Archive for August 27, 2026

Other World Computing to Premiere New and Enhanced Storage and Connectivity Solutions at IBC 2026

Posted in Commentary with tags on August 27, 2026 by itnerd

Other World Computing today announced its plans for the upcoming International Broadcasting ConventionIBC 2026, taking place September 11-14, at RAI Amsterdam, where it will take the wraps off several all-new products as well as showcase its world-renowned media and entertainment workflow innovations, in Hall 7, Booth 7.A60. 

While mum’s the word for now, during the week leading up to IBC 2026, OWC will 

launch brand new and dramatically enhanced storage and connectivity solutions across its OWC Jellyfish, dock, hub, and cable solutions portfolios – which it will then premiere live for the first-time at the event. 

In addition, OWC will feature its acclaimed, real-world proven, lines of storage and connectivity solutions, in Hall 7, Booth 7.A60 including: 

OWC Storage Solutions

  • OWC Express 4M2 Ultra – Thunderbolt 5 (80Gb/s) NVMe RAID storage solution, pre-configured with SoftRAID in 4TB, 8TB, 16TB, and 32TB capacities – also available as a bare enclosure for building your own configuration
  • OWC Envoy Ultra – first and fastest Thunderbolt 5 portable SSD, available in 2TB, 4TB, and a new category-defining 8TB capacity
  • OWC Envoy Pro Elektron – fastest, toughest mini-sized SSD available. It’s crushproof, dustproof, and waterproof for transferring gigabytes of data in seconds
  • OWC Express 1M2 80G – supremely fast, widely compatible, and highly portable USB4 NVMe SSD – build your own or choose ready-to-run solutions
  • OWC Thunderbay Series – delivers where it matters most: massive capacity, dependable performance, and cost-effective storage for large and growing data needs
  • OWC Express 4M2 – four-slot USB4 (40Gb/s) external storage enclosure for NVMe M.2 SSDs
  • OWC Studio Stack – world’s first, fastest, and highest-capacity Thunderbolt 5 stackable hybrid storage solution for Mac Studio and Mac mini machines
  • OWC ThunderBlade X12 – fastest and highest capacity production shuttle and editing RAID SSD in the universe

OWC Shared Storage Solutions

  • OWC Jellyfish Nomad – fastest, smallest, and most user-friendly mobile NAS on the planet, designed for DITs, independent 3D and VFX studios, and on-the-go editing teams
  • OWC Jellyfish Studio – high-performance desktop NAS built for collaborative production teams that need more shared storage, more users, and flexible all-SSD or HDD configurations

OWC Memory Cards & Readers

OWC Connectivity Solutions

  • OWC Thunderbolt 5 Hub – compact port expansion hub that turns one Thunderbolt 5 connection on your computer into multiple high-speed ports
  • OWC Thunderbolt 5 Dock – all-in-one command center for eliminating cables, expanding ports, and maximizing performance at your desk
  • OWC Thunderbolt 5 Dual 10Gb/E Network Dock – high-end network + connectivity docking station built for professionals who need serious network speed

Strada (In December 2025, Strada announced a partnership with and investment from OWC)

  • Strada 2.0 Peer-to-Peer Collaboration Platform – Strada will demonstrate its remote editing capability, which enables remote teams to edit video files stored on-premises…no file uploads or ongoing cloud subscription costs required! With Strada, creative teams can access remote video files, experience a seamless editing experience, and transfer files without any cloud intermediaries. This technology is a breakthrough solution for media customers concerned with data sovereignty, subscription costs, and the environmental impact of cloud storage companies. For a limited time, OWC customers who want their teams to experience remote collaboration can receive a special Strada discount.

“IBC brings together the people who are constantly pushing the boundaries of what’s possible in production, post, broadcast, and content creation, and our job is to make sure their technology never gets in the way of that,” said Chris Kooistra, Vice President, Marketing, Other World Computing (OWC). “Whether you’re moving massive files on set, editing against shared storage, building out a studio, or collaborating with a team across the world, every second matters. Everything we’re bringing to IBC this year is about helping professionals work faster, smarter, and more reliably — eliminating any and all potential bottleneck between capture and final delivery.”

To learn more about IBC 2026 and register to attend, please visit: https://show.ibc.org/.

SIOS Technology Named Among the Best Places to Work in South Carolina for the Seventh Consecutive Year

Posted in Commentary with tags on August 27, 2026 by itnerd

SIOS Technology Corp. today announced that it has been named to the list of 2026 Best Places to Work in South Carolina for the seventh consecutive year. The annual program, created by SC Biz News in partnership with BridgeTower Media and Best Companies Group, recognizes and honors outstanding employers creating exceptional workplace experiences across South Carolina. Winners were recognized at a celebration event on Monday, August 24 at the Columbia Metropolitan Convention Center.

The program evaluates participating companies through a two-part assessment process including an employer questionnaire and confidential employee engagement survey measuring workplace culture, benefits, leadership and employee satisfaction. Companies recognized as a Best Place to Work in South Carolina demonstrate a strong commitment to employee experience, workplace excellence and organizational success.

The M. Bert Storey Engineering and Innovation Center at the University of South Carolina’s College of Engineering and Computing in Columbia serves as the home of SIOS’ research and development operations, as well as its professional services and support teams. SIOS has built strong ties to the University of South Carolina through its ongoing campus partnerships and maintains an active presence in the Columbia community, where employees engage in local initiatives and collaborate with the university’s Computer Science Department.

SIOS high availability and disaster recovery solutions have become the gold star standard for protecting critical Windows and Linux applications such as SQL Server, SAP HANA, and Oracle across cloud, hybrid cloud and data center environments from downtime and disasters.

Guest Post: Exposed Server Reveals Aurora Ransomware Affiliate’s Attacks on 20+ Organisations, AI-Assisted Planning and Crypto Trail

Posted in Commentary with tags on August 27, 2026 by itnerd

An exposed server belonging to an Aurora ransomware affiliate has revealed months of attack activity against more than 20 organisations across nine countries, giving researchers an unusually detailed view of how a ransomware operator moves from network compromise to data theft, encryption, extortion and payment laundering.

The exposed directory contained the operator’s Linux home directory, shell history, credential material, attack tooling, victim data, AI-assisted planning sessions and the Aurora ransomware encryptor itself, a CloudSEK investigation has revealed.

Working with TRM Labs, CloudSEK also traced a ransom payment on-chain. TRM Labs’ wider analysis identified two confirmed victim payments and two additional payments consistent with separate victims, with the funds ultimately converging through shared laundering infrastructure.

The findings provide a rare attacker-side view of a ransomware operation, showing not only the tools and techniques used to compromise organisations but also how the attacker planned intrusions, deployed ransomware and handled the financial proceeds.

20+ organisations compromised, 17 reached at domain or interactive level

The operator was active across the exposed dataset between April and July 2026 and compromised more than 20 organisations in nine countries.

CloudSEK found that the attacker achieved domain-level or interactive access at 17 organisations. Four of the organisations recorded in the attacker’s files were subsequently listed on Aurora’s public leak site, connecting the activity observed inside the operator’s infrastructure with later public extortion.

The victim set covered multiple industries, including manufacturing and industrial organisations, food and agriculture, professional and financial services, transport and logistics, consumer goods, environmental services, and IT and backup infrastructure. The United States accounted for the largest share of confirmed victims.

In several cases, the attacker obtained highly privileged access or sensitive material, including domain administrator credentials, Kerberos tickets, VPN credentials, Group Policy information, backup-system credentials and other authentication data.

Most of the affected organisations identified in the dataset have not appeared on public ransomware leak sites. CloudSEK initiated coordinated notification with relevant national CERTs and/or affected organisations before publication for victims that had not already been publicly identified.

AI coding assistant used to plan real-world attacks

One of the most significant findings was the operator’s use of Cursor, an AI-powered coding assistant, during attack planning.

Recovered sessions showed the attacker using Cursor in Russian to reason through attack sequences, including detailed planning around Active Directory Certificate Services exploitation. The chat history showed sustained back-and-forth use of the AI tool during victim engagements.

The finding offers direct visibility into how readily available AI tools are being incorporated into cybercriminal workflows, not merely for generating code, but for planning and working through attack paths against enterprise environments.

A repeatable playbook for compromising enterprise networks

The exposed directory allowed CloudSEK researchers to reconstruct a repeatable attack methodology used across multiple targets.

The operator repeatedly performed Active Directory and SMB discovery, retrieved password policies and carried out Kerberoasting and AS-REP Roasting. For privilege escalation, the attacker relied on several techniques depending on the environment, including a custom noPac chain, Active Directory Certificate Services abuse across ESC1, ESC6 and ESC8, and NTLM relay attacks using PetitPotam, PrinterBug and DFSCoerce.

Exploit code for at least a dozen vulnerabilities was also stored in the exposed environment. Much of it consisted of public proof-of-concept code, while some tooling had been modified and a FortiOS toolkit had been rebuilt as an independent framework.

The operator maintained custom NetExec modules, including tools designed to collect browser credentials across multiple browsers and identify ESXi infrastructure.

CloudSEK assesses with high confidence that the individual was operating directly as an Aurora ransomware affiliate rather than functioning solely as an initial-access broker. The activity continued beyond obtaining access into credential theft, domain compromise, exfiltration, ransomware staging and extortion.

Aurora ransomware built in Zig targets Windows, Linux and ESXi

The exposed environment also contained multiple versions of the Aurora encryptor for Windows and Linux/ESXi systems.

Both versions were written in Zig, a relatively uncommon programming language in ransomware development. The Windows and Linux variants appear to have been built from the same Zig codebase and compiled for different operating systems.

The encryptor supports several options designed to speed up or customise encryption, including partial-file encryption, multithreading and file-size restrictions.

The Linux/ESXi version contains functionality specifically designed for virtual infrastructure. Before encryption begins, the ransomware enumerates running virtual machines and force-terminates them. It also handles ransom-note delivery differently: instead of simply dropping a note as a file, it can modify the ESXi host’s SSH login banner so that the ransom message appears when administrators connect to the server.

The report includes indicators of compromise and a detection rule designed to identify this behaviour.

Following the ransom payment trail

The exposed files also provided researchers with visibility into the financial side of the operation. The wallet address the operator provided for payment was found to hold 7 BTC at the time of analysis, a balance more consistent with accumulated proceeds from several victims than a single payment, and itself a strong indicator that this operator’s activity generates significant revenue.

A key recovered from the Aurora encryptor allowed CloudSEK to access records from a completed ransom negotiation. The victim involved is not being named.

Working with TRM Labs, CloudSEK traced the resulting payment on-chain and examined how the funds moved after payment.

The wider analysis identified two confirmed victim payments and two additional payments consistent with separate victims. While each payment began on a separate path, several later converged at shared consolidation points before moving towards cash-out infrastructure.

Researchers also observed differing splits across the payments analysed, including 35/65, 21/79, 46/54 and 40/60, with no single ratio consistently repeated. The finding suggests that, across the transactions examined, the division of proceeds between participants was not based on a single fixed percentage.

Most of the traced funds passed through two dominant consolidation clusters before reaching cash-out addresses. One payment followed a different route through a peeling chain, where funds were gradually moved across a sequence of transactions rather than through the main consolidation hubs.

The financial activity observed in the investigation suggests that Aurora-linked ransomware activity may extend beyond the victims visible on public leak sites. 

Russian-speaking operator, CIS targets absent from observed dataset

CloudSEK assesses with high confidence that the operator is Russian-speaking.

The assessment is based on material created directly by the attacker, including Cursor conversations, module documentation and session notes written in Russian.

Researchers also found that no CIS-allocated IP ranges or CIS-country domains appeared in three months of the operator’s target lists, scans or success logs.

CloudSEK’s assessment relates to the operator’s language and the targeting behaviour visible in the recovered dataset and does not establish the individual’s nationality or physical location.

Why the investigation matters

Ransomware investigations typically begin after an organisation has already been compromised, forcing defenders and researchers to reconstruct an attack from the victim’s environment.

In this case, the exposed directory provided visibility from the other side.

Researchers were able to examine the attacker’s working environment, understand how organisations were enumerated, follow privilege-escalation attempts, review stolen credentials and attack tools, observe the use of AI during operational planning, analyse the ransomware itself and follow a victim payment into cryptocurrency laundering infrastructure.

Taken together, the findings provide an unusually detailed picture of the operational lifecycle of a modern ransomware affiliate, from enterprise intrusion and data theft to encryption, extortion and the movement of ransom proceeds.

The full report also includes technical indicators of compromise, attacker infrastructure, malware hashes, detection rules and detailed mitigation recommendations to help organisations identify and defend against similar activity.

For more information, read the full report.

Eclypsium InfraTrust Pulse for Aug 2026 Is Now Live

Posted in Commentary with tags on August 27, 2026 by itnerd

Eclypsium has published the second-ever monthly InfraTrust Pulse for August 2026 today, led by researcher Paul Asadoorian. Think of this as the Patch (Wednesday) for hardware and infrastructure, which you can now expect monthly.

Read it here: https://pulse.infra-trust.org/august-2026/.

Security expert comments on the risks of giving Grok Bot access to bank accounts 

Posted in Commentary with tags on August 27, 2026 by itnerd

Users are considering giving Grok Bot access to their bank accounts, with one user suggesting it could “track spending, move money, pay bills, and watch for weird charges.”

Elon Musk encouraged the user to “try it out,” adding that if “Grok Bot messes up, we will make you whole.”

Cybernews information security researcher Rasa Jurgutytė warns that giving an AI agent this level of access could create risks that reimbursement cannot fix.

Her comments:

  • “In this case, where an agent essentially performs bank operations on your behalf, so many things can go wrong. An agent might misunderstand a request at best, or can be manipulated via prompt injections/malicious requests at worst.”
  • By giving Grok Bot access to your data, there’s also a risk of accidental information disclosure.
  • In this context, leaked data could include “your transaction history, balances, payment method, or personal information, which is much worse than a brief summary of your spending habits, or whatever else a person might ask on a prompt,” Jurgutytė told Cybernews.
  • While Musk tells the user not to worry, as he will reimburse potential damages caused by Grok Bot, Musk “cannot undisclose your information,” Jurgutytė concludes.

Feel free to use Rasa’s comments in your coverage. I can also provide additional information if useful.

Here’s the full Cybernews article about this for more context: https://cybernews.com/ai-news/grok-bot-connect-bank-acccount/ 

The CISA Warns Users Of The Gitea Flaw

Posted in Commentary with tags on August 27, 2026 by itnerd

The CISA  warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. What’s Gitea you ask? CVE-2026-60004 which gets an almost perfect CVSS score of 9.8 centres around remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Gitea OS user.

In other words, it’s bad.

Noelle Murata, COO, Xcape, Inc. (https://www.linkedin.com/in/nmurata)

“Compromising developer infrastructure grants threat actors direct access to source code, intellectual property, and pipeline secrets, turning software management platforms into high-leverage launchpads for downstream supply chain attacks and malicious code insertion. Pipelines concentrate high-value trust and credentials, making developer tools a preferred target over hardened perimeters. The build pipeline is where trust and credentials concentrate, so attackers skip the hardened perimeter and target the choke point instead.

“Although the CISA advisory targets federal agencies, private industry should take note as well. This vulnerability requires an authenticated user; however, Gitea’s default configuration allows self-registration, enabling external adversaries to easily gain the required access. Default settings like open self-registration convert unauthenticated external threats into authenticated exploit paths.

“Most of the defense relies on configurations you already own: mounting directories with noexec, closing self-registration, monitoring for new user sign-ups, and using scoped tokens defangs the exploit before you ever reach the patch. Hardening existing configurations (disabling self-registration, enforcing noexec, and scoping tokens) defangs exploits while patches are deployed. Ultimately, hardening development environments requires security teams to enforce strict access controls and patch their systems without delay.

“Defense in build environments comes down to simple hygiene: lock down registration, scope your tokens, and patch your systems.”

Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)

“Gitea has been the target of other recent attacks. At first glance, it may appear that attackers are interested in going after software repos specifically, because development environments can be target rich. But considering the gaping security holes that are being discovered, its more likely that these are opportunistic.

“In the case of this vulnerability, it requires that the user be authenticated, and have write access. This sounds like it would be somewhat limiting, as proper permissions and IAM processes would effectively block attackers out. However by default, Gitea allows users to self-register their own accounts, and setup new repos which they then have write access to. Meaning that in practice, any unauthenticated attacker without write access can simply grant themself those permissions, and exploit away.

“The impact of this depends entirely on the motivations of the attackers. We’re seeing reports of this exploit being used for crypto mining. It’s common for low effort attacks to utilize RCE exploits to simply mine a bit of crypto. This wastes organizational resources, but only minimally interferes with normal operations, and cleanup tends to be straight forward. Higher impact attackers could perform more disruptive attacks, such as ransomware. Especially now that this is getting attention for how easy this one is to exploit. Same exploit, different monetization strategies.

“As always, patch your systems, people!”

Patching your systems should be the first thing that you do as 9.8 out of 10 isn’t good from a security standpoint.

Four in Five AI Tools Operate Without IT Oversight 

Posted in Commentary with tags on August 27, 2026 by itnerd

The State of Agent Security 2026 Report issued today by Reco finds that four in five AI tools operate without it oversight, leaving security teams without a clear view of which ones are active, who owns them or what they can access. The analysis of 500 published agent tools based on Reco telemetry found that 62% can both read local data and reach the internet, creating a direct path for data exfiltration. 

AI agents aren’t just another third-party applications, they’re increasingly embedded inside the ecosystem of tools employees use everyday, where they can inherit user permissions, OAuth grants, service accounts and API access. The risk comes from intended combinations: one tool can read files, another can reach the internet, another can trigger a workflow, and together they grant agents the ability to move through the enterprise in ways no single application owner intended.

Liquibase VP Ryan McCurdy Had This To Say:

  “Most employees aren’t trying to bypass security, they’re just trying to get their work done. If the approved AI tool is harder to use, less capable, or doesn’t fit how people actually work, they’ll find another way, and risks grow as AI moves from accessing information to taking action. An unsanctioned chatbot creates one level of risk, but an AI agent with credentials and access to code, infrastructure, or production databases creates another entirely. And at that point, the organization may not even know the agent exists, much less what it can access or change.

  “With four in five AI tools running with no IT oversight, the biggest problem is losing visibility and control over what AI can actually do. An agent can make a bad decision, misunderstand an instruction, or be manipulated. That shouldn’t automatically become a production problem. Enterprises need to know what an agent can access, what it can change, and what policies have to be met before it can act. The answer isn’t to stop people from using AI. It’s to make the governed path the easiest path.

  “The broader challenge in agentic AI security is that organizations are moving beyond governing what AI can generate, and need to govern what AI can actually do. As agents get access to more tools, credentials, and production systems, security can’t stop at the model. Governance has to follow the action all the way to the system being changed. And it has to operate at the speed of AI. Adding more tickets and manual approvals every time an agent wants to do something defeats the reason enterprises are adopting agents in the first place.

  “Shadow AI becomes even more serious whenever agents move into software delivery, data workflows, and production systems. An agent that writes code or generates a database change is not just producing content. It is proposing change to the business. That change needs governance, traceability, and proof of control.

    “To manage Shadow AI risks, organizations should start with policy and visibility. IT teams need to know which AI tools are being used, what data they can access, and what actions they can take. Then make the governed path the easiest path. Give employees a way to use AI without adding more tickets, manual reviews, and bottlenecks. And when AI reaches critical systems, put governance around the change itself so policy doesn’t depend on which AI tool created it.”

“The fix isn’t to slow AI down, it’s to design the work before it’s automated.”

This might sound familiar. AI that runs itself is dangerous. It needs guardrails and safety before you turn it loose. Otherwise bad things are going to happen.

400,000 WordPress Sites Impacted by Account Takeover Vuln in TranslatePress Plugin

Posted in Commentary with tags on August 27, 2026 by itnerd

Researchers have uncovered a critical vulnerability with a CVSS score of 9.8 in the TranslatePress WordPress plugin, with 400,000 active installations, that could allow unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account takeover.

More info here: https://www.wordfence.com/blog/2026/08/400000-wordpress-sites-affected-by-account-takeover-vulnerability-in-translatepress-wordpress-plugin/

Dan Moore, Sr. Director CIAM Strategy at cybersecurity company FusionAuth, provided the following comments:

TranslatePresss (CVE-2026-19632)

An attacker can gain admin access to multi-language WordPress sites by retrieving a plaintext admin password reset link and key via an unprotected API. This shows how combining two unrelated APIs can have unexpected and unfortunate security implications. In addition, trp_get_translations_regular handles translations for all types of users, including admin, logged in and anonymous users. Separating these and ensuring all API endpoints that handle known user data have proper authentication and access controls is critical of security.

“Forminator (CVE-2026-15748)

By allowing anyone to manipulate form submissions to set their own upload rules for field names and data handling, Forminator lets attackers run their code on your site. This is a case where the cracks in several systems were chained together:

  • Forminators uploading accepting user content
  • The difference in the handling between WordPress’s and Forminator’s blocklists
  • The lack of .htaccess protects for certain configurations

Complex systems interact in unexpected ways that attackers exploit. I mean, no single piece of this is obviously catastrophic on its own. That’s kind of the point. And that’s exactly what makes this class of vulnerability hard to patch your way out of.

Given that I am a WordPress user, I am going to check my site to make sure that I am protected. You should do the same.