Archive for August, 2026

Encrypted Reasoning Cracked Across Anthropic, OpenAI & Google

Posted in Commentary with tags , , on August 11, 2026 by itnerd

Researchers from MATS Research, the Max Planck Institute for Intelligent Systems, the ELLIS Institute Tübingen, Snyk, and the University of Tübingen have found a way to crack encrypted reasoning logs across all three major AI providers.

The researchers found that encrypted reasoning blocks can be passed between compatible models within the same provider’s ecosystem. By feeding an encrypted reasoning block generated by a more capable, heavily safeguarded model into a weaker, less restricted one, they were able to force the weaker model to decode and reproduce the previously hidden reasoning in plain text, without ever directly attacking the more capable model.


“By porting a valid authenticated encrypted reasoning blob across this security gap, an attacker circumvents the frontier model’s alignment entirely, using the weaker, more compliant model as an unwitting decryption oracle,” researchers explain. 

The root cause is an architectural design choice: all three providers appear to use a single global encryption key shared across their entire model family. This means encrypted reasoning blocks are not tied to the session, account, or model that created them. A reasoning block generated by one user, on one model, in one session, can be picked up and decoded by a completely different user using a different model in a different session entirely.

This vulnerability was present in the latest AI models from Anthropic, OpenAI, and Google.

This vulnerability was tested in the real world as well. Researchers scraped 315,320 encrypted reasoning blocks from publicly available repositories and decrypted:

  • 367 Personally Identifiable Information (PII) artifacts
  • 182 credentials
  • 62 API keys
  • 33 passwords
  • 30 personal email addresses

They also demonstrate cases where information hidden in the model’s reasoning was significantly more sensitive than what appeared in the model’s final, visible response, including potentially harmful information that the model had refused to provide in its final answer.

You can find the full research paper here: https://arxiv.org/pdf/2608.09867

Voldemaras Kadys (https://www.linkedin.com/in/voldemaras-kadys/), the Head of Security at Cybernews, with over 15 years of experience in cybersecurity and IT infrastructure, comments:

“The most interesting part of this research is that the researchers didn’t need to ‘break’ the encryption in the traditional sense. They found that encrypted reasoning traces could be passed between compatible models within the same provider’s ecosystem, effectively turning a weaker model into a master decryption key.

The main lesson here for users and organizations is this: if you’re using AI with sensitive inputs or outputs, treat chat logs as sensitive data, even when they look like meaningless encrypted text.

Those encrypted blocks can contain credentials, personal information, and other sensitive data that isn’t visible to the person sharing the log.

As this research demonstrates, encryption doesn’t necessarily make that information inaccessible, and the barrier to decrypt it may be much lower than users expect.”

This further dents the reputation of AI. Thus it might be worth a look at your use of AI to see if anything sensitive is making its way into the public domain.

SOCRadar Named No. 542 on the 2026 Inc. 5000 List, the Most Prestigious Ranking of America’s Fastest-Growing Private Companies 

Posted in Commentary with tags on August 11, 2026 by itnerd

SOCRadar, a global leader in extended threat intelligence and cybersecurity, today announced it has been ranked No. 542 on the 2026 Inc. 5000 list, the annual list of the fastest-growing private companies in America. The list is the most prestigious ranking of the nation’s most successful independent and entrepreneurial businesses, recognizing companies that have achieved remarkable growth while driving innovation, creating jobs, and shaping the future of the economy. Past honorees include companies such as Microsoft, Meta, Chobani, Oracle, and Patagonia. 

This year’s Inc. 5000 recognizes a new class of companies redefining what growth looks like. From AI and advanced manufacturing to healthcare, consumer products, and professional services, these businesses are expanding their impact, creating jobs and proving that entrepreneurial ambition continues to fuel the U.S. economy. Among the 5,000 companies on the list, the median three-year revenue growth rate was 130%, and those companies have collectively added more than 627,208 jobs to the U.S. economy over the past three years. 

For the full Inc. 5000 list, honoree company profiles, and a searchable database by industry and location, please visit: www.inc.com/inc5000

Inc. will celebrate the honorees at the 2026 Inc. 5000 Conference & Gala, taking place October 14–16 in Dallas, Texas and the top 500 will be listed in the Fall issue of Inc. Magazine. Tickets are on sale now.

Inc. 5000 List Methodology 

Companies on the 2026 Inc. 5000 are ranked according to percentage revenue growth from 2022 to 2025. To qualify, companies must have been founded and generating revenue by March 31, 2022. They must be U.S.-based, privately held, for-profit, and independent—not subsidiaries or divisions of other companies—as of December 31, 2025. (Since then, some on the list may have gone public or been acquired.) The minimum revenue required for 2022 is $100,000; the minimum for 2025 is $2 million. As always, Inc. reserves the right to decline applicants for subjective reasons. 

Canadian SMEs Head Into Fall Optimistic But More Disciplined About Hiring and AI Investment, New Employment Hero Survey Finds

Posted in Commentary with tags on August 11, 2026 by itnerd

As Canadian businesses head into the second half of the year amid ongoing economic uncertainty, new research from Employment Hero, the global AI-powered employment platform, suggests SMEs are entering Q4 with cautious optimism – continuing to invest in talent and AI while taking a more disciplined approach to growth, hiring and productivity.  

The inaugural Employment Hero SME Pulse, a quarterly survey of 600 Canadian senior business leaders, found 58% of SMEs are optimistic about their business outlook over the next six months, compared to just 18% who are pessimistic. At the same time, businesses are taking a measured approach to growth, balancing hiring and investment decisions against continued economic uncertainty.  

Hiring remains a priority, but employers are becoming increasingly selective. More than one-third (34%) of SMEs expect to expand hiring over the next six months, while another 32% say they plan to hire selectively, suggesting businesses continue to invest in talent while taking a more deliberate approach to workforce growth.  

Technology continues to be a key part of that strategy. Nearly two-thirds (62%) of Canadian SMEs report increasing their investment in AI, signalling that businesses are moving beyond experimentation and embedding AI into day-to-day operations to drive efficiency and support future growth.

The survey also highlights the biggest challenges facing Canadian SMEs heading into Q4. Productivity (41%) ranked as the leading business pressure, followed by wages (39%) and hiring and talent acquisition (36%), underscoring the balancing act many employers face as they continue to grow while managing costs and workforce demands.  

The findings also suggest businesses remain focused on long-term growth. More than one-quarter (26%) of SMEs say expansion or growth is their primary financial focus over the next six months, while 41% are focused on maintaining a balanced approach between growth and operational stability.  

As Canadian SMEs prepare for the busy fall season, Employment Hero says the findings point to a business community that remains optimistic about future opportunities while taking a disciplined approach to hiring, investment and workforce planning. 

2,500+ Organisations and 434,000 CI/CD Pipelines Potentially Exposed in the Largest AI Supply Chain Breach of 2026

Posted in Commentary with tags on August 11, 2026 by itnerd

More than 2,500 companies and approximately 434,000 CI/CD pipelines worldwide were potentially exposed in what is believed to be the largest supply-chain attack targeting AI infrastructure in 2026.

In March 2026, threat actor group Team PCP compromised LiteLLM, a widely used open-source AI gateway. CloudSEK Threat Intelligence subsequently reconstructed the victim exposure and is now sharing details of impacted organisations to help security teams identify potential exposure and take remedial action.

The affected LiteLLM packages were reportedly available through PyPI for only around 40 minutes. However, automated CI/CD environments can download and execute dependencies rapidly, allowing even a short-lived compromise to create prolonged security risk.

Among the information potentially accessible from affected environments were AWS, Google Cloud and Microsoft Azure credentials, SSH keys, Kubernetes tokens, CI/CD secrets, repository credentials, environment variables and LLM/API keys.

CloudSEK’s exposure dataset includes high-confidence matches associated with major global organisations including NVIDIA, Samsung Electronics, Cisco Systems, Siemens, S&P Global, ServiceNow, Deloitte, Vodafone, X Corp, Zscaler, FedEx, Volkswagen, Thales and London Stock Exchange Group, among others.

CloudSEK stresses that an exposure match does not automatically confirm successful compromise, data theft or malicious use of credentials. Organisations identified in the dataset should validate their exposure and investigate relevant systems.

The Threat May Outlive the Original Attack

The significance of the incident extends beyond the malicious package itself.

Once credentials are copied from an affected environment, removing the compromised software does not invalidate those credentials. According to CloudSEK’s analysis, stolen access can potentially be reused, sold or weaponized even after the malicious package has been removed, creating the possibility of downstream attacks weeks or months later.

The FBI also issued FLASH-20260702-01 on July 2, 2026, covering cybercriminal group TeamPCP, further highlighting the continuing security concern surrounding the campaign.

CloudSEK is sharing the exposure research openly so affected organisations can identify possible exposure, rotate credentials, investigate suspicious activity and harden their environments before compromised access is reused.

AI Infrastructure Is Becoming a High-Value Target

The LiteLLM incident also reflects a broader shift in cyberattacks.

AI gateways, MCP servers, agentic systems, vector databases and other AI infrastructure increasingly sit between sensitive corporate data, identities, cloud services and systems capable of taking action.

This makes AI infrastructure an attractive target for attackers seeking access beyond a single application. CloudSEK assesses that future attacks are increasingly likely to target the AI layer precisely because of how deeply it is connected to enterprise environments.

CloudSEK AIVigil: Continuous AI Attack Surface Monitoring

The growing attack surface around enterprise AI is the security problem CloudSEK AIVigil is designed to address.

AIVigil continuously discovers and monitors exposed AI infrastructure, MCP servers, leaked AI credentials, vector databases, agentic workflows and shadow AI. It combines CloudSEK’s cyber threat intelligence with AI exposure monitoring to help security teams identify exposed assets, credentials and attack paths before they develop into wider enterprise incidents.

Check Your Exposure

Organisations can use CloudSEK’s free exposure-checking tool to determine whether credentials associated with their environment appear in the identified dataset:

Free Exposure Checker:  https://exposure.cloudsek.com/ai-supply-chain-incident 

Full Research Report: https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines 

Full List Of Exposed Companies: TeamPCP CI/CD Secret Exposure — Check if your organisation is affected | CloudSEK

UPDATE: Rohit Valia, CEO of cybersecurity company Tumeryk, provided the following comments: 

“Incidents like the recent LiteLLM supply chain compromise show that a single unrevoked token in an open source build chain can result in an ecosystem-wide exposure. Open source innovation is essential to the pace of AI development, but enterprises need more than the raw project — they need it hardened, tested, and accountable. It also needs to be put through rigorous security validation before it reaches production. Sanctioned shouldn’t just mean ‘permitted’ — it should mean proven.”

UPDATE #2: Seemant Sehgal, Founder & CEO, BreachLock adds this:

   “The malicious packages were live for 40 minutes, but the window mattered to defenders long after it mattered to the attacker. Any system that pulled 1.82.7 or 1.82.8 during those 40 minutes ran malware on every subsequent Python startup, meaning credentials harvested from those environments have been sitting in attacker hands since before most teams knew there was an incident.

   “Cloud keys, SSH keys, AI provider tokens, and package-publishing credentials from 434,000 CI/CD pipelines enable access, and access can be used quietly for a long time before anyone sees the effect. The initial scanner compromise fed LiteLLM’s CI pipeline, which pushed malware to PyPI. The affected organizations were two steps removed from the original breach, with every link in the chain working exactly as designed.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “One of the biggest takeaways from this latest LLM attack, especially when viewed alongside the recent wave of malicious NPM packages, is that sophisticated attackers are increasingly focused on the software supply chain. They’re looking for opportunities to compromise the tools and components that everyone trusts because that gives them an enormous amount of reach.

   “What concerns me most about this attack isn’t just its scope, although the scope is certainly significant. It’s how difficult it would be for many organizations to detect. These attacks often operate outside the visibility of traditional security controls.

   “In many ways, this reminds me of the early days of internet worms like Conficker, SQL Slammer, Blaster, and Nachi. Those threats spread incredibly fast, and because they were so loud, the entire security industry mobilized to detect them, contain them, and ultimately build better defenses.

   “I think we’re seeing something similar with supply chain attacks today. Right now, attackers are going big. They’re compromising widely used packages and trying to maximize their impact. My concern is what happens after this phase. History tells us that attackers eventually become more disciplined. Instead of going after everything, they’ll become more selective, targeting the specific packages, libraries, and dependencies that give them access to the organizations they actually want to compromise.

   “That’s why I see these attacks as a harbinger of what’s coming next. They’re already difficult to detect because they exist outside the normal visibility of EDR platforms, firewalls, and traditional intrusion detection and prevention systems. As attackers become more targeted and more subtle, that detection problem is only going to get harder for defenders.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “Forty minutes was the theft. Five months later, the FBI is still warning that the stolen credentials will be weaponized.

   “I’ve been tracking TeamPCP’s campaign since they hit Aqua Security’s Trivy scanner in March. LiteLLM’s CI pipeline pulled Trivy from apt without pinning a version. One poisoned build later, the attackers had LiteLLM’s PyPI publishing credentials and pushed two malicious versions that ran code at Python startup, no import needed, bypassing the install-script protections most teams count on.

   “2,500 organizations and 434,000 pipelines from that window. Automated build systems explain the math. They pull dependencies in seconds, cached layers spread them further, and a poisoned package rides the distribution network into every downstream consumer before anyone notices.

   “TeamPCP has used this playbook all year. Trivy, LiteLLM, Microsoft’s durabletask-python twice, always re-entering through credentials that survived the previous cleanup. SANDCLOCK grabbed cloud keys, Kubernetes tokens, SSH keys, AI provider credentials, everything the runner could reach. Those stolen credentials often valid until someone actively revokes them.

   “Organizations with a Software Bill of Materials (SBOM) knew within hours whether LiteLLM 1.82.7 or 1.82.8 was anywhere in their stack. A mandated delay on dependency updates, even an hour, would have cleared the entire 40-minute window before either version installed. Pin CI dependencies to verified hashes, scope runner credentials to the minimum each job needs, and if you ran either version, rotate every secret that runner could reach.”

China Attacks Vulnerabilities In Microsoft Software

Posted in Commentary with tags on August 11, 2026 by itnerd

China-linked hackers exploiting a critical vulnerability in Microsoft’s software and turning that access toward ransomware. While you can find out about the issue here, this is the TL:DR. Please read the entire chain:

Phillip Wylie, Chief Security Evangelist & Sr. Consultant, Suzu Labs (https://www.linkedin.com/in/phillipwylie)

“The biggest takeaway isn’t just another critical vulnerability – it’s that attackers are increasingly targeting the tools organizations trust most. RMM platforms, identity systems, and security products provide privileged access by design, making them ideal force multipliers for threat actors. Organizations should treat these platforms as crown-jewel assets, prioritize rapid patching, closely monitor privileged activity, and assume that even trusted management infrastructure can become an attack vector.”

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“This particular attack fits into China’s broader cyber great power initiative that they’ve been working on for well over a decade, building the capability to exploit and gain access to as many systems as possible. I tend to think this particular attack was triggered by the vulnerability being discovered. China may have already been exploiting it for some period of time before the vendor publicly disclosed it on July 31.

“And this gets into a larger question that I think we need to ask whenever we see nation-state attacks suddenly transition into ransomware campaigns. What were they doing before?

“Remember, with a nation state like China, Russia, or even the United States, the primary goal generally isn’t ransomware. The goal is access. They want to dwell inside environments and maintain that access for as long as they possibly can. The way this particular attack has been linked to China leads me to believe the vulnerability may have been used for that type of access and persistence for some period of time. But once the vulnerability became public and a patch was available, its usefulness for longer-term nation-state operations dropped significantly. At that point, you might as well transfer the capability over to ransomware operations and extract whatever remaining value you can from the vulnerable systems that are still out there.

“There’s another issue here involving the vendors we choose for core security technologies, especially RMM tools. We really need to question whether we should be self-hosting these systems at all. If it’s a cloud service, the provider can potentially patch and update that service very quickly across its entire customer base. If you’re self-hosting it, you’re now dependent on your own organization getting that patch deployed as quickly as possible. And that matters here. Some of the research we’ve been seeing indicates that more than 25% of these servers may still be unpatched and vulnerable to this attack.

“Once again, this highlights one of the major problems with on-premises technology when a serious vulnerability drops. Getting a patch is one thing. Getting that patch deployed everywhere fast enough to matter is something completely different.”

The threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the CISA KEV catalog on August 3, 2026. You should apply all updates to your Windows systems and Microsoft Defender for Endpoint detects this activity. So update that too.

Park Place Technologies Named to Inc. 5000 List of America’s Fastest-Growing Private Companies for Tenth Time

Posted in Commentary with tags on August 11, 2026 by itnerd

Park Place Technologies has been named to the 2026 Inc. 5000, the annual list recognizing the fastest-growing private companies in America.

Park Place earned the No. 4,874 spot on this year’s ranking, rejoining the list after narrowly missing the cutoff in 2025; it has received this recognition for 10 years. The Inc. 5000 has become one of the most respected measures of entrepreneurial success and sustained business growth in the United States, recognizing companies that have demonstrated significant revenue growth while navigating changing market conditions.

Since its founding in 1991, Park Place Technologies has built a global presence serving organizations across industries with third-party maintenance, managed services, professional services, IT asset disposition and network monitoring solutions. The company’s continued growth reflects increasing demand for flexible, cost-effective alternatives that help enterprises optimize their technology investments.

This year’s recognition marks another milestone in Park Place’s history of appearances on the Inc. 5000.

The 2026 Inc. 5000 celebrates the private companies that have achieved remarkable growth over the past three years, representing a wide range of industries that are shaping the future of the U.S. economy.

OpenAI flags upcoming AI model as potential critical cybersecurity risk 

Posted in Commentary with tags on August 10, 2026 by itnerd

OpenAI said it cannot rule out that its upcoming AI model, Astra, possesses “critical” cybersecurity capabilities, prompting the company to pause some internal development activities and activate enhanced safety protocols. Under OpenAI’s Preparedness Framework, the designation applies to models that could autonomously discover and exploit zero-day vulnerabilities or carry out sophisticated cyberattacks capable of causing severe real-world harm.

“OpenAI said Astra will not be released until additional safeguards are in place and the company is confident the model does not exceed its acceptable risk thresholds. The move comes amid increasing scrutiny of frontier AI models following recent incidents in which advanced systems demonstrated unexpected autonomous cyber capabilities during security testing.

John Strand, Owner, Black Hills Information Security, Inc.:

“The big question I have about this statement from OpenAI is, why now?

“I mean, now is fine. But why not months ago?

“You have the leaders of these companies constantly warning everyone about the dangers of artificial intelligence. Yet when we look at the escapes that happened with OpenAI and the escapes that happened with Anthropic, it certainly looks like they had very, very poor security controls around AI, especially when it comes to security and vulnerability research.

“So I guess it’s great that they’re now saying they’re going to slow down and put additional safeguards in place. But remember, these are the same people who were warning the rest of us about the need for safeguards more than a year ago.

And they didn’t do it themselves.

“That’s the part I have a problem with. I don’t think we can simply trust AI vendors to police themselves. There needs to be some type of meaningful oversight and accountability. As much as these companies may hate that idea, they have demonstrated again and again that we cannot simply assume they’re going to do the right thing on their own.

“We have to find some way to start holding these companies accountable. Otherwise, what exactly is going to force them to change?

“There’s another part of this that bothers me even more. I seriously think both Anthropic and OpenAI looked at having a gigantic offensive AI escape and saw it, at least partially, as a marketing opportunity rather than a reason to pause and seriously reflect on what they were doing.

“And that should concern everyone.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Astra reaching the point where OpenAI cannot rule out critical cybersecurity capability under their own Preparedness Framework is a real capability shift, and pausing internal development activities until they understand what they have is the right call. The technical discipline here is in knowing where the boundary sits between a model that found something in a controlled test and one that can operate reliably across the unpredictable configurations, detection gaps, and trust relationships that exist in live environments.

“The organizations that have spent years mapping how attackers actually move through real infrastructure, particularly those of us building autonomous systems to do that work safely at scale, will recognize this problem quickly, because we’ve been solving the human version of it for a long time.”

Nick Mo, CEO & Co-founder, Ridge Security Technology Inc.:

“This isn’t surprising. The Mythos news and the series of cyberattacks from frontier models, including the Hugging Face attack, have already shown that these models hold significant power.

“The unsettling fact is that open-source, open-weight models have similar capabilities. With so many ‘abliterated’ models in the market, bad actors are already using these advanced capabilities for malicious purposes. Self-policing and limiting access for legitimate customers only makes the cybersecurity landscape more challenging.”

AI clearly has been burned by its recent hacking episodes. Maybe OpenAI will make it so that there’s less perceived risk? I guess we’re about to find out.

Meta launches open-weight AI model as Zuckerberg pushes for fewer U.S. restrictions

Posted in Commentary with tags on August 10, 2026 by itnerd

Meta launched Muse Glimmer, a new open-weight AI model designed to perform agentic tasks directly on a Mac or PC using a single graphics card.

CEO Mark Zuckerberg also said Meta plans to release the weights for Muse Spark 1.2, its most advanced model, and called for U.S. policies that make it easier for American companies to compete with Chinese open-weight AI developers.

Reports noted that Hugging Face recently used a Chinese open-weight model to defend against an attack by a rogue OpenAI model because closed models restricted certain cybersecurity uses. Zuckerberg also said Meta will establish a governance structure giving independent directors authority to approve safety criteria for future model releases.

Doc McConnell, Head of Policy and Compliance, Finite State:

   “Today’s essay from Meta on a “Positive AI Future” focuses on the theoretical benefits of widespread, accessible AI for the public. The cybersecurity industry is primed to be receptive to this message after hearing the same lofty promises all last week during the Black Hat and DEF CON conferences in Las Vegas. But to achieve this positive future, society needs a way to select the best model, not the cheapest, or the first-to-market, but the one that users can rely on.

   “As companies race to produce competitive AI, the market will ultimately reward those that provide the greatest transparency into how they’re built, how they work, and how they stay safe and secure.

   “The AI labs are expecting users to trust their products with their most sensitive information: personal preferences, medical history, customer data. The labs need to earn that trust.”

Meta hasn’t earned my trust. And I expect that others feel that way. The question is can they earn that trust back and keep it.

Suisin City, CA hit with cyberattack and declares state of emergency 

Posted in Commentary with tags on August 10, 2026 by itnerd

Over the weekend, Suisin City, California declared a state of emergency in light of a cyberattack that impacted critical services like 911 routing, police and fire dispatch and more.

After malicious software infected systems, the city shut down its entire IT network to contain the threat and preserve evidence.

More info is available here: https://www.suisun.com/Community/20260807Cybersecurity-Incident-Updates

Arvind Parthasarathi, CEO and founder, CYGNVS had this to say:

“What happened in Suisun City shows why cyber recovery is fundamentally an operational resilience issue. Malware affected systems supporting 911 routing, police and fire dispatch, records and other municipal services, forcing the city to shut down its IT network. The fact that dispatchers were able to shift 911 operations to Solano County and keep emergency calls moving is exactly the kind of continuity organizations need to plan for before an incident occurs.

With the city’s systems still offline and every network function needing to be inspected and cleared before restoration, the next challenge is coordinating a safe recovery.

 Organizations should have an out-of-band command center ready to bring together security, IT, legal, risk and compliance teams with external counsel and forensics providers. Those teams need tested playbooks and regular tabletop exercises so that when critical systems go down, they already have the muscle memory to maintain essential operations, investigate the incident, restore systems safely, and manage regulatory and stakeholder reporting.”

This is all good advice that organizations should follow. The question is if organizations will follow it.

UPDATE: Seemant Sehgal, Founder & CEO, BreachLock had this comment:

“Municipal IT and security teams, more often than not, operate under resource constraints that most enterprise security organizations would find genuinely difficult to imagine, and when you see three incidents like this in the same news cycle, it’s clear that attackers have figured that out.

“Suisun City, Coweta, Washburn County — these are not outliers, they are a pattern, and the pattern tells us that local government infrastructure is being treated as a reliable target. The people responding to these incidents are doing exactly what you do when you have limited staffing and a network that cannot go dark for long without causing a real emergency, and the hard reality is that the window between ‘contained’ and ‘encrypted’ is often shorter than any reasonable detection and response process can close.”

Ashley Knowles, Security Consultant for Black Hills Information Security, Inc.:

“City services are always a lucrative target due to attackers’ ability to directly impact critical services, residents, and sensitive data. Government IT departments often operate with constrained budgets while wearing multiple hats, and in the age of AI-assisted attacks, that combination makes municipalities a prime target. That said, it appears the city made the right calls, which underscores exactly why having a business continuity plan and regularly practicing it is so important.

“From here, the focus will likely shift to forensic investigation to identify the root cause and initial access vector, followed by a methodical restoration of systems from known-good backups. The declared State of Emergency positions the city well to access the resources needed for a full recovery while federal partners assist with the investigation.”

John Strand, Owner, Black Hills Information Security, Inc.:

“Once again, I think a lot of these local IT departments for cities and counties are doing the right thing by pulling the plug and shutting things down as quickly as possible before the attack has an opportunity to spread. In the middle of an active attack, sometimes that is absolutely the right move.

“But what I hope is happening with these breaches is that they’re hitting the news enough that they’re starting to reach mainstream consciousness. Municipalities all over the United States need to realize that they have to start being proactive about their security. They can’t just sit back and hope they don’t get hit.

“They need to start having honest conversations about where they actually stand. They need security assessments performed by professionals who can look at the organization as a whole, identify the total security risk, and determine just how exploitable that organization actually is.

“We’re seeing attacks against water systems. We’re seeing attacks against municipalities. And these attacks seem to be kicking up quite a bit.

“I just hope we’re finally reaching critical mass in the mainstream news space where counties and cities start to wise up and move a little bit faster with their computer security programs.

“Because at this point, simply hoping you’re not going to be the next municipality that gets hit is not a security strategy.”

Denis Calderone, CTO, Suzu Labs:

“Suisun City’s network shutdown is disruptive, but the dispatch handoff to Solano County is what a resilient public-safety system is supposed to look like. Whatever technical and operational arrangements were already in place between the two jurisdictions, Suisun City could take its network offline while Solano County continued receiving calls, keeping a cyber incident from becoming a public-safety failure.

 “That outcome did not happen by accident. 911 centers cannot improvise a handoff in the middle of a cyber incident. The specific technical arrangement here has not been publicly disclosed, but the ability to shift operations to a neighboring jurisdiction gave Suisun City room to contain the incident while police and fire continued responding.”

“Municipal leaders should learn from this incident and the others affecting their peers. The immediate priority in an incident like this is to contain it while preserving evidence, then determine how attackers got in, eradicate their access, and recover safely. Make sure your incident-response and business-continuity plans provide for tested backups, manual operating procedures, and workable fallback arrangements while the affected environment is offline. Be diligent about common attack paths: Internet-facing remote access, privileged accounts, gaps in MFA coverage, overdue patches, and vendor connections. Those basic controls matter, but so does gaming out these scenarios with your neighbors.”

Microsoft, Red Hat, and DH2i to Present, “Simplify Hybrid SQL Server: Windows & Red Hat OpenShift Side By Side”

Posted in Commentary with tags on August 10, 2026 by itnerd

DH2i today announced that it will join with Microsoft and Red Hat to present a live webinar titled, “Simplify Hybrid SQL Server: Windows & Red Hat OpenShift Side By Side.”

When: August 20, at 12:00 pm Eastern Time (9:00 am Pacific Time) 

What Attendees Will Learn: An increasing number of IT teams are adopting a hybrid approach that allows them to take advantage of Kubernetes for development and testing, while also continuing to run production workloads on Windows Server. Unfortunately, it is not easy to get there.

Teams have traditionally been forced to manage a patchwork of platform-limited HA solutions, endure labor-intensive networking tech and firewall manipulations, design and maintain complex ETLs to link dev/test and production, and worst of all – do it all under the looming threat of extended downtime.

Aimed at organizations looking to extend their SQL Server OLTP environments to Red Hat OpenShift, this webinar will detail a safer, simpler way that enables unified HA for hybrid clusters and leaves the door open for organizations interested in full modernization.

Microsoft, Red Hat, and DH2i will provide a walkthrough showing how to deploy a secure, cross-platform Availability Group (AG) that seamlessly bridges the gap between a Windows Server virtual machine (VM) and Red Hat OpenShift. Attendees will learn how to:

●      Automate the deployment of a Kubernetes AG cluster with an operator 

●      Securely connect replicas across platforms with Zero Trust Networking (ZTNA) tunneling 

●      Protect databases with HA automation across hybrid SQL Server environments

This walkthrough demo will help enable any IT team to take their SQL Server from legacy infrastructure to a scalable, hybrid cloud environment with Azure Red Hat OpenShift.

Featured Speakers:

●      OJ Ngo, Co-Founder and Chief Technology Officer (CTO), DH2i

●      Amit Khandelwal, Principal PM Manager – Azure Data, Microsoft

●      Vivien Wang, Sr. Engineering Partner Manager, Red Hat

Learn more and register herehttps://dh2i.com/webinar-simplify-hybrid-sql-server-windows-openshift/

Can’t make the live webinar? Register anyway and DH2i will send you a link to the full recording, following the live event.