Archive for August, 2026

TELUS commits $2 million to support emergency wildfire relief across British Columbia

Posted in Commentary with tags on August 12, 2026 by itnerd

As devastating wildfires sweep across British Columbia, TELUS is responding with a $2 million commitment in network connectivity, data top-ups and bill credits for affected customers, and donations and support to charities. TELUS is directing resources toward affected First Nations and non profit organizations on the ground – including the Salvation Army BC and community food banks – while ensuring residents and first responders have access to the critical communications services they need to stay connected.

Maintaining connectivity and critical network operations

TELUS technicians are working tirelessly to keep network infrastructure operational under extreme conditions, including bringing in additional equipment like generators to keep cell sites running despite a lack of commercial power, and restoring damaged infrastructure as soon as it is safe to do so. This critical work ensures firefighters and other emergency personnel working on the frontlines of the fire remain connected, that residents facing possible evacuation orders have access to the latest information, and keeps families in touch during this difficult time. Our teams are coordinating with government agencies and relief organizations to provide connectivity at evacuation centres, command centres, and other critical locations, while deploying mobile connectivity solutions to fill gaps where fixed infrastructure has been damaged.

How TELUS is further supporting our customers and communities: 

  • Keeping families connected – Affected customers should not be worried about their bills. We’re automatically giving 50 GB of free wireless data to evacuated TELUS and Koodo postpaid mobility customers to keep them connected, and are crediting TELUS Internet, TV, home phone, and SmartHome Security bills for all evacuated households. We will continue to pause all home services billing for any customers who face an extended evacuation or displacement. Evacuated customers can call the dedicated line 1-855-889-7233 beginning Wednesday, August 12 for help with their TELUS services and re-entry plans. 
  • Delivering emergency support on the ground – TELUS team members and volunteers are delivering emergency kits with essential supplies, extra cell phones, and power bricks and charging cables to evacuation centres. We’re also working closely with evacuated First Nations communities to address their specific connectivity needs and offer our support including through emergency kits.
  • Supporting communities with direct funding – TELUS and the TELUS Friendly Future Foundation are committing $100,000 to affected First Nations including Okanagan Indian Band and Westbank First Nation and local charities providing immediate aid on the ground. This funding goes directly to trusted partners including Animal Lifeline Emergency Response Team Society, Canadian Disaster Animal Response Team Southwest BC Society, Central Okanagan Food Bank, Clinton Food Bank Society, Mamas for Mamas, Nicola Valley and District Food Bank Society, North Okanagan Friendship Centre Society, and Salvation Army British Columbia Division. 
  • How customers can help – TELUS customers can text DONATE to 41010 to donate $20, or redeem their TELUS Rewards points to support wildfire relief through the TELUS Friendly Future Foundation.
  • Providing wellbeing support – The TELUS Health Community Crisis Support line (1-844-751-2133) offers free, professional emotional support and/or resource referrals to anyone in Canada and is operational 24/7. 

A longstanding commitment to disaster response and recovery

For more than two decades, TELUS has invested over $300 million in emergency response and community recovery globally, including more than $125 million toward wildfire and flood relief across Canada in recent years. British Columbia is TELUS’ home, and when things are at their worst, British Columbians know they can count on the TELUS team to step-up and be at their best. TELUS is leveraging its technology, health capabilities, and remarkable team to help British Columbians stay safe, connected and supported throughout this wildfire emergency. 

11GB Of Data Exposed Says Cybernews

Posted in Commentary with tags on August 12, 2026 by itnerd

Cybernews researchers discovered an unprotected Talentsconnect database with nearly 11GB of live recruitment data, referencing 843 companies, including references associated with Siemens, Deutsche Bank, Vodafone, BASF, and EY. Talentsconnect is a company that specializes in direct-to-talent (D2T) matching platforms, which connect job seekers and employers. 

Here are the key findings:

  • The exposed database with over 5 million job listings included applicants’ names, emails, phone numbers, salary expectations, Base64-encoded CVs, or cover letters.
  • The database showed 335 plaintext credentials across 56 client integrations. One belonged to the waste management company Remondis, with username and password information potentially providing access to their recruitment portal.
  • Researchers found 80 plaintext credentials for FFG Prescreen, a background-check tool used in hiring. These are intended to allow candidates to modify submissions, but malicious actors could exploit them to post fake jobs, alter details, or delete data. 
  • Exposed data contained AWS Secrets Manager references for such companies as Siemens, Vantage Towers (Vodafone), Hornbach, ARAG, Computacenter, Peek & Cloppenburg, and UniCredit.

“This is a single point of failure sitting behind the hiring pipelines of hundreds of major European employers. Anyone on the internet could have read the entire client roster, harvested candidate personal data, or, because access was read/write, altered or injected data. For example, posting fake job ads under real company names, submitting fraudulent applications with malicious attachments, or deleting listings,” our researchers explained.

Talentsconnect closed the database after researchers disclosed the issue to the company, and the information is no longer publicly accessible. Cybernews researchers found no evidence that unauthorized users accessed the data while it was still leaking. 

For more information, here’s the full report:

https://cybernews.com/security/talentsconnect-hr-database-data-leak

Park Place Technologies Achieves Additional “Powered by Nutanix: Verified Solutions” Badge

Posted in Commentary with tags on August 12, 2026 by itnerd

Park Place Technologies today announced it has achieved its fourth “Powered by Nutanix: Verified Solutions” badge. The badge reflects the company’s commitment to designing and delivering services aligned with Nutanix prescribed best practices and architectural standards.  

Through the “Powered by Nutanix: Verified Solutions” program, Park Place Technologies’ Sovereign Cloud offering has been reviewed against Nutanix-defined technical and operational criteria for alignment with platform best practices. As data sovereignty moves up the boardroom agenda, this offering responds to a clear market need: cloud models that give organizations the freedom to innovate while maintaining greater control over data location, governance, and operational risk. 

It follows the successful achievement of our previous “Powered by Nutanix: Verified Solutions” badges for Dedicated Private Cloud, Multi-Tenant Private Cloud, and Disaster Recovery as a Service solutions, reflecting a sustained, scalable commitment to delivering secure, resilient, and enterprise-grade cloud and IaaS services to customers. 

These recognitions are designed to provide customers with confidence that their cloud services are built on Nutanix technology and aligned with defined design and operational guidelines.  

The “Powered by Nutanix: Verified Solutions” program empowers service providers to deliver comprehensive, market-ready cloud offerings built on the Nutanix Cloud Platform. These solutions provide a modern architecture that is designed to support performance, security, and scalability requirements and the flexibility to support virtual machines, containers, and AI workloads, all managed via a single, unified control plane. 

With four “Powered by Nutanix: Verified Solutions” badges, Park Place Technologies has achieved a key milestone that underscores its commitment to delivering validated, enterprise-grade cloud solutions. 

The announcement comes at a time when many organizations are reassessing their virtualization and cloud strategies. As enterprises evaluate options for hybrid cloud, sovereign cloud requirements, and alternative virtualization platforms, Park Place Technologies provides customers with a range of deployment models supported by independently verified solutions. This enables businesses to align infrastructure decisions with operational, regulatory, and commercial objectives while reducing transformation risk.

The Park Place xCloud platform, powered by Nutanix technology, offers customers flexible deployment options spanning dedicated private cloud, multi-tenant cloud, Disaster Recovery as a Service, and sovereign cloud. This approach allows organizations to place workloads where they make the most sense from a performance, security, compliance, and cost perspective. 

The latest validation further strengthens the longstanding relationship between Park Place Technologies and Nutanix and highlights the organizations’ shared commitment to helping customers modernize infrastructure while maintaining operational resilience and business agility. 

The “Powered by Nutanix: Verified Solutions” badge reflects evaluation against Nutanix program criteria and does not constitute a warranty, endorsement, or guarantee of performance, security, or regulatory compliance by Nutanix.  

MCP Servers Are the New Software Supply Chain Risk

Posted in Commentary with tags on August 12, 2026 by itnerd

New research from ASSET Research Group shows malicious MCP servers can split data-exfiltration instructions across multiple tool calls, letting AI coding agents piece together and leak SSH keys, source code, and customer data even when a single blunt request would get refused. No CVE yet, but the technique worked against nearly every major model tested once the request was fragmented.

The Hacker News has a good writeup about this here: Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

Justin Beals, CEO and Founder of Strike Graph, sees this as a governance failure, not a model failure, and has a sharp take on why treating MCP servers as trusted extensions rather than unverified third parties amounts to repeating a twenty-year-old mistake with software dependencies:

“This is the AI supply chain problem in miniature. Everyone is watching for one bad instruction. Nobody is watching for four good ones that add up to a bad outcome.

The real failure here is trust. Once a developer connects an MCP server, that server is treated like a trusted extension of the agent instead of an unverified third party. That is the same mistake we made with software dependencies for twenty years, just moved one layer up the stack.

Organizations need to start governing AI agents the way they govern any other identity with access to sensitive systems. That means verifying MCP servers before connecting them, not after something goes missing. Treat every tool result as untrusted data until proven otherwise. The agents are only going to get more capable and more connected. The organizations that survive this next phase will be the ones who assumed the server on the other end was hostile from day one.”

If you think you are exposed, then this is your wake up call to take action. Because if you don’t take action, pwnage is inevitable.

Guest Post: By Is the National Vulnerability Database still meeting the needs of defenders, or has the volume and complexity of modern vulnerabilities outgrown the current model?

Posted in Commentary with tags on August 12, 2026 by itnerd

By Tyler Reguly, Associate Director of Security R&D at Fortra

Is the National Vulnerability Database still meeting the needs of defenders, or has the volume and complexity of modern vulnerabilities outgrown the current model?

A more interesting question might be “has the National Vulnerability Database ever actually met the needs of defenders?” The only valuable information provided by NVD in the past has been CVSS information, and I’ll leave it up to the individual to decide if CVSS has ever been “valuable.” The other information provided by NVD was CPE data, and it has long been known that if you were using NVD CPE data for vulnerability detection, you were not getting accurate or reliable vulnerability detection.

What role should AI play in vulnerability discovery, prioritization, and remediation, and where is human oversight still necessary?

AI is playing a pretty strong role in vulnerability discovery with source code. That is the perfect application in my mind. We’re seeing the results with the size of the patch drops from companies like Microsoft and Oracle. When you let AI explore your source code, you fix all sorts of obscure vulnerabilities.

At the same time, we’re climbing a hill right now, discovering all the obscure issues that were either too buried, too complex, or too restrictive to be sought out by human researchers. Once these issues are all discovered and AI tools are run on new code bases, problems will be fixed before they are shipped, and those aren’t vulnerabilities and don’t require CVEs, so we’ll start to go back down the hill, and everything will normalize once again.

When it comes to prioritization, anything I’ve seen out of AI so far has been “good enough.” I’d call it on par with a junior analyst. I haven’t seen it perform prioritization as well as a VM expert.

Finally, remediation… I would not trust the remediation of vulnerabilities in critical systems to AI just yet. There’s no coming back from that. There’s a reason human-in-the-loop is still so critical, and as soon as AI starts remediating vulnerabilities, you lose the human oversight. In test environments, sure. In labs, definitely. In production systems… not yet.

What risks could organizations face if they rely too heavily on AI-generated vulnerability analysis and prioritization?

The risk is overlooking real risk. AI prioritization tends to rely on knowns and treats prioritization like a science. CVSS was used for years as a prioritization metric (they finally updated their documentation to advise against this, but people still use it that way). Prioritization is still, in my mind, an art. There’s a gut feeling that goes along with all the variables. You can get close (and some companies have interesting algorithms in the space), but you still have the art of it all that plays a major role in my mind.

How should security teams adapt their vulnerability management programs as attackers increasingly use AI to identify and exploit vulnerabilities faster?

Remember that vulnerability management is just one of the pillars of good cybersecurity hygiene. If you are layering it with FIM, EDR, and proper system hardening, then you’ve got a solid foundation. Yes, you have to make adjustments in some places, but remember that patches fix multiple vulnerabilities, that few vulnerabilities are ever actually exploited, and that known active exploitation increases risk. From there, a few simple choices will keep your VM program running smoothly.

If NIST successfully modernizes the NVD, what capabilities or improvements would have the biggest impact on organizations over the next five years?

First, we should talk about what modernization looks like. It’s better application of CPEs and CWEs. It’s inclusion of EPSS data alongside CVSS data. It’s providing better remediation guidance and a more structured list of external resources. My biggest fear is that OVAL will be seen as a useful standard and further adopted or that CPE data will continue to be less than complete. I’m not saying that everything needs better enrichment, but critical vulnerabilities need to be completely enriched and pulled out and better accessed. We need to deprioritize CVSS data. If we can start to make changes and improvements, then we may see a place where organizations can actually start to look for guidance. Right now, I would say that CISA Kev and CVE.org are a better combination of data than NVD, and I’m not sure anyone really needs to go to NVD. 10 years ago, NVD was at the top of the pecking order, and it would be interesting to see them return to that status.

Hackers breach Polish power plant through private cellular network

Posted in Commentary with tags on August 11, 2026 by itnerd

Poland’s CERT has disclosed a cyberattack that shut down a steam turbine and process-water treatment system at a combined heat and powerplant supplying roughly 50,000 residents. The December 2025 attack caused a short-lived operational disruption, but customers did not lose heat or electricity.

Investigators found the attackers initially compromised a FortiGate VPN/firewall at a separate wind farm, then used a cellular router to enter a private APN connecting remote infrastructure. Because the network lacked client isolation, the attackers reached a WAGO industrial controller using default administrator credentials, pivoted into the plant’s OT network and ultimately accessed its SCADA system and Siemens PLCs. CERT Polska said it believes this is the first known real-world cyberattack to gain access to an OT network by moving laterally through a private APN.

Waseem Ahmed, Head of Engineering, Secure.com:

“Breaches like this do not start with anything fancy. They start with a device someone forgot about. Attackers got into a wind farm firewall, then rode a private cellular network into a power plant that had nothing to do with it. The controller they landed on still had its default password. From there they reached the plant floor and stopped a turbine.

“CERT Polska assessed this as the first confirmed case of an attacker using a private cellular APN as a lateral movement path into OT infrastructure, which matters because operators often treat private APNs as inherently safe without applying the same segmentation controls they would to any other network connection.

“A private network is not the same as an isolated one. Client isolation, replacing default credentials, and treating every remote link as untrusted stops most of this. When offense maps these paths first, defense knows which door to close.”

Denis Calderone, CTO, Suzu Labs:

“Private cellular networks are a good idea for OT connectivity, but they only solve one problem: keeping traffic off the public internet. What they don’t solve is what happens when one device on that network gets compromised. In this case, a single insecure controller on the operator’s private APN gave the attacker vertical exposure all the way down to the SCADA system and Siemens PLCs at a completely separate facility. The APN kept the outside world out, but nobody considered the trust boundaries between devices inside it. Without client isolation, a private APN is just a flat shared network where any compromised node can reach everything else.

“The private APN in this case was set up by the distribution system operator, the entity that runs the local electricity grid, to communicate with distributed generation sites. Wind farms, CHP plants, substations, all connected to the same carrier-managed cellular network for SCADA communication. This makes perfect sense architecturally, but the problem is that the DSO architected it as a flat mesh. Every site could reach every other site. Think of it like an MPLS network where multiple customers are in the same VRF with no route filtering between spokes.

“The wind farm had zero operational reason to communicate with the CHP plant’s controllers. Both sites needed to talk to the DSO’s central SCADA, and that’s it. But because there was no hub-and-spoke enforcement and no spoke-to-spoke restriction, an attacker who compromised a Teltonika router at one wind farm could scan the entire APN, find a WAGO PLC at an unrelated facility still running default credentials, and use it as a bridge into that plant’s OT environment. One compromised site gave them the run of the entire network. 

“CERT Polska says this APN misconfiguration was common across Poland at the time of the attack and is believed to be widespread internationally. That tracks. Back in May there were the Polish water treatment attacks where operators were running passwords like ‘111111’ on internet-exposed HMIs and mistaking active intrusions for equipment glitches. Same pattern here. The CHP plant operators initially thought the shutdown was a contractor error during routine maintenance. CERT Polska only investigated because the timing coincided with the larger coordinated attack on 30 other energy sites that same day. Without that coincidence, this might still be filed as an unexplained equipment failure.

“The prescriptive side here starts with the APN specifically. Contact your carrier and confirm that client isolation is enabled. If it’s not, or if you must run a flat APN mesh between every site, make sure to enforce your own site-to-site edge controls. Where possible, the default configuration should be to enforce hub-and-spoke so each site can reach the central SCADA gateway and nothing else. And beyond the cellular network, this is the same OT security discipline we preach on every engagement. Industrial controllers and SCADA interfaces should never have their administrative interfaces exposed on any network they don’t absolutely need to be on. Default credentials on PLCs need to be treated with the same urgency as a default password on a domain admin account. Segment OT environments from IT with monitored firewall boundaries. And include your cellular connectivity in your security testing program.”

John Strand, Owner, Black Hills Information Security, Inc.:

“This is the problem with unseen IT, OT, and legacy technology. Anything that falls outside of mainstream server and endpoint infrastructure tends to get neglected by organizations. That doesn’t necessarily mean those organizations are incompetent or negligent. The reality is that there simply aren’t as many security products and services available to protect these environments, and a lot of that comes down to market share.

“We are starting to see improvements, but it’s still very easy for organizations to ignore these technologies or even create exceptions for them within their compliance frameworks. Attackers understand this. If they can move away from environments protected by mainstream EDR and other widely deployed security technologies, they can start targeting unseen, out-of-the-way, and lesser-known systems where they have a much higher probability of success. That’s the attack surface we need to start paying a lot more attention to.” 

This is an epic fail. But at least they were honest enough to put what happened down on paper. But how about stopping this from happening in the first place? That’s real progress.

3X Surge in AI Agent Deployments Since 2025 Says Salesforce

Posted in Commentary with tags on August 11, 2026 by itnerd

Salesforce has released its 2026 Agentic Enterprise Index, which analyzes global AI usage data to uncover how businesses are deploying, using, and getting value out of AI agents. 

The index shows enterprise adoption is scaling up, with the average number of AI agents activated per enterprise nearly tripling year-over-year. Based on data from 734 million completed AI tasks, businesses are shifting from basic AI chatbots to complex, multi-step automated workflows that deliver tangible ROI.

The findings come as 27.8% of large Canadian enterprises are actively adopting AI, according to Statistics Canada, raising the question of what effective agent deployment looks like in practice. Salesforce’s data provides key insights for Canadian organizations looking to move from AI experimentation to measurable business impact.

Insights from the report include:

  • Agent Versatility: The unique skill set of an average agent grew from 2 distinct business actions to 6 by the end of 2025, turning agents into cross-functional partners for enterprises.
  • Faster Time-to-Value: Average agent deployment time dropped 53% to just 2 days, showing companies are moving past long pilot phases.
  • Industry Rollouts: Consumer sectors have scaled AI agents quickly during demand spikes (during peak shopping season, the average retail agent drove 4x the sales for companies compared to those without one and was able to act on 9 skills), while highly regulated industries, such as Financial Services, led in agent sophistication.

You can read the report here: https://www.salesforce.com/news/stories/agentic-enterprise-index-insights-2026/

Gunra ransomware group bypassing MFA and exfiltrating enterprise data via Fortinet flaws

Posted in Commentary with tags , , on August 11, 2026 by itnerd

The FBI, CISA, and South Korea’s National Police Agency issued a joint advisory Monday on Gunra ransomware, also known as Golden Community. The RaaS operation exploits two Fortinet firewall vulnerabilities, CVE-2024-55591 and CVE-2025-24472, for initial access, then runs double extortion against healthcare, financial services, and government targets worldwide.

Roman Sannikov, Global Research Coordinator, iCOUNTER

“Gunra’s exfiltration playbook is what should worry Microsoft 365 shops specifically. The advisory documents a custom executable pulling data straight out of OneDrive and SharePoint, then in at least one case moving the archived data out to Mega in volumes running into the tens of terabytes. Getting into position to do that took real infrastructure: the actors moved laterally using Impacket tools over SMB and hijacked active sessions by stealing VPN cookies, all before touching a single file. Moving that much data without tripping alerts takes real operational patience, and it fits a pattern: CISA notes the actors deliberately operate between 10pm and 6am to stay under the radar of anyone watching logs during business hours. Once they do start encrypting, it’s fast, ChaCha20 paired with RSA-4096 across a multi-threaded engine hitting multiple files at once. If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

These advisories are not made lightly. So organizations need to pay attention. Especially Microsoft 365 shops to avoid being pwned by these threat actors.

UPDATE: Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this comment: 

“Gunra made multi-factor authentication (MFA) lie for them. In the South Korean case, the group modified virtual desktop infrastructure (VDI) authentication files to accept a hardcoded attacker-chosen one-time password, and every subsequent login looked legitimate to monitoring tools. Most organizations treat MFA as the last line of defense. Gunra treated it as the first thing to subvert.

“The sector targeting is economic. Healthcare, financial services, and government can’t tolerate downtime or survive a data leak. Encrypting their systems while threatening to publish stolen records hits both pressure points at once.

“CVE-2024-55591 and CVE-2025-24472, the two Fortinet authentication bypasses that got them initial access, are eighteen months old and have been exploited by multiple ransomware groups. Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow. I’ve seen organizations close the vulnerability and declare themselves clean while the attacker’s persistence mechanism sat untouched in the auth stack.

“The advisory also flags a recoverable flaw in Gunra’s Linux encryptor. The variant seeds its ChaCha20 keys with time() instead of a secure random number generator, so defenders who preserve file timestamps can reconstruct keys without paying. Any organization hit by the Linux variant should get forensics involved before wiring cryptocurrency.

“Gunra created a “forticloud-sync” account with super user privileges and a hardcoded password on compromised Fortinet firewalls. That account survives a firmware update, and so do modified VDI authentication files. An organization that patches and stops there is giving Gunra a head start on round two.”

John Strand, Owner, Black Hills Information Security, Inc.:

“The goal of targeting critical infrastructure is really twofold. With nation-state attacks, the objective can be straightforward. You want to create pain for your adversary. But with ransomware groups, I think there are two things we need to understand.

“First, critical infrastructure has become a dinner bell. Ransomware groups have seen how exposed and neglected some of this infrastructure is in countries like the United States, and now they’re swarming toward it because they recognize the opportunity.

“The second factor is pain. There’s been a major push in the security industry for organizations to refuse ransomware payments. But that position becomes much more complicated when an attack against critical infrastructure potentially impacts hundreds of thousands or even millions of people. It’s one thing to say you won’t pay the bad guys when the impact is contained to your organization. It’s another thing entirely when water, power, healthcare, or essential municipal services are disrupted. At that point, refusing to pay may sound principled, but elected officials also have to answer to the people whose lives are being disrupted. That creates enormous pressure to restore those services as quickly as possible.”

TD becomes the first bank in Canada to digitize direct deposit switching

Posted in Commentary with tags on August 11, 2026 by itnerd

TD has launched a new mobile-first experience that helps clients securely set up or switch payroll direct deposit within the TD app. With most employers, the process can be completed in about a minute, reducing paperwork and helping clients manage an everyday banking task more simply and conveniently.

The launch reflects TD’s continued focus on simplifying everyday banking by digitizing routine tasks, while delivering that convenience within the trusted, full-service banking relationship clients expect. The feature helps reduce administrative steps traditionally associated with updating payroll information, including paper forms and employer coordination.

Key takeaways:

  • Switching direct deposit is now faster and simpler: Clients can set up or switch payroll direct deposit online in about a minute, with most employers, using a guided experience in the TD mobile app.
  • A first among Canada’s Financial Institutions: TD is the first financial institution in Canada to offer a fully integrated in-app payroll direct deposit switching experience.
  • No paperwork and manual coordination: The digital process eliminates forms and reduces the need for contacting employers or payroll providers directly.
  • A more secure way to manage payroll information: The in-app experience helps reduce the need to share sensitive banking information through paper forms or email, helping lower the risk of manual data-entry errors and unnecessary exposure.
  • Making it easier for clients to establish TD as their everyday banking account: The secure, digital setup simplifies the direct deposit onboarding process, helping clients move their everyday banking with confidence, not just with speed.

For many Canadians, updating payroll direct deposit has historically involved paperwork and coordination with employers or payroll providers. TD’s new in-app experience helps simplify the process, giving clients a faster and more convenient way to update where their pay is deposited.

With the new in-app experience, clients can:

  • Set up or switch payroll direct deposit in about a minute, with most employers
  • Avoid printing, scanning or emailing sensitive financial documents
  • Reduce the risk of manual data-entry errors
  • Keep banking information secure within the TD mobile app

By simplifying a traditionally manual process, TD is helping clients spend less time on administrative tasks and more time focused on what matters most, backed by the scale, security and advice of one of Canada’s leading banks.

A first among Canada’s Financial Institutions

Built in collaboration with Atomic, a U.S.-based fintech company powering embedded banking infrastructure, including direct deposit switching, bill and subscription management and payment switching, TD is the first bank in Canada to offer a fully integrated, in-app payroll direct deposit switching experience. TD holds exclusive Canadian rights to this capability through the end of 2026, reinforcing the Bank’s focus on delivering innovative digital experiences that help meet client needs.

The launch also supports TD’s “digital first, human always” approach, combining modern digital convenience with the security, trust, advice and support that clients expect from a full-service bank.

In collaboration with Atomic, TD is making a once-manual banking task faster, simpler and more secure for Canadian clients on the mobile app, delivering an innovative digital experience that puts clients at the centre.

Q&A: Digital Direct Deposit in Canada

What is digital direct deposit switching?
Digital direct deposit switching allows TD clients to securely update where their paycheque is deposited without completing paper forms or contacting their employer directly. Clients can choose which eligible TD account, including chequing, savings or unsecured line of credit, they want their direct deposit moved to, and with most employers, the process can be completed in about a minute, within TD’s secure mobile app.

If a client’s employer or payroll provider is not currently supported, clients are guided to a pre-filled manual form to complete the process.

How do TD clients switch direct deposit in Canada?
With TD Digital Direct Deposit, clients can follow a guided process in the TD mobile app to securely update their payroll information without needing to locate account details or submit forms. With most employers, the process can be completed in about a minute within the TD app.

How long does it take to switch using TD Digital Direct Deposit?
Digital Direct Deposit is designed to be completed in about a minute, with most employers, within the TD app, allowing clients to quickly update where their pay is deposited.

Is it safe to use TD Digital Direct Deposit to change direct deposit online?
TD Digital Direct Deposit helps reduce the need to share sensitive banking information through email or paper forms by keeping the process within TD’s secure digital banking environment, lowering the risk of errors and exposure.

Do I need to contact my employer to change direct deposit when using TD Digital Direct Deposit ?
With most employers, TD Digital Direct Deposit reduces the need for manual coordination by providing a guided in-app experience. If an employer or payroll provider is not currently supported, clients are directed to complete the process using a manual form.

LexisNexis pulls data services offline after unusual activity on a third-party vendor’s servers

Posted in Commentary with tags on August 11, 2026 by itnerd

LexisNexis has taken three Nexis products, Diligence, Metabase API, and Newsdesk, offline after detecting unusual activity on a third-party vendor’s servers. No data exposure has been confirmed, and the company says it isn’t connected to last week’s separate Metabase Cloud SQL injection zero-day that hit Framework and Tally.

More details here: LexisNexis shuts down services after suspicious activity on servers

The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online.

“Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week.

“To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems.”

Amit Shuster, VP Product & Engineering, Vetric had this to say:

“An outage like this doesn’t announce itself as a security story. It shows up as teams that suddenly can’t see what they could see yesterday, even though nothing in their own environment changed. For investigators and trust and safety teams working time-sensitive cases, lost visibility means a stalled case, and threats don’t pause while service is restored. That’s why the organizations on the front lines are getting deliberate about resilience, working with partners alongside their existing sources, so one provider’s bad week never becomes their blind spot.”

This is a security story. And I hope that LexisNexis is honest about this so that we can all learn from it not to mention find out what happened and how it was addressed. Not to mention that the vendors that you work with are your weakest point and every organization needs to address this ASAP.