Archive for September 25, 2026

Edinburgh Napier and Approov team up on smartphone security innovation

Posted in Commentary with tags on September 25, 2026 by itnerd

A new partnership between Edinburgh Napier University and mobile cybersecurity firm Approov Limited will aim to improve smartphone security.

The Edinburgh-based company has agreed a Knowledge Transfer Partnership (KTP) with ENU, which will include the recruitment of two cyber security researchers, co-funded by Innovate UK.

Over the course of 30 months, Approov and Edinburgh Napier will work together to create innovative defence mechanisms and an offensive test bed – known in cyber security as ‘blue team’ and ‘red team’. 

The project, which received the highest rating in Innovate UK’s assessment for this funding round, will involve the ENU-hosted Scottish Centre of Excellence in Digital Trust and Distributed Ledger Technology.

It builds on Edinburgh Napier’s strong record in cyber security and digital trust technology. It has been recognised by the UK’s National Cyber Security Centre and Department for Science, Innovation and Technology (DSIT) as an Academic Centre of Excellence in Cyber Security Education (ACE-CSE) – and was the starting point for several successful cybersecurity spin out companies.

Background:

Edinburg Napier holds early accreditation from the National Cyber Security Centre (NCSC), is recognized as a leader in cyber skills and training. It’s globally ranked in Computer Science and Electrical and Electronic Engineering by U.S. News & World Report, and the UK’s Research Excellence Framework (REF) ranked Edinburgh Napier as the top modern university in Scotland for both research power and research impact, with nearly 70% of evaluated research deemed world-leading or internationally excellent.

The CISA releases election security plan 40 days before midterms

Posted in Commentary with tags on September 25, 2026 by itnerd

The CISA released its 2026 Election Infrastructure Security Plan 40 days before the November midterm elections, outlining cyber and physical threats facing election systems and federal resources available to state and local election officials.

The plan identifies potential threats including cyberattacks against voter registration databases, election networks and other systems, as well as physical threats against election facilities and personnel. It recommends measures including vulnerability scanning, risk assessments, incident response planning, information sharing and the use of auditable paper ballots.

CISA also designated its 10 regional directors as Election Security Advisors responsible for connecting state and local officials with federal cybersecurity resources. The plan comes after staffing and program reductions affected CISA’s election security operations, with some state election officials raising concerns about reduced federal support ahead of the midterms.

Ted Miracco, CEO, Approov:

“CISA’s new 2026 Election Infrastructure Security Plan is right to insist on paper ballots and hand audits. But it never once mentions mobile devices, apps or APIs, which is a strange gap given how much of American voting now runs through them.

“Most US jurisdictions check voters in on electronic poll books, and the most widely used one runs on Apple iPads. Forty-two states and D.C. let people register online, and millions of voters track their mail ballots by text message.

“Bangladesh, which went to the polls in February, took a clearer-eyed approach. Its Election Commission built a mobile app that registered more than 450,000 overseas voters and let them follow their ballots. Then it had every one of them mark a paper ballot and mail it home. The same commission had already scrapped electronic voting machines for all future elections. That is the right design: phones for access and tracking, paper for the vote itself, and serious security for the digital layer in between. Nobody can hack a paper ballot from abroad. They can hijack the phone number that gets a county clerk into the voter rolls. America already has the paper half. What it lacks is a federal plan that treats the phone in a voter’s pocket, and in an election official’s hand, as election infrastructure. While the ballot itself can stay analogue, the threat model cannot.”

Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security:

“My firsthand work as an offensive security tester has taught me that election security extends beyond voting equipment to the people, infrastructure, vendors, and processes supporting elections. A plan or scan is a starting point; the safeguards need to be tested in practice.”

Cyber and physical threats are clearly present when it comes to the midterms. And I am glad that someone is securing them from being tampered with. I hope that true with any threat that comes along.

Guest Post: Why are the FBI hackers so obsessed with their reputation? 

Posted in Commentary with tags on September 25, 2026 by itnerd

By Stefanie Schappert

For most ransomware and extortion gangs, the end goal has always been pretty simple: money.

Steal enough sensitive data, threaten to leak it, and hope the victim decides paying millions of dollars is better than dealing with the fallout.

But what happens when money is no longer the ransom?

This week, the notorious ShinyHunters hacker group announced it had breached multiple FBI systems, claiming it made off with sensitive data belonging to “almost all” FBI agents, employees, and even job applicants.

The FBI has said it is investigating the alleged breach.

The thing is, in this case, the hackers aren’t asking the FBI for millions of dollars – they’re asking the FBI to take back what the group says are “false allegations” about how they operate. 

ShinyHunters gave the FBI seven days to remove or correct statements it made in a May cyber advisory that the group says falsely accused it of exaggerating hacking claims, threatening victims and their families, engaging in swatting, and falsely claiming to possess compromising material. 

Seemingly insulted by the suggestion, ShinyHunters also took the time to “unequivocally” declare they are “NOT SEXTORTIONISTS” and “unequivocally” unrelated to the nihilistic hacking collective known as The Com.

The hackers also “unequivocally” (they used the word unequivocally a lot) insist the attack has nothing to do with money.

So why would a cybercriminal group go to such extraordinary lengths to defend its reputation?

Because in the world of cyber extortion, reputation is just another form of currency.

Honor among thieves

Extortion only works if the victim believes the threat.

If hackers threaten to dump sensitive information if a victim refuses to pay, there has to be some reason for that company to believe they will. 


If companies begin to suspect a hacker group is bluffing, the threat loses its power, the ransomware gang loses leverage over its victims, and the well runs dry, so to speak.

That’s why an FBI warning suggesting ShinyHunters may exaggerate its claims isn’t simply an insult. 

From the hackers’ perspective, it potentially damages the very credibility their business model depends on.

And ShinyHunters isn’t the first cybercrime group I’ve seen fiercely protective of its public image.

Last year, another fine group of extortionists – known as the Qilin gang – contacted my newsroom after taking issue with how I characterized the ransomware group in an article, politely requesting I correct it. 

Rather than get on the bad side of one of the most active gangs for nearly two years running, I kindly obliged. 

And it appears ShinyHunters has joined the quest, publicly taking issue with how journalists are covering the FBI story, in an obvious attempt to control the narrative.  

ShinyHunters also slammed journalists for mishandling the proof samples it so graciously provided, essentially “ruining the experience for everyone.” 

Citing the inappropriate sharing of highly sensitive data (yes, the irony is not lost here), the hackers – who clearly have a reputation to uphold – simply decided they would no longer engage with media for this faux pas. 

Cash is king – or is it?

For organizations negotiating with these groups, this raises a much bigger question.

As hackers accumulate increasingly sensitive information capable of destroying careers, exposing trade secrets, or putting people’s physical safety at risk, organizations may face demands that have nothing to do with money.

Think of all the highly sensitive data out there potentially at risk.  

Medical records, trade secrets, proprietary technology, private communications, customer databases, information about executives – or, in the FBI’s case, home addresses, phone numbers, family information, and other personal details of highly specialized federal agents.

Furthermore, with ransomware attacks, the public may eventually learn that an organization was breached, but rarely sees everything that happens behind the scenes: the negotiations, whether a ransom is paid, or how much.

In the past few years at least, we’ve become accustomed to hackers demanding tens of millions of dollars from their victims in exchange for stolen data.

But stolen information, as we’ve now witnessed, can be leveraged for much more than money, and the more damaging the information, the greater the leverage. 

From a simple retraction or public statement to a forced change in corporate behavior – or potentially a demand we haven’t even seen or thought of yet – many cyber insiders believe the stakes are evolving. 

The question we must ask isn’t simply how much a victim is willing to pay to protect its data, but what else it would be willing to do to protect it.

ABOUT THE EXPERT

Stefanie Schappert is a Senior Journalist at Cybernews covering cybersecurity, AI, national security, cyber policy, critical infrastructure, data privacy, and the human impact of technology. Based in New York, she is the first American journalist at Cybernews and a broadcast news veteran previously at Fox News, NY1 News, and Verizon FiOS 1. She holds a Master’s degree in Cybersecurity and is ISC2 Certified in Cybersecurity (CC). A guest commentator on TV, radio, and podcasts, including CBS News, iHeartMedia, and KTLA, Schappert explores how technology and cyber risk shape society, from ransomware attacks and hacker groups to emerging technologies and digital policy. She has been published in Fortune and cited by the US Senate, FCC, HHS, Henry Jackson Society, academic institutions, and other leading technology publications.

TELUS brings Toy Story 5 to life in select GTA stores

Posted in Commentary with tags on September 25, 2026 by itnerd

Toy Story 5 is gearing up for its highly anticipated release on Disney+, and TELUS is celebrating with a special in-store activation at five locations in the greater Toronto area. Fans of all ages can step into the world of Woody, Buzz and Jessie and experience the magic of Toy Story 5. While there, they can also discover why TELUS Stream+ — with Disney+, Netflix, and an Amazon Prime membership, all in one bundle — is the ultimate home for family entertainment.

What awaits you in select GTA stores:

  • Family photo ops: Snap a pic at our fun Lilypad photo op, featuring life-size Toy Story 5 props for a frame-worthy family photo.
  • Giveaway: One weekend only (Oct 17–18): Make any purchase in-store and receive a limited-edition Toy Story 5 power bank— available to the first 25 customers per store.
  • Nationwide home cinema contest: Customers across the country can enter into our Ultimate Home Cinema contest at https://www.telus.com/toystory5 and one lucky winner will win a 4K TV, soundbar and 1 year of Stream+ Premium (which includes ad-free Netflix and Disney+ as well as an Amazon Prime membership).
  • Stream+ Benefits: Get your favourite shows all in one subscription with Stream+, and learn how you can save up to 15% compared to subscribing separately. 

Participating Locations:

  • TELUS Toronto Eaton Centre
  • TELUS Square One
  • TELUS Sherway Gardens
  • TELUS Pen Centre
  • TELUS Vaughan Mills

Guest Post: Fortune 500 not so fortunate: Employee credentials leak every 100 seconds

Posted in Commentary with tags on September 25, 2026 by itnerd

Findings from a report from NordLayer, a toggle-ready network security platform for business, reveal that credentials of Fortune 500 employees are being leaked on the dark web at an alarming rate, with the overall number of leaked credentials reaching nearly 10 million. The numbers are accelerating in 2026 — dated infostealer logs from this year show a new Fortune 500 credential appearing on the dark web every 100 seconds.

NordLayer analyzed findings from NordLayer Intelligence by NordStellar, a threat intelligence platform, which revealed that 9.96 million Fortune 500 employees’ credentials were leaked on the dark web. The research found that over 6.6 million unique corporate email addresses were exposed. 

The leaked credential sets analyzed in the research comprise combolists — re-purposed credentials obtained from data breaches and infostealer infections — and dated infostealer logs, the only sets that record when the data was collected. 

Analysis of infostealer logs shows that 130,000 Fortune 500 employee credentials were leaked on the dark web across roughly 147 days in 2026 alone. This amounts to a new Fortune 500 credential surfacing on the dark web every 100 seconds.

“The credential leaks that could be traced down to this year were harvested using infostealer malware,” says Andrius Buinovskis, cybersecurity expert at NordLayer. “Unlike ransomware, which typically targets specific organizations, infostealer campaigns are often more opportunistic, focusing on individual users rather than entire companies. This malware primarily hides within pirated software, gaming applications, fraudulent ads, fake captchas, and phishing emails.”

Almost all credentials harvested from browsers

According to Buinovskis, infostealers scrape data from users’ devices almost immediately after infection, stealing any credentials or credit card details they come across. The browser is their preferred hunting ground for users’ log-in information — of the analyzed 2026 infostealer logs that record a source application, 99% point to browsers.

“Infostealer malware is specifically designed to extract credentials from built-in browser password managers. Because standard browsers store this sensitive data in predictable local directories, it is an easy target for malware,” explains Buinovskis. “The vulnerability of these industry giants proves that even the best corporate defenses can be bypassed by a single employee’s habits. In the face of opportunistic malware, the browser has become the enterprise’s weakest link.”

Desk-heavy industries top infostealer exposure rates

2026 infostealer data analyzed in the research shows that mid-sized Fortune 500 companies record higher infostealer exposure rates than the largest employers. Companies in the mid-sized bands (between 5,000 and 25,000 employees) record the highest median credential leakage rate — 1.27 unique credentials per 1,000 employees — while the largest employers show the lowest rates. The highest per-employee credential leak rates come from mid-sized technology companies, topping out at 42 credentials per 1,000 employees.

By industry, media and entertainment companies show the highest median credential leakage rate at 10.59 per 1,000 employees, followed by telecommunications and technology at around 3. According to Vakaris Noreika, a cybersecurity expert at NordLayer Intelligence, the rates mirror the attack surface these industries expose — sectors where nearly every employee holds a corporate login and saves credentials in a browser present infostealers with more to harvest.

“Many Fortune 500 giants employ vast numbers of frontline staff — whether on factory floors or in retail outlets — who operate without a corporate inbox, naturally lowering the company’s overall credential footprint,” says Vakaris Noreika. “At the opposite end, companies operating in the media and entertainment, telecommunications, and technology industries are almost entirely desk based, meaning nearly every employee is a potential infostealer target — and that exposure accumulates fast.” 

Safeguarding against infostealers

Buinovskis highlights five main measures companies should implement to build an infostealer-resistant cybersecurity strategy. 

  1. Secure the browser. Browsers are the main hunting ground for infostealers, yet consumer-grade browsers often lack robust security measures and the ability to enforce centralized security controls. To reduce the risk of users downloading infostealers, the browser must block malicious websites and prevent users from downloading infected files.
  2. Implement proper password hygiene. “Abandon built-in browser password managers and ensure that employees are not reusing the same passwords for different accounts,” says Buinovskis. “Password reuse can turn a single leak into a total compromise. If an employee uses the same login for every work application, they’re not just losing one password to an infostealer — they’re handing over the keys to every company resource at once.”
  3. Raise employees’ cybersecurity awareness. Cybersecurity is everyone’s responsibility — fostering this mindset is crucial to reduce user error where possible. When an employee understands how a single pirated file or a click on a link in a phishing email can compromise the entire company, it’s easier for them to shift from treating cybersecurity incidents like an IT problem and start seeing them as their own responsibility. 
  4. Monitor the dark web for any company credential leaks. This enables companies to have a heads up as soon as possible, empowering them to quickly implement necessary remediation steps, like flagging compromised accounts, resetting passwords that appeared in the data leak, and keeping a close eye on any anomalies.
  5. Adopt a zero-trust approach to security to reduce the fallout. “A comprehensive cybersecurity strategy is essential to minimize the impact of a data breach,” says Buinovskis. “Instead of automatically trusting users and devices, companies should embrace a zero-trust mindset and treat every login attempt as a potential threat until proven otherwise. By verifying every move, organizations can effectively stop threat actors from infiltrating the network, preventing a simple credential leak from turning into a major security breach.”

Methodology

NordLayer and NordLayer Intelligence by NordStellar analyzed leaked credentials and identified those tied to domains belonging to 2026 Fortune 500 companies, covering 500 companies and 3,692 corporate domains. Subsidiary brands were not included. The research began with 34.86 million raw records, which were deduplicated to 9.96 million unique email and password pairs, counted once per company. Each company was matched to its industry, revenue, and headcount. The leaked sets are made up of combolists and infostealer logs, and only the infostealer logs carry a collection date. About 130,000 of those dated records fall within roughly 147 days of 2026, which works out to about 1 new credential every 100 seconds. Per-employee exposure was calculated by dividing a company’s unique leaked emails by its headcount, then scaled to a rate per 1,000 staff and grouped by company size and by industry for comparison. 

What Canadians Need To Know About Cellphone Searches At The US Border

Posted in Tips with tags on September 25, 2026 by itnerd

Everyone’s cellphones contains years and years of data about you. And that is likely why US Customs And Border Protection is super interested in looking at your cellphone. The fact is that this can tell them a lot about you and whether they should admit you to the US. So in the interest of getting the facts out there, here’s what Canadians need to know about those cellphone searches.

  1. This is not new: Canadians think that cellphone searches are a new issue because of the most recent Trump Administration. But they are not. On they Canadian side of the fence, I wrote about this here and here. And on the US side of the fence (Not to mention other places. More on that shortly) I wrote about it here in reference to laptops. But cellphones can be copied and pasted here as well. And that was 2008 during the Bush/Obama administrations.
  2. They’re looking for social media: US Customs And Border Protection appear to be looking for someone’s social media, text messages and emails. That way they can determine if you are admissible to the US. In other words, if you say something bad about the administration, you can be kept out of the US.
  3. Refusing to hand over your password can end badly for you: A lot of us has password, fingerprint, or face authentication on our phones. And refusing to unlock a phone can make you “inadmissible” to the US because you cannot be properly inspected. And for you specifically, that may last years or forever.
  4. Erasing your phone can end badly for you: If you get the bright idea to erase your phone to stop US Customs And Border Protection from looking at your phone. Don’t. A US citizen got arrested because he wiped his phone at the border. There’s zero reason to believe that non-US citizens can’t be arrested as well.
  5. A burner phone might not even protect you. An idea is to get a burner phone so that it only has country specific info on it and it leaves off anything else. A good idea. But I have heard from a couple in my condo that they were refused entry to the US because having a burner phone implied to US Customs And Border Protection that they had something to hide. And I heard this from other people as well. I looked around and couldn’t find a hard and fast policy on this, but I have to assume that this might be a thing.

So what do you do? Well you have to make a call whether going into or through the US is worth it for you. My wife and I for example have determined a long time ago that it wasn’t worth it. So we won’t be visiting the US anytime soon. Also, you might want to consider that these rules in some way, shape or form might or will be coming to other places as well. Something to keep in mind if you travel frequently.