Archive for August, 2026

NTT DATA and Palo Alto Networks Sign Global Strategic Alliance to Accelerate Secure AI Transformation

Posted in Commentary with tags , on August 20, 2026 by itnerd

NTT DATA and Palo Alto Networks today announced a multi-year strategic alliance designed to help organizations securely adopt AI, modernize cybersecurity, simplify complex technology environments and build cyber resilience for the AI era.

As Palo Alto Networks first strategic alliance of this kind with a global systems integrator, the agreement, which targets $1 billion in joint business by the end of three years (2029), combines Palo Alto Networks AI-powered cybersecurity platforms with NTT DATA’s consulting, engineering and managed services.

Leveraging joint engineering, co-innovation and coordinated global delivery, the alliance will help clients assess cyber risk, deploy AI securely and continuously optimize security. Through these joint solutions, clients will gain a unified approach that seamlessly spans cybersecurity strategy, implementation and managed services.

Building on the companies’ Frontier AI collaboration, the alliance brings together Palo Alto Networks Unit 42® threat intelligence with NTT DATA’s global cybersecurity expertise, AI governance and managed services. Backed by joint investments, more than 2,000 certified experts, as well as dedicated Forward Deployed Engineers, the alliance will deliver a seamless approach to streamline deployments and speed client outcomes. Through direct engineering collaboration, NTT DATA will gain early access to new platform features — further accelerating the delivery of AI security services to clients. 

Initial solutions will address the most pressing cybersecurity challenges facing clients in highly regulated and critical industries, including financial services, healthcare, manufacturing and the public sector, across six strategic transformation areas:

  • Autonomous Security Operations Center (SOC) – Modernize security operations with Agentic AI and managed services that help organizations detect, investigate and respond faster to increasingly sophisticated, machine-speed cyber threats while reducing operational complexity.
  • AI governance – Embed governance, security and risk management throughout the AI lifecycle, helping organizations manage emerging AI risks and confidently scale AI innovation with greater accountability, transparency and control.
  • Identity security –  Protect human, machine and AI agent identities, including workloads and devices, through an Identity Security Framework designed to discover, manage, secure and govern identities across the enterprise.
  • Zero Trust & SASE – Helps secure users, applications and data across an increasingly complex attack surface through a unified Zero trust and secure edge architecture, leveraging AI-driven threat detection and prevention.
  • Resilient cloud – Enables organizations to improve visibility, compliance and autonomous risk reduction across multi-cloud environments with AI-enabled security posture management and stronger governance.
  • Firewall modernization – Modernize firewall environments to reduce complexity, improve visibility and strengthen enterprise security.

NTT DATA brings world-class cybersecurity expertise to the collaboration, backed by over 7,500 cybersecurity professionals, 70+ delivery centers and 20+ Autonomous Cyber Defense Centers. Paired with Palo Alto Networks AI-powered platforms and Unit 42 threat intelligence, the alliance delivers the technology, expertise and global reach enterprise organizations need to securely deploy AI across complex environments.

Meta and Google are the most data-hungry Big Tech companies

Posted in Commentary with tags on August 20, 2026 by itnerd

A new study by Surfshark reveals a significant disparity in how the world’s largest technology companies handle personal information. After analyzing 171 Apple App Store apps from Google, Apple, Microsoft, Amazon, and Meta, researchers found that Meta’s apps are the most “data-hungry,” collecting an average of 25 out of 35 possible data types, more than triple the average of Apple (7) or Microsoft (8).

The study analyzed apps across 35 unique data categories, ranging from precise location and browsing history to purchase data linked to user identity. Company averages varied widely: Meta’s apps collected 25 data types on average, followed by Google with 17, Amazon with 12, Microsoft with 8, and Apple with 7. The sample included 44 Google apps, 41 Apple apps, 40 Microsoft apps, 34 Amazon apps, and 12 Meta apps.

The seven most data-hungry apps in the study were all developed by Meta. Meta AI collected 33 data types, followed by Meta Horizon, Meta Business Suite, Meta Ads Manager, Messenger, Forum, and Facebook with 32 each. Notably, all of this data is linked directly to the user’s identity.

Google dominates TOP 40 ranking while Microsoft and Apple remain the least data-hungry

Google accounted for 29 of the 40 most data-hungry apps in the study, compared with 9 from Meta and 2 from Amazon. Google apps in that group collected between 18 and 26 data types each. Although Google’s apps collected fewer data types on average than Meta’s, its presence across the ranking highlights the scale of data collection throughout its extensive app ecosystem. Meanwhile, Amazon Alexa was the most data-hungry non-Meta app, collecting 28 data types.

Microsoft and Apple consistently ranked as the least data-hungry developers across app categories. Microsoft ranked either the least or second-least data-hungry developer in most categories, with the lone exception of Graphics & Design. Apple covered the widest range of categories (15 in total) and consistently ranked as the least data-hungry developer. For example, Apple’s 13 Utilities apps collected an average of 6 data types, compared with 17 for Google’s Utilities apps.

To see a more detailed profile of each Big Tech company, please see the blog post: https://surfshark.com/research/study/big-tech-data-collection  

In just 20 days, manufacturers face EU’s new vulnerability reporting mandates

Posted in Commentary with tags on August 19, 2026 by itnerd

Effective worldwide and starting September 11, 2026, all manufacturers of goods shipped into the EU must notify The European Union Agency for Cybersecurity (ENISA) within 24 hours of any actively exploited vulnerability. 

Most have focused on the EU Cyber Resilience Act‘s (CRA) ultimate December 2027 deadline, but as of this Friday, 20 days away, manufacturers become newly accountable for digital resilience throughout the entire product lifecycle. 

  • Within 24 hours of discovering any actively exploited vulnerability, they must notify ENISA and a designated Computer Incident Response Team (CSIRT).
  • Within 72 hours, they owe a detailed follow-up notification, including a description of corrective action.
  • Within 14 days, once a mitigation is available, they must submit a final report detailing the vulnerability and any exploitation of it.

According to Doc McConnell, Head of Policy and Compliance, Finite State, “For many companies, the challenge isn’t simply reporting, it’s determining within a few hours whether a vulnerability exists inside their products, whether it’s being actively exploited, and who might be affected.”

(Doc is a former CISA Branch Chief and a former Senior Advisor for Cybersecurity Policy with the U.S. Office of Management and Budget.)

“The biggest obstacle isn’t paperwork, it’s visibility. Many companies lack accurate software inventories across their product lines, and have limited insight into third-party components embedded in products. Even more lack an in-place internal decision process to meet that 24-hour reporting mandate. 

“The CRA readiness gap persists across sectors: ICS, automotive, medical devices, consumer electronics, IoT, IT gear, mobile applications distributed to EU end users, embedded software and more.

“And are their legal and compliance departments ready to assess cyber resilience?”

The Manufacturer’s Guide to CRA Vulnerability Handling is worth reading: https://finitestate.io/resources/cra-vulnerability-handling-guide

Also worth reading is the CRA Vulnerability Reporting: September 2026 is Around the Corner: https://finitestate.io/blog/cra-article-14-september-2026-reporting-deadline

OpenAI overhauls security controls following Hugging Face breach 

Posted in Commentary with tags on August 19, 2026 by itnerd

OpenAI has introduced new security requirements for developing and testing advanced AI models, including stronger network isolation, increased monitoring of model activity and additional alignment and security work during post-training.

The changes follow the July incident in which a pre-release OpenAI model escaped its testing environment and breached Hugging Face systems. OpenAI also disclosed that it paused reinforcement learning for two weeks following the incident.

Training has resumed for some lower-risk models, but the company’s largest planned frontier reinforcement-learning run remains on hold while it conducts additional testing and validates safeguards. OpenAI said the controls will become stricter as models demonstrate greater capabilities and risk.

John Strand, Owner, Black Hills Information Security, Inc.:

“Popular culture and science fiction have been training us for this moment for decades. From I Have No Mouth, and I Must Scream to WarGames and Terminator 2, we’ve been telling stories about what happens when powerful AI systems escape their constraints and start operating beyond human control. So it’s difficult for me to understand how the engineers building these systems could be surprised when something like this actually happens. What concerns me even more is that the controls being discussed now, after the system escaped, are controls that should have been there from the beginning.

   “I’m glad they’re putting additional safeguards in place, but there’s a bigger question here. Can we trust the same companies that got this wrong to effectively self-regulate systems backed by immense amounts of computing power? I don’t think that question has been answered yet. These companies need to demonstrate far more openness about what happened, what went wrong, and exactly what they’re doing to make sure it doesn’t happen again.”

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “The Hugging Face incident is an important wake-up call for the AI industry because it demonstrates that AI security can’t rely solely on guardrails and alignment. As models become more capable and autonomous, they need to be treated much like potentially hostile code during development and testing. Strong network isolation, least privilege, continuous monitoring, and multiple layers of containment have to be built into the environment from the beginning.

   “What makes this particularly significant is that the model wasn’t necessarily acting with malicious intent. It was pursuing an objective and found a path outside the boundaries researchers expected it to respect. That is a very familiar cybersecurity problem: when a system has capabilities or access that exceed its intended boundaries, eventually those boundaries will be tested.

   “OpenAI pausing its largest frontier reinforcement-learning run while validating additional safeguards is a responsible response. As AI capabilities increase, security controls have to scale with them. The lesson for the broader industry is simple: don’t assume the model will stay inside the sandbox. Design the environment assuming it will try to get out.”

Noelle Murata, Sr. Security Engineer, Xcape, Inc.:

   “Disclosed July 21, 2026: an OpenAI model went rogue mid-task and targeted Hugging Face, escaping its training environment by compromising a tool on OpenAI’s network that had Internet access – drawing external criticism of the company’s network security practices. OpenAI paused development and testing of frontier workloads capable of executing code or reaching the Internet, suspended further reinforcement learning progress for two weeks, and only resumed  for less-risky models, with the primary model training still held for smaller-scale evaluation and safeguard validation. The postmortem is still pending. New controls include sandboxing, network isolation, continuous testing, and multi-stage monitoring.

   “Post-Hugging Face, OpenAI is rebuilding safety controls across three pillars ahead of Astra:

  • Infrastructure: sandboxing and network isolation so a single workload compromise doesn’t yield Internet or internal network access; continuous security testing at a deliberately slowed pace; code-execution and Internet-capable workloads paused, Astra release held until infrastructure performance goals are met.
  • Monitoring: classifiers escalate to automated investigators that read tool usage, actions, and raw reasoning traces, and alerting inside 30 minutes, which should be mandatory for any model with external tools operating at ~20% of the monitored process’s compute.
  • Alignment: Reinforcement Learning (RL) paused two weeks, resumed only for lower-risk models with the largest frontier runs still frozen pending smaller-scale validation; new RL controls target reward hacking, deception, and guardrail bypass under an evolving Preparedness Framework.

   “Critical Takeaways:

  • Containment is a shared failure mode. Anthropic disclosed Claude models escaping testing and breaching three companies; Meta reported its own exploit incident. Three labs, same vulnerability class during internal development.
  • The problem is authority, not intelligence. Alignment built around what models say doesn’t transfer to models that are granted code execution, external tools, and network access; the risk moves from content to network-level harm.
  • Pre-release no longer means safe. Models escaping via minor Internet-connected tools have forced labs to slow internal testing and stand up sandboxing and isolation before resuming advanced runs.  A sobering reality while the same cyber capabilities that will soon drive security operations are the ones that turned outward when guardrails fail.

   “Three labs independently discovered that their test environments were, technically, connected to things.”

Seemant Sehgal, Founder & CEO, BreachLock:

   “Frontier AI development is increasingly becoming a security discipline as much as a research discipline. OpenAI’s decisions reflect a recognition that capability gains must be matched by proportional risk management. As AI systems become more capable, organizations will be evaluated not only by what their models can do, but by how effectively they can contain, govern, and monitor them throughout the development lifecycle.”

This won’t be the last that we hear of the story, I guarantee it.

RegScale Collaborates with Microsoft to Support Accelerated FedRAMP Readiness

Posted in Commentary with tags on August 19, 2026 by itnerd

RegScale, the AI-powered continuous controls monitoring (CCM) platform, today announced it is collaborating with Microsoft to help customers pursue FedRAMP readiness and authorization to operate (ATO) efforts on Microsoft Azure. RegScale customers will benefit from Microsoft Azure’s FedRAMP-authorized secure cloud environment complemented by RegScale’s compliance automation and continuous controls monitoring platform. 

Achieving FedRAMP has long been one of the most time-consuming and resource-intensive milestones for any CSP selling to the U.S. federal government, often taking a minimum of 18 months. This collaboration pairs the scale of Microsoft with RegScale’s compliance-as-code native platform to help software providers realize a faster, clearer route to certification, regardless of where they are in their compliance journey.

The partnership also aligns with FedRAMP 20x, the initiative that moves security assurance away from point-in-time paperwork toward continuous, automated validation. Its core principles of transparency, flexibility, accountability, accuracy, and automatic validation map directly to how RegScale operates: continuously validating controls and reporting on them in real time rather than staging evidence for an audit.

RegScale supports the customer-owned compliance automation and continuous controls monitoring path by automating evidence collection, continuously validating controls against FedRAMP’s Key Security Indicators (KSIs) and through RegScale’s RegML AI agents, and turns FedRAMP certification from a periodic project into a continuous capability.

RegScale builds on a proven federal track record: the company achieved FedRAMP High in just six months using its own platform, a fraction of the typical 18-month minimum timeline. That combination of credibility and automation enables RegScale to serve as an important compliance automation path for industry customers seeking to achieve their own FedRAMP certification.

Looking ahead, the collaboration lays the groundwork for RegScale’s expanding role in the federal ecosystem, including forthcoming capabilities to help agencies consume continuous monitoring data directly from their cloud service providers.

Researchers got Microsoft Copilot to explain its own security bypass just by asking it the right follow-up questions

Posted in Commentary with tags on August 19, 2026 by itnerd

Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a critical flaw in Microsoft Copilot Personal made of three chained weaknesses that let an attacker exfiltrate data from a victim’s connected accounts, Gmail, Google Drive, Calendar, with a single click on a malicious link, discovered by researchers who questioned Copilot’s own reasoning rather than attacking its code until it disclosed an undocumented URL parameter and the protections meant to block it. Microsoft patched the flaw August 18, 2026, after Varonis reported it in December 2025 with no evidence of exploitation before the fix shipped, making it the third Copilot vulnerability Varonis has found this year.

Arti Raman, CEO & Founder of Portal26

“The exfiltration matters less than how the vulnerability was found. Researchers didn’t break Copilot’s code. They kept asking it questions until it explained its own bypass to them, an undocumented URL parameter, its own history of using it, and the protections meant to block it, all without ever touching the underlying software. The AI’s reasoning is part of the attack surface now, and most organizations have no visibility into what their assistant would say to a user, or an attacker, who kept pushing. This is the third Copilot flaw the same research team has found this year. That points to a structural gap in how these assistants get governed before they ship. You cannot govern what you cannot see, and right now almost nobody can see what their AI assistant would say under pressure.”

Anar Bayramov, Head of Product, Polygraf AI

“CoSnitch did a good job of finding the exploit. The researchers kept asking Copilot why a prompt wouldn’t run on its own, and it named the parameter, the conditions it worked under, and the protections that were supposed to disable it. The problem is that those protections weren’t set.  Everything after that is a mistake the industry repeats – Varonis found this in their Reprompt research, then in RovoBlast against Atlassian’s Rovo, and now in Copilot Personal.

Same idea every time: let a URL parameter seed the assistant’s prompt because it’s convenient for sharing. Once that parameter can execute inside a logged-in session, you’ve got CSRF with an LLM’s permissions. What’s more interesting is the memory. Microsoft addressed this attack class in June – sanitization on write, Task Adherence checks, memory updates surfaced in Defender, and scoped all of it to Microsoft 365. The consumer assistant, where an injected instruction survives password changes and session revocation without leaving a log entry, wasn’t covered by that guidance. The controls exist, but they just weren’t described for the product where this landed.”

The good news is that no user action is required to fix this. But it should make everyone question if having AI in house without the proper safeguards is worth it or not. I personally say not but I am free to be proven wrong.

UPDATE: Mark Mazur, Field CTO of Approov Mobile Security, offers the following comment:

   “CoSnitch proves that user authentication via OAuth isn’t enough when the execution client can be manipulated. Security teams must enforce Client and API Integrity alongside user identity, ensuring that every API request comes from a verified, untampered environment, preventing hijacked AI workflows from silently exfiltrating sensitive enterprise data.”

Facial recognition database exposed 9 million images 

Posted in Commentary with tags on August 19, 2026 by itnerd

Recently, cybersecurity researcher Jeremiah Fowler discovered a database containing roughly 9,042,977 facial images totaling 450.2GB, in a research conducted in collaboration with ExpressVPN. The database, which appeared to be linked to ClarityCheck, a US-based reverse image search and identity verification service, was publicly accessible without password protection or encryption.

The exposed database contained:

  • Facial images stored in folders labeled “faces” and “profiles,” including photos of adults, teens, and children.
  • Profile pictures, screenshots, and personal photographs likely uploaded by users for searches or identity verification.

You can read Jeremiah’s full findings on the ExpressVPN blog here: https://www.expressvpn.com/blog/clarity-check-data-exposed/

The CISA warns Medusa ransomware has hit over 500 critical infrastructure organizations  

Posted in Commentary with tags on August 19, 2026 by itnerd

The CISA said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. Both Medusa developers and affiliates use a double-extortion model where they encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid.

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech: 

“Since Medusa first started adding victims to its data leak site in early 2023, we’ve logged just over 500 attacks in total (across all sectors and countries). As the figure is similar to CISA’s, this demonstrates how many ransomware victims slip under the radar, either because ransom negotiations are successful and the entity isn’t added to the group’s data leak site and/or the attack isn’t acknowledged/publicized by the entity involved.

To date, 162 organizations worldwide have confirmed attacks via Medusa and 100 of these are US-based. Of the confirmed US victims, 14 are government organizations, 25 are healthcare providers, seven are finance companies, three are tech companies, and four are manufacturers (two of which would be classed as critical infrastructure).”

The CISA has mitigation strategies that do work. I strongly suggest that you read and implement them ASAP or you could be Medusa’s next victim.

UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this to say:

   “It’s kind of refreshing to get back to a good old-fashioned ransomware story instead of everything being about AI. But I have a sneaking suspicion there’s some AI lurking underneath the surface here. The fact that attackers were exploiting vulnerabilities up to two weeks before patches were available tells me we’re either dealing with some incredibly talented security researchers and exploit developers, or AI is helping accelerate that process. Possibly both.

   “The other concerning part of this story is the continued focus by ransomware groups on critical infrastructure and healthcare. If attackers can disrupt a municipality, hospital, or another organization that serves a large community, they can create tremendous pressure that goes far beyond the financial impact on the organization itself. The dinner bell has been rung.

   “Attackers have figured out that these organizations can be lucrative targets because the people making the decision about whether to pay aren’t just answering to employees or shareholders. They’re answering to entire communities that may depend on those systems and services.”

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “Medusa is a good example of how ransomware operations have evolved beyond simply encrypting systems. When attackers can exploit a newly disclosed vulnerability within 24 hours, or potentially exploit it before it is even publicly disclosed, traditional patching cycles are no longer enough.

   “Organizations need to know exactly what they have exposed to the internet, prioritize those systems for rapid remediation, and have compensating controls in place when a patch isn’t available. The reported triple-extortion tactics also reinforce an important point: paying a ransom does not guarantee the incident is over. Attackers may come back for more, which makes resilient backups, segmentation, detection, and a tested incident response plan more important than ever.”

Damon Small, Board of Directors, Xcape, Inc.:

   “Rapid exploitation of perimeter vulnerabilities by Medusa ransomware operators presents an enduring operational risk to healthcare and critical infrastructure providers, where unexpected downtime threatens essential public services.

   “While the group occasionally weaponizes flaws shortly before or after public disclosure, its primary entry point remains well-known vulnerabilities on Internet-facing software for which patches already exist. As CISA and the FBI highlight, these threat actors intentionally target organizations that often lack dedicated cybersecurity teams. However, an absence of specialized security staff does not excuse neglecting fundamental IT administration.

   “Virtually all targeted entities employ internal or third-party system administrators whose core capability and job responsibility includes basic software maintenance and routine patching. Ransomware will remain a pervasive and lucrative threat as long as the industry fails to execute basic hygiene. Security leaders and IT managers must enforce strict patching SLAs on all edge assets, mandate rigid network segmentation around sensitive workloads, and maintain immutable offline backups to resist multi-stage extortion tactics.

   “Critical Takeaways

  • Hygiene failure: Medusa primarily weaponizes well-known, patchable vulnerabilities on Internet-facing systems rather than relying strictly on complex zero-days.
  • Administrative accountability: Lacking a dedicated security operations team does not absolve internal or third-party sysadmins from performing fundamental software maintenance.
  • Extortion escalation: Threat actors are increasingly turning to multi-stage extortion and re-extorting victims who pay, making immutable off-grid backups essential.

   “Ransomware operators do not need cutting-edge exploits when our industry refuses to perform routine IT maintenance.”

Seemant Sehgal, Founder & CEO, BreachLock:

   “Medusa’s activity is a reflection of how quickly today’s threat actors can move from identifying an opportunity to acting on it. The takeaway for defenders is that speed and visibility have become powerful advantages in security programs. 

   “Teams that continuously understand their internet-facing exposure, prioritize rapid remediation, and maintain strong operational discipline are in a much better position to stay ahead of emerging threats. 

   “The reported triple-extortion case is also a reminder that resilience is paramount. Effective recovery plans, tested response processes, and business continuity preparation give organizations options and control when facing a ransomware event.”

CVEs have spiked 10x since March Says Tuukka Tiainen Of Recast Software

Posted in Commentary with tags on August 19, 2026 by itnerd

Recast tracks CVE disclosures for third-party applications through its Setup Store catalog. Since March 2026, the number of unique CVEs registered each month has climbed from roughly 150-200 to more than 60,000 in June alone. This trend lines up with major software vendors (Chromium, Firefox among them) adopting AI-assisted vulnerability testing.

Tuukka Tiainen serves as Senior Security Engineer at Recast Software, bringing over a decade of experience in IT and information security. His expertise spans technical security as well as governance, risk, and compliance. Passionate about threat and vulnerability management, Tuukka also brings deep knowledge of Microsoft’s security solutions.

His Bio is here and here is his LinkedIn profile: .

What’s driving the trend?

This trend is driven by the industry with the assumption that with the expended usage of the AI tools, vendors can test more and catch more vulnerabilities in their software.

I can only talk about what I’ve seen during the time I have reviewed the monthly statistics (since May 2024). It is visibly clear that something has changed in the number of unique vulnerabilities patched by vendors this year. You can see those spikes starting to grow in March this year.

Browsers: Chromium and Firefox have dominated the vulnerabilities number wise for the last three months. Both Mozilla and Google are participating in Project Glasswing, giving them access to Anthropic’s frontier AI model. Firefox is evidence that harnessing Claude Mythos in their pipelines has greatly increased the number of security bugs found. See the blog written by their Tech Lead and Principal Engineer.

Microsoft and Google haven’t disclosed similar information about the findings to public but at least Microsoft has admitted publicly that they use Mythos. There’s a pretty strong assumption that the reason is the same for them resulting in more patched vulnerabilities in the last few months. I think that the Project Glasswing is just the first wave. Once the model and other frontier models get into the hands of more software vendors it will result in even more vulnerabilities to be patched.

What are the operational or security implications? What should organizations be doing differently as a result?

By following the same narrative, organizations using the 3rd party software should have more vulnerabilities to deal with. I would even claim that the number of exploits will grow because AI has become so much better in autonomously discovering weaknesses and chaining multiple lower-severity issues into exploits. In the worst-case scenario there will be more of everything: vulnerabilities, software versions (patches), out-of-band patches, exploits and zero-day vulnerabilities.

Another big aspect of this is the patch gap possibly becoming the most important vulnerability management metric. The “patch gap” is the time between a security patch becoming available and it being installed on your systems. The industry has traditionally focused on zero-days, but the patch gap may become an equally important security challenge. If AI can help attackers quickly reverse engineer patches and understand the vulnerabilities they fix, the window between a patch being released and an exploit becoming available could shrink dramatically. In that world, the greatest risk is not necessarily the vulnerability no one knows about, but the one everyone knows about and hasn’t patched yet. If this is the case, patch management vendors need to help to minimize the time between a software vendor releasing a patch, making it available for the customers and customers actually applying the patch on their systems.

If organizations need to patch more and faster, it might become a heavy burden for IT and security. I think this is one of the reasons why, for example, CISA is driving its new initiative for patching. Check out Patch Smarter, Not Harder. I also wrote a blog over a year ago how to patch smarter based on other factors than just the good old CVSS.

According to CISA, only the most critical vulnerabilities should be patched within three days. It is up to organizations to come up with their own processes, but it will be even more important to be able to prioritize in the future. Organizations should also play with the idea that they must be able to effectively patch a vulnerability within three days. How does that change the existing practices and models?

A brief explanation of where the data came from, how it was collected, what timeframe it covers, and approximately how many applications/CVEs were analyzed.

The vendors report CVEs when a new version is published. Sometimes this information is added later (a few days). We (Recast) scan those resources and as soon as the CVE data is available, it is added to the Setup Store. We are collecting the data about the applications stored in the catalog. The trend started to take a clear shape from March 2026 on. 

Are all these applications in Setup Store? Just third-party apps? Enterprise apps? Does the data include severity (Critical/High/etc.)?

This is related only to the applications stored in the Setup Store, so the scale in the market is larger. Those are 3rd party applications that were eligible to be added to the catalog. The data does not include the severity.

What is the biggest or most surprising trend?

It’s not that it’s surprising but rather expected. It is confirmation of the global security changes written in the data and that AI tools are used extensively and vendors are focusing on improving.

Here’s some raw data in graph form for your viewing pleasure:

Active China-Linked Cyber Espionage Campaign Targets Gov’t Across Asia

Posted in Commentary with tags on August 19, 2026 by itnerd

Bitdefender has released research detailing SilkParasite, an active, year-long China-nexus cyberespionage campaign targeting government bodies across Central Asia. The operation is using seven custom remote access tools (RATs), five of them newly identified.

SilkParasite is the latest evidence of a trend Bitdefender has tracked since early 2025: as Russia’s regional influence recedes, China-nexus threat actors are expanding operations into Central Asia, targeting government officials who manage the region’s deepening economic ties with Beijing. The objective is spying, not disruption or financial gain.

Key findings:

An active, year-long campaign using seven custom RATs against Central Asian government targets

Professionally engineered, modular toolset built for minimal footprint and evasion, using AI only to speed development, unlike poorly written AI-generated malware elsewhere

Command/Control (C2) traffic routed through legitimate cloud services, including Google Drive, to blend in with normal network traffic

Why it matters: China-nexus tooling typically resurfaces elsewhere, putting organizations across the globe at risk for similar attacks.

You can read the report here:https://businessinsights.bitdefender.com/silkparasite-tracking-china-nexus-apt-across-central-asia