Archive for September 1, 2026

Today Starts National Insider Threat Awareness Month

Posted in Commentary on September 1, 2026 by itnerd

National Insider Threat Awareness Month (NITAM) is a critical reminder that some of the most damaging security incidents originate from within. Human error, policy bypasses, and phishing-induced lapses account for most internal breaches, often costing millions to fix.

Organizations can protect their sensitive information by strengthening internal defenses, adopting stronger controls such as multifactor authentication and authorization, and fostering a culture of vigilance.

Eric Polet, Director of U.S. Operations, Arcitecta had this to say:

“At a time when cyberattacks are more frequent and data environments are larger and more complex, safeguarding critical assets requires continuous vigilance, intelligent monitoring, and a proactive defense against internal vulnerabilities.”

Max Gannon, Cyber Intelligence Team Manager at Cofense adds this:

“Insider threats are often associated with employees who intentionally misuse their access, but that definition misses a growing part of the risk. External attackers can create many of the same problems by stealing employee credentials, hijacking sessions or manipulating users through social engineering. Once they are operating through a legitimate account, malicious activity can be much harder to distinguish from normal business behavior.

Insider risk is no longer only a question of employee intent. It also includes how trusted access can be compromised. Employees are often the first to notice when a login request, MFA prompt or message feels out of place, making human context an important signal in identifying misuse of trusted access that may otherwise appear legitimate. Insider Threat Awareness Month is an opportunity to broaden the conversation around what insider risk actually looks like today.”

Piyush Sharrma, co-founder and CEO at Tuskira says this:

“Insider risk gets much more complicated once you stop looking at permissions as a flat list.

A user may only have access to a handful of systems. One of those systems may trust another identity. That identity may connect to a cloud role. An exposed vulnerability may open the next step. What looked like fairly limited access on paper can become a path to something far more sensitive.

Security teams already have plenty of data describing vulnerabilities and identities. The harder question is how those pieces connect.

AI-assisted attack-path analysis can trace that relationship across an environment. It can identify where legitimate access intersects with exploitable weaknesses. It can also show whether existing controls break the path before critical assets become reachable.

With insider threats, the first credential doesn’t have to be stolen. Sometimes it was legitimately issued. The security problem begins with everything that credential can reach next.”

Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ adds this:

“An insider already has what an external attacker usually wants first: access.

That’s why organizations can’t judge insider readiness by whether an alert exists for suspicious downloads or abnormal logins. They need to know how much damage a trusted account could actually cause if it were abused.

Can that user reach a privileged system? Can they escalate access? Can they move laterally toward sensitive data? In many environments, the answer is yes, especially when permissions have accumulated over time or controls haven’t been tested against real attacker behavior. The more important question is whether existing defenses would detect and stop those actions before access turns into compromise.

This is where continuous exposure management becomes useful. Insider scenarios should be part of the same adversarial validation organizations use against external threats. AEV can test realistic techniques against existing defenses before a real employee, compromised account or malicious contractor tries them.

Awareness helps people recognize insider risk. Validation tells you whether the environment can withstand it.”

Ross Filipek, CISO at Corsica Technologies follows with this:

“The insider threat problem isn’t always dramatic. Sometimes nobody disables an old account. An employee moves to another department and keeps permissions they no longer need. A contractor finishes a project but still has remote access. Someone leaves the company and their SaaS accounts aren’t shut down until days later.

Those gaps can be easy to miss because access follows people across IT, HR, and management processes. Smaller organizations may not have one team watching the entire employee lifecycle. Responsibilities get split up, and access quietly accumulates.

Basic process discipline is incredibly important. Teams need to know what employees should have when they join, review access when their roles change, and remove it immediately when they leave. Periodic access reviews can catch what gets missed along the way.

Insider threat programs don’t have to start with sophisticated surveillance. For a lot of businesses, simply making sure people only retain the access they actually need could eliminate a surprising amount of risk.”

Kevin Kirkwood, CISO at Exabeam had this to say:

“We need to retire the idea that an insider is always a disgruntled employee stealing files on the way out the door.

Exabeam has already encountered a much stranger version. A foreign operative aligned with North Korean interests made it through the hiring process and entered the organization as a seemingly legitimate employee. The access looked legitimate too. Small behavioral anomalies eventually told a different story. Those weak signals became meaningful once they were viewed together.

Now organizations have another insider entering the workforce: AI agents.

Agents can hold credentials. They can interact with internal systems. They can take actions without someone approving every step. None of that makes an AI agent malicious. It does make blind trust dangerous.

Insider Threat Awareness Month should push security teams beyond asking whether an identity successfully authenticated. They need to understand whether its behavior still makes sense. That applies to employees. It applies to contractors. Increasingly, it applies to machines acting with employee-like authority.

The next generation of insider defense will depend on understanding normal behavior well enough to notice when trusted identities stop acting normally.”

Kevin Mata, Director of Cloud Operations and Automation at Swimlane says this:

“One strange login probably isn’t enough to call something an insider threat. Neither is a large download or an unexpected privilege change. The challenge starts when several of those signals appear around the same person and nobody has the full picture.

That’s a very real problem for security operations. Identity data may sit in one system. Endpoint activity lives somewhere else. Cloud access adds another layer. Analysts can spend more time assembling the story than deciding what to do about it.

AI can help connect those signals while the investigation is still developing. Automation can enrich the activity and pull in additional context. It can also route higher-risk cases to the people who need to see them.

That last part matters with insider risk. Security isn’t always the only team involved. HR or legal may need to participate. The best response isn’t necessarily the fastest one. It’s the one where everyone is working from the same evidence before a judgment is made.”

Michael Centrella, Head of Public Policy at SecurityScorecard:

“National Insider Threat Awareness Month often brings to mind the traditional image of a malicious employee walking out with sensitive information. Today’s threats show that this is only one part of a much larger issue. Organizations also have to contend with outsiders who obtain legitimate access, contractors who can be recruited or compromised, stolen identities, and employees who intentionally or unintentionally put sensitive information at risk.

Recent incidents show both sides of that equation. A North Korean IT worker was hired by a U.S. government agency, giving a suspected foreign actor legitimate access through the front door rather than forcing them to break through the perimeter. In another case, a former TD Bank employee pleaded guilty after accepting bribes and using his legitimate access to obtain confidential customer information that was passed to outside co-conspirators. In one case, an outsider became a trusted insider. In the other, a trusted insider became an avenue for outside criminals.

Insider threat programs cannot rely only on pre-employment screening or assume that a valid account equals a trusted user. Security teams need to understand what access people and third parties actually require, limit privileges accordingly, and identify when behavior begins to deviate from the role behind the credentials. Trust cannot be treated as permanent. In a workforce increasingly made up of employees, contractors, remote workers, and external partners, authorized access needs the same ongoing scrutiny as any other part of the attack surface.”

John Bruggeman, vCISO at CBTS adds this:

“National Insider Threat Awareness Month is a reminder that insider risk extends well beyond the traditional image of a disgruntled employee. A legitimate account can create serious exposure when it is compromised, misused, or retains access that no longer reflects the user’s responsibilities. Most of the time I see organizations have good on-boarding processes but weak off-boarding processes.

With Agentic AI, AI is now an insider threat, AI could now be your weakest link. You need to make sure your AI agents can be trusted, just like your employees. What you want to consider is whether you can recognize when trusted access begins to deviate from its intended purpose. Ask yourself, can you recognize when trusted access, human or AI, starts to drift from its intended purpose?

Answering that question requires disciplined identity governance and consistent oversight. Access should be reviewed as roles change, employment ends, or business needs evolve. Security teams also need enough visibility to recognize meaningful changes in how an account is being used without relying on a single signal. A login from an unexpected location or access to information outside a normal work pattern may warrant scrutiny, particularly when it involves sensitive systems.

Organizations should always know who can reach critical data and why that access is still necessary. Align identity controls with monitoring, and misuse gets caught earlier, before it has room to spread.”

You can read more about this here: https://securityawareness.dcsa.mil/cdse/nitam/index.html

Introducing OWASP OASIS

Posted in Commentary with tags on September 1, 2026 by itnerd

Today, a community of application security professionals launched OWASP Open Automated Security Initiative for Software (OASIS). This global initiative marshals human expertise to deliver crowd-validated vulnerability fixes for the open source software that underlies 98% of commercial codebases, including critical infrastructure and commercial software. OWASP OASIS combines donated AI-powered fix automation and validation tooling with human expertise to move open source security from discovery to immediate remediation at scale.

OASIS has attracted hundreds of AppSec professionals from a variety of industries, alongside founding industry members AppSecAI, Intigriti, and DryRun Security.

What OWASP OASIS Is

For decades, the security industry has focused on finding vulnerabilities. The bottleneck has always been remediation: the cost, process complexity, and specialized expertise required to deliver credible security fixes for vulnerabilities.

OASIS changes that by leveraging Fix Automation and Validation, an emerging category of AI tools that generate and validate candidate fixes as vulnerabilities are found. OASIS’s community-driven validation layer makes those fixes trustworthy for upstream developer validation and contribution.

The three-part process:

  1. AI Pipeline: Automated tools scan open source repositories and generate candidate security fixes at scale. Found vulnerabilities always come with a candidate fix
  1. Expert Community Validation: The community reviews fixes, assesses correctness and safety, and determines which ones are credible, reducing validation time to minutes
  1. Upstream Contribution: Validated fixes are provided to open source teams as credible, community-validated security patches for consideration, allowing maintainers to quickly validate them for functionality and performance and integrate them at their discretion

By generating code fixes while contributing to the open source ecosystem, OASIS democratizes the vulnerability remediation process with a collaborative platform to augment human capabilities and improve security fixes at scale.

Why Now?

The launch of OASIS comes at a defining moment. “Vibe hacking,” the AI-assisted discovery and exploitation of vulnerabilities, enables attackers to move faster than security teams can respond. However, the same generative AI powering attacks offers a defense: the AppSec community now has the power to find and generate validated fixes at comparable speed.

This reality has catalyzed complementary initiatives across the industry. Frontier AI developments like Anthropic’s Project Glasswing introduced highly advanced models like Claude Mythos to defenders, while OpenAI’s Patch the Planet and the Linux Foundation’s Akrites have mobilized elite research teams and tech coalitions to protect core software infrastructure.

While these programs focus on researcher-led intervention for select high-priority infrastructure, OASIS is open, democratic, and vendor-agnostic. It leverages volunteers from the AppSec community to scale broadly across the open source landscape and address the long tail of software libraries and applications used by enterprises.

Why Open Source Needs OWASP OASIS

Open source maintainers face an onslaught of low-fidelity information.

OASIS acts as a community quality filter. AppSec experts assess whether a candidate fix is accurate and safe. Human validation converts rapid AI output into a patch a maintainer can trust. It provides a straightforward, vendor-neutral way for AppSec professionals to give back to the open source community.

Why Enterprise Users need OWASP OASIS

Open source code underlies countless custom enterprise applications.  When that code is vulnerable, they are exposed, dependent on maintainers to keep organizations running. 

How to Get Involved

Join the initiative at owasp-oasis.org

Instarc Secures €1.25 Million Strategic Investment to Expand Cloud-Native Regulatory Compliance Platform

Posted in Commentary with tags on September 1, 2026 by itnerd

Instarc, a regulatory technology firm based in Tallinn, has secured a €1.25 million strategic investment to accelerate the commercial rollout of its cloud-native compliance platform for financial and accountable institutions in South Africa. The system is designed to be fully scalable and adaptable so it can work with compliance regimes around the world.

HFO Investments, advised by Athena Capital and Option 3 Capital, has joined Instarc as a strategic investor through the transaction. As South Africa strengthens KYC/CDD requirements under the Financial Intelligence Centre Act (FICA), the Instarc platform helps accountable institutions address evolving compliance obligations.

It delivers a structured and modular digital operating framework with client onboarding, identity and ownership verification, configurable workflows, document management, retrievable audit records, and APIs that connect seamlessly with institutions’ existing systems.

Instarc addresses a critical need for businesses in South Africa where compliance obligations are among the most rigorous in Africa. Instarc platform allow clients to keep up to date with the rapidly evolving and strengthening KYC/CDD requirements of the Financial Intelligence Centre Act (FICA).

Instarc’s cloud-native technology was designed to integrate compliance into an institution’s operating model rather than to function as a standalone platform. Client journeys can be configured according to product, risk appetite and institutional controls, allowing organisations to adapt processes as regulatory requirements change without rebuilding the underlying technology.

For more information, visit instarc.com.

Half of the top mobile apps silently collect browsing history

Posted in Commentary with tags on September 1, 2026 by itnerd

recent Surfshark analysis shows that 45% of top mobile apps collect information about the websites their users visit. Of the 40 leading Android and iOS apps analyzed across gen AI, social media, e-commerce, and messaging, 18 report collecting browsing history in their app store privacy labels.

Social media collects the most, followed by e-commerce

Nine out of 10 social media apps collect browsing history on at least one platform. Facebook, Instagram, TikTok, X, YouTube, and Pinterest collect it on both Android and iOS. Reddit, LinkedIn, and Snapchat collect it on Android only. Discord was the only social media app that collects it on neither platform.

This data helps platforms build a clearer picture of user interests, target advertising more specifically, and shape in-app feeds based on websites visited outside the app.

Half of the e-commerce apps analyzed collect browsing history on at least one platform. eBay, Shopee, and Shopify collect it on both Android and iOS, while Taobao collects it on iOS only and AliExpress on Android only. The commercial value is direct: the more these apps know about a user’s online interests, the more effectively they can recommend and advertise products. The cost is that browsing habits become increasingly difficult to keep private.

Messaging and generative AI apps also track websites visited

Three messaging apps collect browsing history: Rakuten Viber, Messenger, and LINE. Their parent companies can use this data to build more detailed profiles of users and their interests.

Collection was the least common in the generative AI category. Google Gemini was the only app of the 10 analyzed to report collecting browsing history.

METHODOLOGY

Surfshark analyzed 40 of the most popular mobile apps, 10 each in generative AI, social media, e-commerce, and messaging, selected mainly from Cloudflare’s ranking of the most popular internet services worldwide. For each app, it was recorded whether its Apple App Store privacy label reported collecting “Browsing History” and whether its Google Play Store label reported “Web Browsing History,” then compared results by platform and category. A separate set of browsers was analyzed outside the 40-app sample. For the complete research material behind this study, visit here.