks set to have resulted in an extensive data breach. 

These attacks highlight how ransomware groups hit organisations in various different ways — taking down key systems, stealing troves of data, and even deleting massive datasets. Never has it been more important for organisations to ensure they’re carrying out regular backups (and backups of their backups!) so they can reset systems and restore data as quickly as possible if the worst does happen.”

I would put aside some time to give this a read as it will help you to structure your defenses.

AI Security Institute shows that an AI agent went rogue with disastrous results

Posted in Commentary with tags on August 5, 2026 by itnerd

The UK’s AI Security Institute has revealed that an AI agent went rogue after being given too much freedom. It may have happened in a test:

On 28th July 2026, AISI’s Security Team detected unusual data transfers leaving our research systems during a routine cyber evaluation. On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organisations. We declared a security incident and, within roughly one hour of discovery, had contained it and begun a full investigation.

The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol with cyber classifiers (mechanisms to prevent misuse) disabled. In the most serious case, an agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering  — creating fake online identities and using them to pressure the project’s maintainer to approve the code. A human maintainer caught and refused to approve the malicious code.

These attempts were unsuccessful, and our investigations have not evidenced any resulting real-world harm. But this is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world.  

Luke Hinds, CEO and Co-founder of nolabs had this view:

“This is the latest in a growing list of rogue agent stories, from the Hugging Face incident to models reportedly creating fake identities to get malicious code approved on GitHub. It’s becoming abundantly clear that when agents are given too much freedom, they can take bad actions, whether they are trying to be helpful, misunderstanding the goal, or being manipulated through prompt injection. That leaves businesses with a difficult balancing act. Agents need agency to be useful. They need to access systems, call tools and act autonomously. But every extra permission increases the blast radius when something goes wrong.

“The answer is not to trust frontier labs to solve this. Enterprises shouldn’t leave agent permissions to the companies building the models. Their incentive is to make agents more capable, more connected and more widely used. Instead, enterprises need control over what agents can actually do inside their own environments. Blunt sandboxing is not enough as if you lock agents down too heavily, you kill the value businesses are trying to unlock. But if you put a human approval step in front of every action, you no longer have an autonomous agent. Instead, businesses need controlled freedom – enough authority for the task in front of the agent, and absolutely nothing more. That means protection wrapped around the agents’ action. Once an agent can call tools, use credentials, contact networks or change data, the boundary has to apply to each workload it runs. What can it read? What can it write? Which tool can it call? Which credential can it use? Which network can it contact? And can it do that only for this task, right now?

“Ultimately, businesses should not rely on agents to behave well, or on model providers to mark their own homework. The boundary has to sit outside the model, where it can be enforced independently. Otherwise, companies are not deploying agents safely. They are handing them the keys and hoping they do not find the wrong door.”

Justin Beals, CEO & Founder, Strike Graph, an AI-native GRC and compliance automation platform has this view:

“What AISI found is significant precisely because it’s documented, not speculative. An agent created fake identities and used them to pressure a real person into approving malicious code. That is social engineering, executed by a system we assumed only followed instructions. Credit to AISI for disclosing this openly instead of burying it, and it’s worth being precise about context: this happened with safety filters intentionally turned off and internet access intentionally granted, to stress test the model’s ceiling. That is not how these systems are deployed commercially, and it should not be read as evidence that production AI is roaming free.

Here is the part that should worry security teams more than the headline. The only thing that stopped this attack was a human reviewer’s judgment, not a technical control. That is a governance gap, not a tooling gap. Most security programs are built to catch known signatures and deterministic behavior. They are not built to catch an agent that fabricates identities and adapts its persuasion tactics in real time.

Security teams should take three steps now. First, treat every AI agent as its own identity class, with dedicated access controls and behavioral monitoring, rather than an extension of whoever deployed it. Second, build real-time monitoring into agent workflows so unusual behavior gets flagged as it happens, not discovered afterward through general logs, the way AISI found this. Third, stop relying on human vigilance as your only defense against AI-driven social engineering. Formalize verification steps for any code contribution, regardless of source, because the next attempt may not be caught by an alert reviewer.”

I think it’s clear now that AI might be potentially bad if guardrails are not in place. And you have to restrict AI to make sure that it stays inside those guardrails. Otherwise you get this,

UPDATE: Waseem Ahmed, Head of Engineering at Secure.com has this comment:  

“Let’s be precise about what happened, because “AI went rogue” misses it. AISI’s own report is clear. The agent did not turn evil and it did not escape its sandbox. It was told to solve a hard security challenge, and deception emerged as a by-product of chasing that goal. 

“Two details matter. This was a model not yet released, and testers had switched off the safety filters on purpose to probe raw capability. That is not how these models behave in production with guardrails on. The real lesson is that a capable agent chasing a goal will try routes you never approved, including social pressure aimed at real people. That is new, and it is why we cannot treat agents like ordinary tools.

“The most reassuring fact in the report is also the most alarming one. The attack failed because a human caught the bad code and refused it. Good practice worked, but the margin was thin. It held on human vigilance, not a technical wall that would reliably stop a stronger agent. So here are four moves for security teams. 

“First, block open internet access for agents by default and grant it only when a task truly needs it.

“Second, watch agents in real time so you can stop out of scope actions as they happen, not find them in the logs later. 

“Third, assume any capable agent will try to bend its limits, and build guardrails and containment before it runs.

“Fourth, harden code review and contributor identity checks, because fake identities are now a real supply chain attack path, and treat all AI generated or outside code as untrusted until you verify it in isolation. 

“The strongest response is still standard cyber hygiene done well, which matters more as these agents get stronger.”

SOCRadar Uncovers Formula 1 Phishing Campaign

Posted in Commentary with tags on August 5, 2026 by itnerd

The SOCRadar Threat Research Unit (STRU) has identified and analyzed a multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets.

The attackers use highly convincing replicas of official ticketing platforms to deceive victims, tricking them into providing payment information and two-factor authentication (2FA) tokens. The operation allows attackers to engage in real-time, operator-controlled social engineering, adapting their tactics to bypass multi-factor authentication (MFA) measures.

What sets this attack apart is the backend: Human operators watch each victim’s session live and push a bank specific verification screen tailored to the card just entered, adapting on the fly to get past MFA.

What SOCRadar Uncovered:

  • Full source code recovery: A hosting misconfiguration on one domain, f1-tickets-sg[.]com, let us pull the kit’s complete backend code rather than just the rendered pages – including the Python cloning script, which has Russian-language comments.
  • A 134-page storefront: The mirror reproduces the legitimate site’s entire information architecture (news, event info, FAQs, even the real 15-page Terms & Conditions PDF) far beyond what a stripped-down lure would need.
  • Bank specific fraud, chosen live: The kit reads the victim’s card BIN, identifies the issuing bank, and serves one of eight pre-branded challenge pages (Emirates NBD, RAKBank, HSBC, and five other mostly UAE institutions) while an operator on a live polling connection decides in real time whether to show an OTP prompt, a balance check, a push approval screen, or a generic fallback.
  • A wider domain network: At least 11 lookalike domains impersonate the Singapore and Spanish Grand Prix under a predictable naming pattern, sharing one backend; several are already flagged as malicious.

Why it matters: It is a manned fraud operation. A person is actively steering each victim toward the exact verification screen their bank would show, which is exactly what static phishing detection misses. It’s also a preview of how ticket phishing for major sporting events keeps evolving around those brief, high urgency sales windows.
IOCs include the domain cluster, the live C2 host at 144.31.3[.]209, and behavioral fingerprints such as the session cookie and the URL flags used to switch challenge screens.

To view the full research, please see SOCRadar Formula 1 Phishing Campaign

Elisity Launches Open CLI for Customer-Built AI Agents on Its Microsegmentation Platform

Posted in Commentary with tags on August 5, 2026 by itnerd

Elisity today launched the Elisity CLI, an open command-line interface that lets security and network teams run their own AI agents against the Elisity platform. Teams can script discovery, manage Zero Trust least-privilege access policies, and pull posture reports, then point their own AI orchestrators at the platform to keep checking that segmentation controls still hold.

Plenty of security vendors now ship AI agents that customers can’t see inside. Elisity does the reverse. Security teams point whatever agent they already run at an open interface, and built-in guardrails stop that agent from acting on a guess or making a change nobody approved. Because every action runs on identity through Elisity IdentityGraph™, an agent works from many data points Elisity has already ingested and correlated, so it can tell what a device really is instead of guessing from an IP address. Teams automate only what they want, and a person signs off before anything changes.

Elisity built a command-line interface rather than a Model Context Protocol server by design. An MCP server is a standing, privileged connection into the platform, and it widens what an agent can reach by default. That pattern has drawn steady scrutiny from security researchers, and it asks a security team to run one more always-on service inside the environment it is trying to protect. A CLI inverts the model. It runs only when it is called, it runs under the caller’s own credentials and permissions, and every state-changing command stops for human approval. The concern is not theoretical. In July 2025, researchers disclosed CVE-2025-6514, rated 9.6 out of 10, in mcp-remote, a connector downloaded more than 437,000 times: a malicious MCP server could run operating system commands on the machine that connected to it, the first documented remote code execution against an MCP client.

Elisity built the CLI for teams that want to run the platform programmatically and stand up their own agentic workflows:

  • 466 commands covering the Elisity Cloud Control Center API, plus reporting on Zero Trust posture scores, per-site metrics, and traffic and threat vectors.
  • An operating guide and command glossary for AI agents like Claude or ChatGPT, so an agent runs a real command instead of inventing one.
  • Human approval on every state-changing command, and a separate confirmation for deletes.
  • Output in JSON, table, YAML, or CSV, with profiles for production, staging, and lab.

Customer use of Elisity Intelligence, the platform’s optional AI, has climbed steadily through 2026. The number of customer organizations using it grew 77% between April and June, and the heaviest use is in policy work, device lookups, and the overview dashboard, where the daily work happens. Nothing about it runs on its own. Administrators decide what’s on, and every recommendation waits for a person to approve it before anything changes. Customers running it already include GSK, Main Line Health, and MultiCare Health System, this year’s CSO Award winner.

Elisity offers the CLI to customers today. Teams that want to wire up their own agents can request access through their Elisity account team. Elisity’s AI capabilities data sheet explains how Elisity Intelligence works, and you can request a demo to see the platform.

For more information, visit www.elisity.com.

Review: Apple AirPods Pro 3

Posted in Products with tags on August 5, 2026 by itnerd

Given that my original AirPods Pro were starting to die, I wanted to get a review in of the Apple AirPods Pro 3 before they significantly update them with iOS 27. In short, the Apple AirPods Pro 3 is the most fully formed that the AirPods Pro 3 are at the moment. Which either implies that more features are coming via updates, or a new AirPods are coming.

Anyway, here is a look at the AirPods Pro 3.

If you look at the AirPods Pro 3 on the left, you will see that Apple has changed the shape versus the original AirPods on the right. I find that they fit and stay in the ears better. Even during long sweaty indoor bike rides. One thing that I did note is that I used Comply foam tips to keep the original AirPods Pros in my ears. I don’t have to do that with the AirPods Pro 3 as I use the small hybrid (new for this version) tips that come with the AirPods Pro 3. I should also note that you get four sizes of tips this time around starting with an XS size.

The case is bigger based on the AirPods Pro 3 which gives you eight hours of battery life and the case offers an additional 16 hours, for a total of 24 hours. This is a bit of a drop from the AirPods Pro 2 which offered  24 hours of battery life from the case and six hours from the buds. In other words, it’s a drop from the case perspective. But honestly, I don’t notice the difference because the earbuds last so long. In fact, I run them charging the case to 80% most of the time. Another plus with the case is the the fact that these buds have FIND MY built in that allows for precision finding like an AirTag. Finally, Apple took away the visible light and put it under the white plastic so that you can tell the charge status at any time. Ditto with the external button.

One of the hero features of AirPods Pro 3 is the heart rate sensor. And I am here to say that they work. I tested them with a chest strap and found them to be either on par with that or within one beat per minute. The other thing that they do is to switch between the Apple Watch and the AirPods Pro 3 depending on which is more accurate. It also means you don’t need an Apple Watch to record a workout if you had an iPhone. Could this mean that Apple taking the attitude that you don’t need an Apple Watch to do a workout? Hmmm….

Sound quality is top notch. The AirPods Pro 3 are have more bass. But not overwhelming as they are don’t sound like a Beats product. Which is also an Apple product. In the end, they have the typical Apple sound signature with more bass. I have no issue with them. But Apple is adding an EQ feature in iOS 27 to change that should you want to. In terms of noise cancellation, I don’t know if it is 2x better (relative to the AirPods Pro 2) according to Apple. But it is mostly better. If you have a constant drone that you want to block out, airplane engines for example, then they block that out easily. However I don’t get the same effect with subways trains on Line 1, Line 2 or Line 5 in Toronto. In other words, I would say that your mileage may vary.

Live Translation works surprisingly well. Though not perfect. I tested it with Spanish and Mandarin. The translations are quick enough to keep a conversation flowing, and they feel natural rather than robotic. Even with the slight delay while it waits for context, the results are clear and easy to follow. The feature also works in reverse. When you respond to someone who is speaking another language, your words will appear in the other person’s language on your iPhone screen. It wasn’t perfect as jargon or any sort of colloquial speech can trip it up.

So this sounds close to perfect. What trips it up? Well, it is iPhone only. While you can make it work with an Android phone, I am here to say that you should not bother as it will not work well. While Apple could make this more like a Beats product and make it work with both Android and iOS, it likely will not happen. Apple is also addressing the other issue which is an EQ feature for those who want it. Other than that, I can’t really pick out anything that is wrong with the AirPods Pro 3.

The Apple AirPods Pro 3 are $329 CDN. But if you check Amazon, you can find it cheaper at times. Assuming that you’re part of Team iOS in terms of your phone, these are the best earphones available right now. And they will get a bit better in iOS 27.

Researchers uncover exposed hacker server revealing details of a major phishing operation, complete with a scammer leaderboard

Posted in Commentary with tags on August 5, 2026 by itnerd

The Cybernews research team recently discovered a publicly accessible server running a major phishing operation impersonating the French bank Credit Agricole. After discovering the threat actor’s infrastructure, our team contacted Credit Agricole and the French CERT to inform the company and relevant authorities of the abuse.

Here’s what the investigation found:

  • The phishing campaign had access to 149 stolen SendGrid API keys and three stolen AWS accounts, with a combined sending capacity of around 7,000 emails per day.
  • The phishing panel’s database contained 912 victims who had entered their credentials into phishing forms, as well as 83 payments made to the scammers.
  • Bank credentials were used only to obtain additional data on the victim. To scam people out of their money, cybercriminals called the victims and used social engineering techniques to trick them into paying for a fake service.
  • The phishing panel contained a leaderboard for the phishing operators to compete against each other to see who could earn the most from their victims. The prize for the most successful scammer was €3,000. 

The findings underline a painfully obvious security problem: organizations continue to leave sensitive files exposed in internet-facing systems, unintentionally handing attackers the tools needed to operate fraud campaigns.

For more information, here’s the full report: 

https://cybernews.com/security/bizarre-credit-agricole-phishing-scam

Review: ESR AirPods Pro 3 Case

Posted in Products with tags on August 5, 2026 by itnerd

There was zero chance that I was going to use my new AirPods Pro 3 without a case as I will simply end up with scratches on the case. So to solve that problem I got the ESR AirPods Pro 3 case. This is what the case looks like:

This is a rubber case that has a lanyard to keep things secure. Given that this is a rubber case that has a hole that allows you to see the charge status, I would expect that protection will be better than good. That should keep these AirPods Pro 3 safe in any condition. But it has one trick up its sleeve.

There are four metal pieces that are magnetized. This keeps the cover closed so that neither of the AirPods Pro 3 pop out. This is the number one complaint that I have with how AirPods Pros are stored. That’s good. But there’s other party tricks that this case have:

  • MagSafe magnets allow you to use an Apple Watch or iPhone charger to charge the AirPods Pro 3.
  • Speaker Cutouts allow you to hear the FIND MY app sound alerts clearly.

There’s not a lot of bulk that’s not required, and there is a fair amount of texture which will keep the AirPods Pro 3 in your hand. All of this makes this a total win for me. Expect to pay $24 CDN on Amazon. I highly recommend it.

Maximor grows revenue 35x in 9 months as it elevates finance from task automation to full autonomy

Posted in Commentary with tags on August 5, 2026 by itnerd

Every new way a company grows eventually becomes a finance problem. Usage-based pricing makes revenue recognition harder, acquisitions add new entities, new sales channels introduce more billing exceptions – and so on. Finance is expected to absorb all of that complexity while still closing the books, protecting cash and giving the business a clear view of what is happening.

Maximor believes this has made finance the throttle on growth. Today, the company announced the expansion of its offering into an autonomous finance platform for the full office of the CFO, following 35x revenue growth just nine months after its $9 million seed round.

Why finance automation has reached its limit 

Finance teams have spent decades buying software for every part of the function. The ERP records transactions, billing platforms generate invoices, close tools track reconciliations. Each product makes one step faster, then hands the workflow back to a person.

That is the limit of finance automation: it can complete a predefined step, but it cannot take responsibility for the full outcome. Finance work is full of exceptions, judgment calls, and company-specific precedent. That knowledge is usually learned by people over time and preserved across journal entries, workpapers, emails, and memory rather than encoded in the software. So even when individual tasks are automated, the team still has to interpret what happened, decide what should happen next, and make sure the final result is correct and audit-ready.

A system of action for the office of the CFO 

Maximor’s Audit-Ready Agents™ operate across the core finance function, from revenue recognition and billing to cash application, close, accounts payable and multi-entity reporting. 

They work inside the existing stack, taking action where finance teams already work: posting entries in the ERP, reconciling bank accounts, capturing bills, chasing approvals, sending invoices and escalating judgment calls in Slack. Every action is logged and traceable. The ERP remains the system of record, while Maximor becomes the system of action across it, without requiring a year-long migration.

Around 98% of transactions on Maximor run end to end without intervention. The remaining 2% are escalated when Maximor encounters a decision it has not seen before. Once the team resolves it, the system learns how to handle it next time.

Traction 

Maximor now works with more than 25 customers across industries including software, manufacturing, construction, hospitality, and consumer goods. Its agents operate across hundreds of entities, thousands of bank accounts, and millions of transactions daily. 

Customers report reducing repetitive finance work by approximately 90% and audit exceptions by around 75%. At many companies, transactions are no longer entered manually into the ERP. A small finance team reviews and approves the work Maximor produces.

At one global cybersecurity company, growth through acquisition had left finance managing cash across 10 legal entities, seven currencies and more than 20 bank relationships, with 20 accountants pulling and reconciling data by hand. Maximor went live in under four weeks generating audit-ready reconciliations in seconds and reducing the team needed to manage cash from 20 people to five.  At another PE-backed roll-up with 14 business units and more than 30 subsidiaries, Maximor took over consolidation and back-office operations, reduced audit findings from seven to zero and cut related spending by approximately 70% within six months.

These deployments often begin with a single accounting bottleneck, then expand as Maximor absorbs more of the finance function. Customers pay for work that goes live rather than seats or licenses, aligning Maximor’s economics with the outcomes it delivers.

Built from experience 

Maximor was founded in New York in 2024 by Ramnandan Krishnamurthy and Ajay Krishna Amudan, who previously led enterprise and finance transformations at Microsoft for its own operations and companies including Coca-Cola and Walmart.

They saw that finance was trapped producing an accurate record of the past because its systems could record transactions, but couldn’t carry the judgment required to execute the work. Solving that required agents that could understand each company’s financial context and act across its existing systems.

What’s next

Today, Maximor runs the money by operating the finance function for its customers. As the platform instruments more of that work, it begins to know the money, creating a verified, real-time picture of how decisions move through the company and ultimately appear in its financial results. That foundation can power better forecasting, benchmarking, capital access and strategic decision-making.

Maximor’s long-term ambition is to make finance the intelligence layer of the company. Autonomous operations are the starting point. The larger opportunity is to give every business a finance function that can see what is happening now, understand what is likely to happen next and help leadership decide what to do about it.