Archive for September 28, 2026

New CalPhishing Campaign Uses Internal Email Forwards to Reach Targets

Posted in Commentary with tags on September 28, 2026 by itnerd

Fortra Intelligence and Research Experts (FIRE) have identified a new CalPhishing variant where attackers exploit internal referrals to conduct credential theft attacks. 

Key takeaways:

  • Attackers pose as prospective customers and contact non-sales employees first.
  • Employees unknowingly become “trust bridges” by forwarding meeting-booking links to sales teams.
  • The booking page appears legitimate but ultimately prompts users to sign in with Microsoft 365 credentials.
  • The attack abuses trusted business workflows instead of spoofed identities or compromised accounts.
  • A successful compromise can lead to email access, data theft, fraud, and further phishing attacks.

Full analysis here: https://www.fortra.com/blog/calphishing-through-trust-chain

Autoheal raises $7.9M to build a self-improving software factory for enterprises

Posted in Commentary with tags on September 28, 2026 by itnerd

AI is helping engineering teams ship more code, faster than ever. But that acceleration comes with a growing operational burden: more production incidents to respond to, more security vulnerabilities to remediate, and spiraling token costs to contain. Autoheal is built for these challenges and already battle tested at industry leaders such as Nomura Bank and AvidXchange where off-the-shelf point agents failed to deliver. 

Today, the company announced a $7.9 million seed round to scale the industry’s most advanced self-improving software factory, giving enterprise platform engineering teams a way to build, deploy, govern, and continuously improve multiplayer cloud AI agents across the software development lifecycle. The round was led by Innovation Endeavors, with Harpinder Singh joining Autoheal’s board, alongside participation from Emergent Ventures, U&I Ventures, Darkmode Ventures, Batch Ventures, and Param Hansa Values.

Why platform engineering needs a new operating model 

Repetitive SDLC workflows such as incident response and vulnerability remediation consume more than a third of an engineering team’s capacity. As coding agent adoption grows, controlling LLM spend and managing context is joining that list. To manage these demands, platform engineering teams are shifting toward a “software factory” model powered by specialized AI agents.

However, at scale rollout of these agents often fails due to fragmented tools, a lack of shared context, and strict security constraints. Establishing a unified platform for creating, managing, and iteratively improving all software factory agents, including the existing coding agents, has therefore become an immediate priority. This ensures every agent gets the same engineering context, secure production access, private evaluation infrastructure, cost controls, and a way to stay current as the organization changes.

What Autoheal is building 

Autoheal’s software factory gives enterprises the infrastructure and tools to transform their engineering organization into a self-improving machine. It connects existing coding agents, code repositories, CI/CD, observability, cloud runtimes, and issue trackers, giving all worker agents in the factory a shared engineering context graph. As these worker agents keep executing post-coding repetitive workflows, two self-improvement agents keep working in the background:

  • The Evaluator agent scores every worker agent’s run. For example, a coding agent can be evaluated by scoring the specs and PRs it generates, using the downstream signals of review comments, CI failures and caused incidents as the evaluation criteria. 
  • The Healer agent fixes low scoring worker agents by opening pull requests that improve skills, prompts, tools, or model selections. It even verifies those changes against historical benchmarks for regressions before engineer review.

For platform engineering teams, this creates a continuous agent healing loop as systems change. Every behavior change is version-controlled in git and requires engineer approval. Actions remain governed and audited, with visibility into access, reasoning, and costs. The end goal is higher accuracy, faster execution, and lower cost per successful task with engineers expanding autonomy as agents prove reliable.

Traction

Autoheal is already operating inside complex regulated environments, where engineering teams are using it to cut incident response times, handle customer support escalations and free up thousands of hours of engineering capacity.

Origin story 

Autoheal grew out of the founders’ experience building enterprise engineering and AI platforms at Harness, Microsoft Azure, ThoughtSpot and AppDynamics. After scaling Harness to over $200M ARR, the team recognized a new reality: while building individual AI agents had become easy, safely deploying them across the SDLC and across engineering teams had become extremely time and token consuming. To prevent agent sprawl and ensure day-2 governance, a platform must manage agents as code, overseen by continuously learning meta-agents. That insight became Autoheal’s software factory.

What’s next

Engineering processes & implicit architecture decisions are locked within an enterprise’s boundary or engineer’s minds. Frontier models have been trained on public internet, open source code and synthetic data but not enterprises’ data. Enterprises want to build sovereign & cost-effective intelligence on this data because it’s a competitive advantage. Autoheal will first capture this data by operating the factory and then train small private models of various architectures per customer. These models will soon power the majority of tasks in the software factory which are not generative in nature.

In the long term, the same architecture can extend beyond software engineering into data and security engineering. Autoheal is betting that every large enterprise will run a software factory that has its own population of specialized agents, and wants to be the platform that engineering teams use to build, govern and continuously improve them.

Producing code has never been easier, but AI-generated bugs and rising debugging workloads are slowing software delivery  

Posted in Commentary with tags on September 28, 2026 by itnerd

New research from Undo, the technology that gives developers the runtime context needed to solve the most challenging problems in the most complex codebases, finds that almost four in five (79%) engineering leaders say their release cycles are no faster than before, despite their teams being able to produce code more easily than at any time in their careers. 

As AI agents have increased the volume of code they can create, engineers now spend nearly twice as long debugging it as they do writing it, averaging 16.9 hours a week. That accounts for 42% of the average working week. Engineers are simply unable to keep up with their agents, leading to more than a third (35%) of AI-generated code reaching production before they’ve fully comprehended it. 

Adding to the risk, AI agents frequently hallucinate the cause of failures, or fail to identify problems in the codebase entirely. In the past six months, as a result of their use of AI coding tools:

  • 81% of organizations have had a production incident or service outage affecting internal users or customers
  • 93% have had the root cause of an issue incorrectly diagnosed because of an AI hallucination
  • 91% have had test escapes, serious defects or poorly optimized code enter production

Four in five (80%) engineering leaders say coding agents struggle to solve difficult problems in large-scale, complex codebases. The arrival of more powerful models doesn’t offer a realistic solution, with a strong degree of cynicism about the impact the planned IPOs of Anthropic and OpenAI will have on AI affordability. The majority (82%) of engineering leaders think the costs of coding agents will go ‘through the roof’ as the AI labs prioritize making Wall Street happy.

However, engineering leaders widely agree that improving model context is more important than increasing their capability to make AI more powerful. More than four in five (82%) say AI agents would be far more useful for code comprehension and debugging if they were grounded in the context of what happened during runtime.

To learn more, download the full Overcoming the limitations of coding agents in complex software systems report here: https://undo.io/research-report-2026

Methodology

The research was conducted on behalf of Undo by independent research firm Coleman Parkes during July and August 2026. It surveyed 300 senior engineering leaders at organizations with revenues of $250m or above that deliver mission-critical software built on large, complex codebases, 93% of whom work with C/C++. Respondents were based in the United States (200) and the UK (100), across financial services, networking, semiconductor design, computational software and data management.