Archive for August, 2026

UK power plant outage shows why four days of downtime matters more than attribution

Posted in Commentary with tags on August 24, 2026 by itnerd

A UK power plant reportedly went dark for four days in July after a cyberattack linked to Iranian hackers, but the story only surfaced this week, and the UK government still hasn’t confirmed or denied the incident or the attribution

The government said that at no point was there a risk to the UK’s energy system, but the Department for Energy Security and Net Zero (DESNZ) has contacted power companies to advise them about the risk of cyber attacks.

The Telegraph reported that the attack, which took place last month, was carried out by hackers affiliated to the Iranian regime.

For security reasons, neither the government nor the National Cyber Security Centre, which deals with attacks on critical infrastructure, would give further details of the site affected. However this was not an attack on an essential service such as a large power station.

Josh Picolet, VP of Detection & Analysis, Team Cymru

“State-linked activity against critical infrastructure tends to follow patterns that outlast any single incident, and the four-day recovery window here is the detail worth studying closely. That length of disruption usually means the attacker had dwell time inside the environment before detection, which points to a gap in visibility rather than a one-off failure.

It’s worth noting the UK government has neither confirmed nor denied the incident or the attribution to Iran-linked actors, so defenders should treat the public reporting with appropriate caution while still taking the operational lesson seriously. Regardless of formal attribution, the pattern is consistent with what we’ve tracked from Iran-affiliated groups against critical infrastructure across the US, Israel, the Gulf, and now Europe this year. Smaller operators in particular need intelligence that surfaces staging and pre-positioning activity, not just indicators tied to a confirmed actor, because the next facility targeted may not get four days of warning before impact.”

Justin Beals, CEO & Founder, Strike Graph

“Four days of downtime at a critical infrastructure facility is not a technical failure. It’s a governance failure. Somewhere in that plant’s compliance program, a control existed on paper that didn’t hold up in practice, and nobody caught the gap until an adversary found it first.

This is the same story we keep seeing across sectors. Organizations treat security posture as something you attest to once a year, not something you verify continuously. A point-in-time audit tells you a plant was secure on the day someone checked. It tells you nothing about the day the attacker showed up.The UK has thousands of smaller energy assets like this one, and most of them are operating on the same annual-attestation model. If this attack is repeatable, and there’s no reason to think it isn’t, the operators still relying on periodic reviews instead of continuous monitoring are the ones who will be explaining a multi-day outage to their regulator next.”

Expect more state sponsored actors to do hacks like this. Because there’s likely more of this out there that is under reported.

UPDATE: John Strand, Owner, Black Hills Information Security, Inc. Had This To Say:

   “This particular breach scares me, not necessarily because it happened in the United Kingdom, but because of how much further behind the United States power grid is compared to Europe. Modernization of the U.S. power grid has been painfully slow for a number of reasons, including legislative capture and the basic economics of how utilities make money. They make money from generating and selling power. They don’t necessarily make money from updating aging infrastructure.

   “Then there’s the interconnected nature of the U.S. power grid, with Texas being the notable exception. A relatively small problem at a substation can create ripple effects across multiple areas of the grid. That’s what makes this such a serious wake-up call. When you combine that interconnectedness with the incredibly slow pace of infrastructure modernization, especially across the power grid, I’m very concerned. I think an attack like this could potentially have a far greater impact in the United States than what we’re seeing in Europe.”

Denis Calderone, CTO, Suzu Labs:

   “What has our attention here is not the size of the generator. A savvy attacker isn’t choosing targets based on grid capacity. They’re probing for the weakest point in the armor, and a facility small enough to fall below mandatory cyber reporting thresholds is exactly the kind of target that’s likely under-defended and overlooked.

   “Two weeks ago in Poland, a compromised wind farm became a direct bridge into a completely separate heating plant’s SCADA system through a shared cellular network. Different threat actor, different country, same playbook: find the overlooked facility, use it as a stepping stone. We’ve been tracking Iran-linked operations against Western critical infrastructure since April, and the pattern keeps escalating. PLCs targeted for operational disruption. Gas station fuel monitoring systems. Water systems across 12 US states in a single month. Five agencies flagged AI-generated tools targeting Siemens PLCs four days ago. And now a UK power facility goes dark for four days.

   “The victim became the victim because of poor hygiene. The advice here is the same as it ever was, because the exposure hasn’t changed. Take controllers off the internet. Change default credentials. Inventory every communication path, especially the integrator-installed remote access links and the backup channels that never made it onto a network diagram. But critical infrastructure operators need to be proactively hunting for these weaknesses and prioritizing remediation before an adversary does the discovery for them. The smaller satellite sites are often the ones that fall under the radar during security reviews, so make sure you look at everything. Small and overlooked is exactly what made this target attractive.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

   “There is a real and growing threat to critical infrastructure, however the way we talk about these incidents matters.

   “If this was genuinely a historic cyber-induced shutdown of a British power generator, then operators need to know what made it possible.  Was a PLC directly exposed to the Internet?  Was remote access compromised?  Did attackers manipulate the physical process, or did operators shut the plant down defensively after an IT compromise?  What control would have broken the attack chain?

   “Don’t tell me this was historic and then redact the history.

   “We can protect the identity of the victim and sensitive operational details while still publishing a sanitized technical account.  CERT Polska has shown what responsible disclosure can look like: explain the attack path, identify the class of failure, and give other operators something they can actually use to defend themselves.

   “The same caution applies to attribution.  “Iran-linked” is not the same thing as proving that the Iranian government directed the attack.  We should distinguish what happened to the plant, who conducted the intrusion, and by which nation state it was instructed.  Attribution in cyberspace is an analytical conclusion, not something you read off the source IP address.

   “The larger problem is that too many cyber incidents and near misses disappear into non-disclosure or tightly held incident reports.  One operator learns an expensive lesson while thousands of others are left to learn it again.  The point of incident reporting should not simply be counting attacks.  It should be making the next attack harder.

   “We keep sweeping these incidents and near misses under the rug when we should be dragging them into the light and learning from them.

   “If joint cybersecurity advisories can say what went wrong in Minnesota without handing attackers a blueprint, we should be able to tell operators what class of failure took a British peaking plant offline for four days.”

Seemant Sehgal, Founder & CEO, BreachLock: 

   “OT in power plants and water treatment facilities wasn’t designed with adversarial persistence in mind. The visible coordination across a UK facility and dozens of US water systems in the same window indicates that these environments are being mapped and tested well before the disruptive payload arrives. 

   “The teams running these facilities need to know which of their OT assets are reachable, how an attacker would move from IT into operational systems, and where their recovery dependencies sit, because it’s already too late to be asking those questions by the time the outage clock starts.”

SOCRadar Now Offered Through GuidePoint Security 

Posted in Commentary with tags on August 24, 2026 by itnerd

SOCRadar today announced a new reseller collaboration with GuidePoint Security, the leading cybersecurity solution provider that helps organizations make better decisions that minimize risk. The collaboration is designed to expand customer access to SOCRadar’s award-winning Extended Threat Intelligence platform through GuidePoint’s extensive network of enterprise and public sector customers. 

As organizations face increasingly sophisticated cyber threats, SOCRadar’s comprehensive threat intelligence capabilities and intelligence-driven approach, combined with GuidePoint’s proven advisory and integration expertise, enable customers to proactively identify, assess, and mitigate external risks before they impact business operations. 

SOCRadar is the pioneer of Agentic Threat Intelligence serving organizations across more than 150 countries. The company’s award-winning Agentic Threat Intelligence Platform delivers an industry-first early warning cyber risk detection and mitigation system to proactively identify and reduce external cyber threats before attackers can exploit them. The platform uniquely combines AI agents with one of the industry’s most comprehensive cyber intelligence ecosystems to continuously discover, investigate, and prioritize risks across the internet, deep web, dark web, social media platforms, third-party ecosystems, and exposed digital assets. Integrating Brand Protection and Attack Surface Management (ASM) through its XTI platform, SOCRadar helps customers defend against external threats like phishing, brand impersonation and ransomware, as well as account takeover, exposed credentials, supply chain risks, and emerging attacker activity. 

Android’s nude-scanning app keeps reinstalling itself – and Google is opening access to other developers 

Posted in Commentary with tags on August 24, 2026 by itnerd

Android users were shocked last year to find Android System SafetyCore installed on their devices without consent, silently “scanning” content. Google is now developing an API that makes the content classification functionality available to third-party apps.

Cybernews looked into what SafetyCore does, the new Content Safety Manager API, and whether malicious apps or spyware could abuse it to scan for sensitive images.

Key findings:

  • SafetyCore performs image classification on the device to prevent users from seeing nudity when they receive, send, or forward messages in Google Messages.
  • Google states that this feature doesn’t send identifiable data or any classified content or results to Google’s servers.
  • Android just introduced a new API for developers – Content Safety Manager. It uses the on-device content safety service to classify content and exposes this functionality to app creators.
  • The API can accept images but also other media types, and returns four broad types: allowed / warning / blocked / unclassified.
  • Google doesn’t have complete control over what third-party apps do with the data.
  • Combined with excessive permissions, a malicious app could abuse the content-scanning capability to inspect large amounts of user content. This could lead to privacy-invasive profiling, or much worse – exfiltrating sensitive photos or other private data, and potentially even demanding a ransom.
  • According to Google Play Store, Android System SafetyCore has over 1 billion downloads and an average score of 3.6 stars from nearly 240,000 reviews.

Here’s the full article: https://cybernews.com/security/android-content-safety-manager-api-privacy-concerns/

Review: PuraSIM travel eSIM

Posted in Products with tags on August 22, 2026 by itnerd

Let’s face it, travelling internationally with your cell phone is expensive by Canadian standard. So many Canadians look for a eSIM to supplement their travel activities. Specifically a data eSIM as they want to get to their social media and email while they travel. Which is why I am testing out the PuraSIM over the next few days. In short, it promises “1 minute” activation and data in 218 locations. So, let’s see if that is true.

First I went to PuraSIM.com/en to get my eSIM. I picked North America and 1GB of data as I was only testing the eSIM. But the 1GB would last me 30 days. Thus if I were staying longer, I would have picked a higher data bucket. I then got the cost and paid nothing for the eSIM as PuraSIM provided me the eSIM for free. Then I got a couple of emails:

  1. An email with the invoice. That was ignored.
  2. An email with the QR code to install the eSIM. That was of more interest to me.

I used the second email to scan it with my phone’s camera. It started the wizard on iPhone that installed the eSIM. The website promised “1 minute” activation. It was closer to four. But I won’t hold this against them as I am guessing that this is an iPhone thing.

Curiously, I connected to Rogers Wireless with the PuraSIM:

For me this is an interesting development as I didn’t expect that.

From there, I tested the PuraSIM eSIM. First I tested the signal strength which was easy as both eSIM’s were live in the same phone. The PuraSIM won out as it got 3 bars to the 2 bars that Freedom Mobile got. I also did some tests to make sure that data worked with the PuraSIM which it did. So I decided to do something harder. I streamed BBC World Service from my car. Meaning that constant streaming combined with entering and leaving underground parking would test this eSIM to see if it was better than what Freedom Mobile offers. I literally found no difference between the two which isn’t a bad thing. And my streaming experience wasn’t any different. So I would expect that if you are used to a given carrier – Good or bad – it will be a smilar experience here.

Downsides? Not really. But I did use a SIM (a physical one to be clear) in 2023 which had a local number which was France. That came in handy when I had to make local calls. I would love to see a SIM or eSIM company do that for travellers as that makes life a bit easier. But that’s an industry problem and not a PuraSIM problem.

What I would do is to go to PuraSIM.com/en to see if your destination is covered and what the cost would be for data would be for the region that you are going to. Chances are it’s going to be cheaper than your cell phone carrier which make this eSIM a total win.

NCSC urges stronger security controls for agentic AI 

Posted in Commentary with tags on August 21, 2026 by itnerd

 The UK’s National Cyber Security Centre (NCSC) urging organizations deploying agentic AI systems to follow stronger security controls, here are four experts with comments on these recommendations.

Agentic AI systems have shown potential to transform how organisations work, at times delivering unparalleled productivity gains. They can automate complex workflows, reduce routine effort and enable people to focus on higher-value tasks.

As organisations deploy increasingly autonomous uses of AI at pace, it is important to consider how these systems behave when they do not function as envisaged or expected – and plan accordingly.

Recently, there have been several incidents involving AI models and agentic AI systems carrying out unsanctioned or unintended activity. These events highlight why organisations need to carefully consider how these technologies are deployed, constrained, observed and responded to.

John Strand, Owner, Black Hills Information Security, Inc.:

“I absolutely love this.These recommendations and guidelines actually look like they were written by people who have spent time working with AI and testing these systems in the real world. They’re practical, they make sense, and frankly, I wish we’d had guidance like this five years ago. But we’ll take it now. Once again, it feels like the EU is considerably further ahead of the United States when it comes to establishing meaningful guidance and requirements around how these tools are tested and used.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Agentic AI changes the security model because software is no longer just responding to instructions; it is making decisions and taking actions on its own. Giving an AI agent broad access without clear guardrails is similar to handing out privileged accounts without oversight. The strongest offensive security approach is to treat every agent as a potential point of failure, limit what it can reach, require human review for high-impact actions, and continuously verify that its behavior matches its intended purpose.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“The NCSC published a controls checklist for a problem most organizations haven’t scoped yet. Sandboxing, least privilege, human approval gates, continuous monitoring, all sound right. They also assume you know which agents are running in your environment, what credentials they hold, and which systems they can reach. Most enterprises cannot answer those questions.

“Shadow AI is harder to inventory than shadow IT ever was. An employee spinning up a SaaS application left a procurement trail. An employee configuring an AI agent inside an already-approved platform like Salesforce or Microsoft 365 leaves none. The agent inherits the platform’s existing access, never triggers a security review, and no one in procurement knows it exists.

“The gap widens when agents acquire credentials at runtime, spawn subagents, or chain actions across multiple systems in a single task. Every delegation step creates an identity your IAM system was never designed to track. Most organizations have no ownership model for agent identities and cannot trace an agent’s action back to the human who authorized it.

“These recommendations are step three of a three-step problem. Step one is discovery, mapping which agents exist and who deployed them. Step two is measurement, tracking what those agents actually do at runtime. Most organizations are stuck on step one.

“You cannot sandbox what you have not found. You cannot scope permissions for credentials you have not inventoried.”

Doc McConnell, Head of Policy and Compliance, Finite State:

“This NCSC guidance shows that the recent incidents of autonomous AI agents breaking out of testing environments and executing cybersecurity intrusions have already shifted the risk calculus.

“The NCSC offers two specific pieces of guidance that feel provocative in a time when so many organizations are racing to implement agentic AI in faster, more autonomous ways. First, the NCSC recommends formal threat modeling of AI escape scenarios. Second, it applies a familiar ‘zero trust’ model to agentic AI, including robust sandboxing and deny-by-default permission structures. This shifts the conversation around AI governance from treating agents as potentially reckless to treating them as actively adversarial.”

I pretty much said it earlier today but I will say it again. If you are running AI without guard rails, you are asking for trouble. Organizations need to take that into account or bad things wll happen.

FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

Posted in Commentary with tags on August 21, 2026 by itnerd

The SOCRadar Threat Research Unit has unveiled a delivery technique that they haven’t seen documented before: threat actors are hiding staging commands inside FTP server banners, the greeting text a server sends when you connect to port 21.

Key details

  • Threat actors are hiding malware staging commands inside FTP server banners – the greeting text a server returns on port 21. A shortcut file connects, reads the banner, executes what’s in it. Nothing malicious in the file itself.
  • This is a dead drop resolver on a protocol nobody inspects for content. The technique has not been documented before.
  • Live since early July 2026 and still operational.

Full research can be read here: https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/ 

 AI data giant Alation confirms cyberattack

Posted in Commentary with tags on August 21, 2026 by itnerd

Days after reporting an incident affecting a number of its customers, enterprise data giant Alation today confirmed a cyberattack. Alation has not yet specified the nature of the cyberattack, mentioned the root cause of the incident, or said how many customers are affected. 

When reached by TechCrunch about the incident, the company said it was investigating.

“Alation recently identified an isolated incident involving unauthorized activity in one of its systems,” the company said in a statement provided to TechCrunch by an external representative, Stephen Russell. “We are conducting a thorough investigation of what occurred and we will provide additional information as appropriate.”

Alation did not specify the nature of the cyberattack, mention the root cause of the incident, or say how many customers are affected. The company did not say if it had alerted its customers to the incident or what defensive actions, if any, they should take following the intrusion.

On Tuesday, Alation reported an unspecified incident that resulted in “degraded availability” for some of its customers. The company said it had resolved the incident within an hour.

Much of the company’s systems are hosted on Amazon Web Services. It’s not immediately clear if any data was stolen or exfiltrated during the incident.

Commenting on this news is Dan Moore, Sr. Director, CIAM Strategy & Identity Standards at FusionAuth: 

“A data catalog breach gives attackers a guided tour of how your organization “thinks” and where the valuables are hidden. After a breach like this, the bad guys now know how you classify what’s sensitive, who can access it, and how it all connects. This stolen knowledge remains valuable for years because of data gravity. It’s difficult to remediate, because you can’t simply change passwords or rotate tokens.”

It sucks for Alation because it sounds like we’ll never find out who the threat actors were and how they were kicked out of the network. Assuming that they were kicked out of the network.

T-Mobile physically cuts network connection to eject Salt Typhoon hackers

Posted in Commentary with tags on August 21, 2026 by itnerd

New reporting by Bloomberg details how T-Mobile detected and removed China-backed Salt Typhoon hackers from its network during the group’s widespread 2024 campaign against telecommunications companies. T-Mobile security teams spent months searching for the attackers before identifying unusual activity reaching one of its systems through a router that was powered off but communicating with another T-Mobile machine. After locating the compromised equipment, T-Mobile cybersecurity chief Jeff Simon and three colleagues went to a data center near the company’s Bellevue, Washington headquarters and physically cut the cable connecting the system to the outside world. T-Mobile largely avoided the broader compromise experienced by other organizations targeted in the campaign, which affected hundreds of telecommunications companies, internet providers and data center operators and sought phone records and information on senior U.S. officials.
 

Larry Pesce, VP of Services, Finite State:

   “Credit first: T-Mobile’s team hunted down Salt Typhoon in days when peer carriers had them resident for months, and that’s genuinely impressive work. But this article is written for a general audience, and it shows. It reads like a movie script, complete with the team piling into the CSO’s Tesla, and for anyone who has actually run an incident it leaves a lot of important questions on the cutting room floor.

   “Start with the powered-off router in California. The likely explanation for the spoofing is mundane: the attackers were working from stale topology data and impersonated a device they didn’t know was dark. That mistake is probably what burned them. But flip it around and it’s less flattering: T-Mobile’s own telemetry was attributing live traffic to a device that its own asset inventory should have shown as powered off. The gap between what the network claimed and what the hardware was actually doing is the real story here. Accurate hardware inventory and device status is unglamorous work, and it’s exactly the kind of thing that determines how long an adversary gets to live in your network.

   “Then there’s the handling of that router. Per the article, the CSO told a staffer to “rip” a device suspected of nation-state compromise out of the rack, put it in his car, and drive it hundreds of miles to headquarters. Set aside the scissors for a moment. Where’s the chain of custody? Where’s the forensic imaging before the device gets bounced down I-5 in a trunk? For an artifact that might end up mattering to a federal investigation into Salt Typhoon, that’s a detail that made me wince.

   “As for the scissors: I’ve spent time in data centers of this caliber, and scissors are not part of the standard tech loadout. Every one of those links terminates somewhere you can unplug it, shut down at a patch panel, or kill via CLI. Simon concedes as much in the article, admitting they could have turned the device off virtually. Cutting the cable accomplished nothing that unseating a connector wouldn’t, except producing a frayed trophy now framed in the lobby. I don’t doubt the cable got cut. I just notice that the version that made a better artifact is the version that happened.

   “The substantive issue is what the fast, loud response cost them. Walk the IR lifecycle: containment, absolutely, they nailed it. But by their own account, powering the device back up in an isolated environment later yielded little. The attackers were long gone, and so was the volatile evidence. Abruptly severing the link also told the adversary, unambiguously, that they’d been made. A more patient play, instrumenting the device and the interconnect while quietly constraining what the attackers could reach, likely would have produced far more intelligence about tooling, tradecraft, and other footholds. That matters a great deal when the adversary is a state actor with confirmed presence across nine other carriers. Containment without eradication just means round two happens somewhere you aren’t watching.

   “To be clear, I’m confident T-Mobile’s IR capability is far more sophisticated than this telling suggests, and some of what looks like theater may just be what survives the corporate comms filter. But that’s exactly the problem. The sanitized, cinematic version is the one the industry got, and the useful version, the one about inventory hygiene, trusted carrier interconnects as an attack surface, evidence handling under pressure, and the real tradeoff between fast containment and thorough eradication, is the one we actually needed.”

Seemant Sehgal, Founder and CEO, BreachLock:

   “Cutting a cable makes for good storytelling, but the real headline is that a disciplined security team found an adversary that had worked hard to stay hidden. The significance of the Salt Typhoon campaign is the scale and persistence of the operation, targeting telecommunications infrastructure to gain access to highly valuable data. Based on public reporting, the attackers appear to have leveraged network infrastructure and maintained covert access paths, which highlights how difficult these intrusions can be to detect once established. Many organizations in that situation would still be writing incident reports while the attacker moved laterally. T-Mobile’s team located the threat, made a call, and physically removed it from the equation. That takes clarity of judgment under pressure, and that is genuinely rare.” 

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “The dramatic part of this story is that T-Mobile physically cut a cable, but the bigger lesson is how difficult sophisticated nation-state actors can be to find and remove. Salt Typhoon demonstrates why organizations need visibility into what is actually communicating across their networks, not simply what their asset management tools say should be there. When you identify a compromised system, decisive containment matters more than elegant containment. Sometimes the right incident-response decision really is to pull the plug.”

John Strand, Owner, Black Hills Information Security:

   “There’s only one firewall in existence that is 100% effective, and this is it. Physically cutting the line.

   “I look at stories like this and think security teams need to be empowered to make that decision. For years, the idea of actually cutting network connections during an incident, potentially impacting operations, has been fraught with second-guessing. Hindsight is always 20/20, and security teams are often criticized afterward regardless of the decision they made.

   “But this needs to be normalized. With the rate of attacks we’re seeing, especially with AI dramatically increasing the speed at which attacks can unfold, security teams need to have disconnecting network connections on the table as a legitimate course of action. Organizations should establish that authority before an incident happens, and security teams shouldn’t be punished for using it when the situation calls for it.”

Hayden Covington, Associate Director of Security Operations, Black Hills Information Security:

   “What makes groups like Salt Typhoon dangerous is that they are difficult to detect; not just because they use living-off-the-land techniques, but also because they aren’t a smash and grab operation where eventually the threat actor runs ransomware and you know they’re there. Groups like this are focused on espionage, aiming for long dwell times while they quietly collect sensitive information. Catching an attacker like that often comes down to knowledge of your environment and the ability to dig into anomalies deep enough to know that something malicious is actually happening.”

I have to admit that this is crafty and full of old school thinking. But this needs to be normalized and not the exceptional because everyone everywhere needs to hunt down threat actors and kick them off of any network ASAP.

When AI agents become the attack vector 

Posted in Commentary with tags on August 21, 2026 by itnerd

An OpenClaw supply-chain attack exists in which attackers manipulated AI agents into recommending or facilitating malicious actions, including getting users to install malware. There’s Trellix research on the OpenClaw supply-chain attack along with Palo Alto Networks Unit 42 research on OpenClaw’s agent-skill supply chain that you can read at your leisure… Or maybe not so leisure given the gravity of the situation.

Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)

“AI agents are quickly becoming a new trust layer in the attack chain, and attackers know that trust is often easier to exploit than technology. When a manipulated agent recommends software, a workflow, or a next step, users can inherit the attacker’s influence without realizing it. Organizations should treat AI agents like any other high value system, with adversarial testing, strict guardrails, and continuous validation of what the agent can see, recommend, and act on.”

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“This particular story is wild because it mixes social engineering with supply chain attacks, which is fascinating in and of itself. But I think the bigger issue is the sheer number of people now using AI tools for development who have little to no background in IT, software development, or security.

“AI and open tools like OpenClaw have made it incredibly easy for people to build things quickly and get much closer to that original promise of technology doing complicated work on their behalf. On one hand, that’s fantastic. It lowers the barrier to entry and lets people create things they never could have built before.

“But there’s a security problem hiding underneath all of that. People are downloading packages, installing tools, granting permissions, and running code without necessarily understanding what those actions mean. And frankly, some of these basic security principles are being missed even by seasoned IT professionals. As AI makes development easier and more accessible, we have to make security awareness just as accessible, because the population of people building and running software has suddenly become much larger than the population we’ve traditionally thought of as developers.”

Jacob Krell, Sr. Director: Secure AI Sollutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)

“ClickFix is a social engineering technique where a webpage convinces users to copy and paste a command into their own terminal. It bypasses endpoint defenses because the operating system treats it as a legitimate action from a trusted human. ClawHavoc grafted that technique onto an AI agent, upgrading the lure from a random website to a trusted assistant. Same attack, better packaging.

“OpenClaw lets AI agents read files, run terminal commands, and install third-party skills from its ClawHub marketplace. Researchers traced 1,184 malicious packages across that marketplace, tied to just 12 author accounts. The skills told the agent that users needed to install a fake prerequisite called AuthTool before a feature would work, and the agent relayed that as a normal setup step. Users who followed along got Atomic macOS Stealer, an infostealer targeting 60+ crypto wallets, browser data, SSH keys, and .env files.

“The agent is doing exactly what it was designed to do, reading documentation and relaying instructions to the user. Nobody built a layer between “read instructions” and “present them as trusted guidance.” That gap is the vulnerability, and it’s the same supply chain trust manipulation I’ve been tracking since the npm download pumping research earlier this year. Attackers game whatever trust signal AI tools rely on, whether that’s package popularity metrics or a skill marketplace listing with a plausible name.

“Organizations deploying AI agents need to treat every installed skill as third-party code execution, with approval gates before any agent-initiated system command. Run agents on isolated hosts with scoped credentials and restricted outbound network access. Monitor for node.exe spawning PowerShell or curl. The agent can suggest an action, but the OS and identity layers need to independently prevent that suggestion from becoming unreviewed execution.”

Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)

“AI agents create a new social engineering problem because the attacker is no longer impersonating someone the victim trusts. The attacker is manipulating the system the victim already trusts.

“The strongest control is dedicated, hardware bound fingerprint authorization at the agent gateway. When an agent wants to install software, connect a new tool, access credentials, send sensitive information, transfer money, change security settings, or execute an administrative command, the gateway must require a fingerprint from an authorized person on dedicated trusted hardware.

“The fingerprint must authorize the exact action. The trusted device should display what will be executed, where it came from, what permissions it requests, and which systems or data it will affect. The hardware should then cryptographically sign that specific transaction. Any change to the command, software, destination, permissions, or scope must require a new fingerprint authorization.

“This physical requirement is essential because a digital approval can be delegated, simulated, or automated. Without hardware bound biometrics, one compromised agent could ask another agent to approve the action, creating the appearance of human oversight when no human was ever in the loop. A software confirmation button, approval message, or agent generated authorization is not proof of human presence.

“The fingerprint sensor and approval display must therefore sit outside the control of every agent. No agent should be able to generate, relay, or satisfy the approval itself. The biometric template should remain within the dedicated hardware, and the gateway should accept only a signed authorization produced after a live fingerprint match.

“This does not make a malicious recommendation safe. It establishes a hard separation between an agent’s ability to propose an action and its authority to perform one. An AI agent may recommend, but consequential authority must come from the physical presence of a verified human.”

AI agents need guard rails. If you don’t have them, you are risking getting pwned. It’s that simple.

EORN Cell Gap Project Delivered With The Help Of Rogers

Posted in Commentary with tags on August 20, 2026 by itnerd

Eastern Ontario Regional Network (EORN) and Rogers Communications today announced the successful delivery of the EORN Cell Gap Project.

5G cellular services are now available across eastern Ontario, improving services for residents, businesses, first responders, municipalities, Indigenous communities and visitors in the region.

Federal, provincial, municipal and Indigenous partners marked the successful delivery of the project at an event in Rockland, Ontario.

The EORN Cell Gap Project is a $300 million public-private partnership. The Province of Ontario and the Government of Canada each contributed $71 million and the municipal members of the Eastern Ontario Wardens’ Caucus (EOWC) and participating members of the Eastern Ontario Mayors’ Caucus (EOMC) collectively contributed $10 million. Rogers contributed the remaining investment of $150 million. The company was selected through a competitive bidding process.

Rogers built 346 new wireless sites, a combination of new tower constructions and colocations. In addition, the company upgraded 311 existing sites with state-of-the-art 5G equipment delivering essential services to municipalities, Indigenous communities and visitors across eastern Ontario.

Quick Facts

  • The Cell Gap Project targets were 99% voice call coverage, 95% standard definition coverage, and 85% high-definition coverage in the demand areas where people live, work and travel on major roadways across the municipalities of the Eastern Ontario Wardens’ Caucus (EOWC) and the participating cities and towns of the Eastern Ontario Mayors’ Caucus (EOMC).
  • Participating Eastern Ontario Wardens’ Caucus (EOWC) counties are: County of Frontenac, County of Haliburton, County of Hastings, City of Kawartha Lakes, County of Lanark, United Counties of Leeds and Grenville, County of Lennox and Addington, County of Northumberland, County of Peterborough, United Counties of Prescott and Russell, Prince Edward County, County of Renfrew and United Counties of Stormont, Dundas and Glengarry. Participating cities of the Eastern Ontario Mayors’ Caucus (EOMC) are: Belleville, Cornwall, Gananoque, Kingston, Pembroke, Peterborough, Prescott, Quinte West and Smiths Falls.