Archive for September 29, 2026

The Thanksgiving plus-one that actually help according to Samsung

Posted in Commentary with tags on September 29, 2026 by itnerd

Thanksgiving comes with plenty to be thankful for, and a pretty long to-do list.

This year, the Galaxy Z Fold8, Z Fold8 Ultra and Z Flip8 can be the holiday plus-ones that actually pitch in. Here’s how Samsung devices can take something off your Thanksgiving plate:

1.      Plan Like A Pro: As Thanksgiving plans come together, Galaxy AI helps keep you on track. Now Brief shares useful information at a glance, while Now Nudge recognizes dates, times and locations on screen and suggests next steps (like populating your calendar or pulling up a shared location).

2.      Become A Multitasking Machine: Too many cooks in the kitchen? Unfold Galaxy Z Fold8 or Galaxy Z Fold8 Ultra for more room to multitask. You can keep the Friendsgiving group chat open alongside that ambitious recipe, or go full screen on a YouTube tutorial when it’s time to de-lump the gravy.

3.      Capture The Moments Worth Keeping Everyone knows the phone eats first, and 50MP cameras on these Galaxy devices have the goods to document an Instagrammable plate. The Galaxy Z Fold8 Ultra’s 200MP main camera can capture everything from close-up details to the whole Thanksgiving spread, while Flex Mode on the Galaxy Z Flip8 makes hands-free shooting for group selfies as easy as pie.

For a little extra peace of mind over the holiday weekend, Samsung Care+ offers added protection for eligible Galaxy devices, with 24-month, 12-month and month-to-month coverage options.

97% of deepfake victims at schools were female, most fakes were created by students

Posted in Commentary with tags on September 29, 2026 by itnerd

Cybernews has analyzed the Resemble AI Deepfake Incident Database and found that there have been 83 deepfake incidents at educational institutions around the globe since the start of 2025. Researchers then analyzed the cases to understand who is being targeted, who is creating the content, and where these cases are happening. 

Here are the key findings:

  • 71% of recorded deepfakes at educational institutions involved sexual content;
  • 97% of victims were female;
  • 72% of victims were minors;
  • 65% of deepfake incidents at educational institutions happened at secondary schools;
  • Students themselves were the perpetrators in 57% of cases, while teachers/staff were the perpetrators in 18% of cases.

The cases show just how big a problem AI-generated deepfakes have become at schools, and how vulnerable children are. Creating a convincing fake no longer requires advanced technical skills, which is why prevention, clear school policies, and effective guardrails on AI platforms are as important as ever.

For more information on this, here’s the full study:

https://cybernews.com/ai-news/deepfakes-at-educational-institutions-research

CloudSEK Traces 85 npm Typosquats to Infrastructure Hosting a GPU Attack Framework Targeting vast.ai

Posted in Commentary with tags on September 29, 2026 by itnerd

CloudSEK is out with a two-part investigation — TOPHIT — uncovering a threat operation that connects a large-scale npm supply-chain campaign with an emerging GPU cryptojacking framework targeting the vast.ai marketplace.

In Part 1, CloudSEK researchers found that a single npm account, @prime0, published 85 typosquatted packages in just over three minutes, targeting 29 of the ecosystem’s most widely downloaded libraries, including chalk, semver, debug, minimatch and ajv. The packages were designed to beacon system information to a command-and-control server and, when loaded, could poll the server every 30 seconds for commands to execute on the infected machine.  

The researchers found that the same server hosting the npm command infrastructure was also running VHX Harvester, a purpose-built offensive framework targeting the vast.ai GPU rental marketplace, which CloudSEK investigates in Part 2. The evidence currently establishes shared infrastructure and an assessed common operator, rather than proving that the npm campaign was directly feeding victims into the GPU operation.  

Key findings from the investigation

  • 85 malicious npm packages were published by one account within approximately 3 minutes and 13 seconds, indicating automated mass deployment rather than manual publishing.  
  • The packages imitated 29 extremely popular npm libraries, with every target library recording at least 181 million weekly downloads.  
  • The malware could collect details including the hostname, username, operating system, working directory, IP addresses and Node.js version, and could establish a remote command channel when the package was loaded.  
  • The same infrastructure exposed VHX Harvester, a GPU-focused offensive platform actively targeting vast.ai.  
  • By September 25, the framework had enumerated 297 GPU host IPs, scanned 13,368 service endpoints, harvested metadata from 416 services, deployed 25 bridge agents and achieved one confirmed root shell on a victim Jupyter notebook.  
  • CloudSEK found that 17 API endpoints on the attacker’s own panel required no authentication, exposing the framework’s API documentation and even its complete agent source code with hardcoded credentials.  
  • Researchers also found 208 exfiltrated files, including 98 environment-variable dumps containing API keys, database credentials and cloud-service tokens from victim GPU instances.  
  • The framework outlines an eight-stage attack chain, moving from GPU-host discovery and scanning to credential harvesting, lateral movement through Docker networks, Jupyter access and ultimately the intended deployment of cryptocurrency miners. At the time of CloudSEK’s investigation, no miners had yet been planted, indicating the operation was still developing.  

One particularly interesting technique is the use of legitimately rented GPU containers as “bridge agents”. The operator rents a low-cost container on the same physical host as a target and then scans the internal Docker bridge network, potentially reaching services that are not exposed directly to the internet.  

Here’s both parts of CloudSEK’s investigation below:

Part 1: A One-Operator npm Typosquat Flood, Co-hosted with a GPU-Cryptojacking C2

Part 2: Renting the Attack Surface: A GPU Cryptojacking Framework Targeting vast.ai, Exposed by Its Own Misconfiguration
 

Dodge AI raises $2.65M from Accel and Google to fix the $600B enterprise firefighting problem

Posted in Commentary with tags on September 29, 2026 by itnerd

Enterprise software is never finished. Once SAP, Salesforce, Oracle, or Microsoft Dynamics goes live, the business keeps changing, and thousands of company-specific rules get built into the software over years. When something breaks, the answer is rarely in one place. Keeping it all running costs enterprises more than $600 billion a year. 

Dodge AI has raised $2.65 million to change how that work gets done, with an AI platform that resolves incidents and change requests across enterprise applications while documenting the custom logic that makes each system unique. The round was led by Accel and Google’s venture arm, with participation from New Build Venture Capital, Antler, Schema Ventures and angels from the SAP ecosystem.

Why this matters now

For decades, enterprise application maintenance has run through large system integrators like Accenture, TCS, and IBM. The standard playbook: put 20 to 50 people offshore to handle incidents, change requests, background jobs, and the everyday operational fires that keep enterprise systems alive.

That model keeps the lights on, but it creates a deeper problem. Fixes go undocumented, customizations pile up, and technical debt compounds inside systems of record. Over time enterprises grow more dependent on their maintenance partner, because the knowledge of how the system actually works lives across tickets, consultants, configuration layers, and memory.

What Dodge AI is building

Dodge AI’s platform acts as a control plane across enterprise applications including SAP, Salesforce, Microsoft Dynamics, Kinaxis, Oracle JDE and the other systems that sit at the core of large companies. It connects across business processes, ERP customizations, ITSM systems, and legacy configurations to pinpoint root causes, recommend fixes, and modernize faster.

The platform is also designed to become a source of truth for agents operating in production. In enterprise systems, the most important knowledge lives in the exceptions: why one warehouse allocates inventory differently, why one pricing rule overrides another, why a background job runs only at night.

Traction

Dodge AI is already working with more than a dozen enterprises, half of them publicly listed companies, on incident management and process optimization across stacks like SAP, Kinaxis, and Microsoft Dynamics. The platform fields hundreds of queries every hour, giving Dodge AI a widening view into how enterprise systems break and which patterns drive repeat maintenance work.

The results are concrete. When a truck could not load at a warehouse because a Goods Receipt Note was printing incorrect information, Dodge AI traced the fault across SAP, Kinaxis, and internal warehouse software and delivered a fix within minutes. Another customer had been running inventory planning overnight because SAP kept crashing if it ran in the morning; Dodge AI modernized the process and made it 132x faster, freed the team of 10 people maintaining it, and improved order allocation time by 8 hours.

What’s next

Dodge AI sees maintenance as the entry point to a much larger change in enterprise IT. Companies want to modernize, but CIOs cannot risk breaking systems that already work, and tight budgets are consumed by daily incidents. Solving maintenance first frees IT teams from constant firefighting and gives them a clearer path to modernization, because the same exception intelligence that resolves incidents today is what lets production agents operate safely inside mission-critical systems tomorrow.

The company is now pushing deeper into the maintenance layer, into the exceptions, configurations, and operational logic that define how each enterprise actually runs. Whoever understands mission-critical systems best gets to automate them, and Dodge AI is turning the hidden intelligence inside every enterprise into the operating manual for the agents that will run enterprise IT.

CData Launches Connect AI Gateway, One Control Point Between AI and the Systems That Run the Business

Posted in Commentary with tags on September 29, 2026 by itnerd

CData Software today launched CData Connect AI Gateway, the next evolution of the Connect AI platform designed to give organizations a single control point for the models, tools, data and actions used by AI agents and the individuals who work with them. The Gateway connects agents and individuals to enterprise systems through governed tools, applies company context at every step, enforces permissions down to the record and routes each request to the most efficient model for the task, helping enterprises move AI from answering questions to taking action.

Built on CData’s data layer, which already powers Palantir, Google, hundreds of enterprise products and thousands of customers worldwide, Connect AI Gateway understands the schemas, objects, relationships and operations of connected systems from day one. It imports the knowledge a company already holds, including metric definitions, business terminology and existing semantic models, and keeps what resolves each request, so context accumulates inside the customer’s environment and under its control. Schema-aware tools also send models only the information a request needs, cutting AI cost while keeping AI accurate across systems.

Bringing Enterprise Context to AI Agents and Individuals

Connect AI Gateway is built on CData’s portfolio of hundreds of schema-aware connectors. The connectors give AI access to the structure, relationships and semantics of the systems they reach, including applications, databases, data warehouses, on-premises systems and legacy environments. Its design makes five things possible:

  • Enterprise MCP built in, useful on day one. Hundreds of CData-built connectors exposed as governed tools over live systems the moment an agent connects: SAP, NetSuite, Salesforce, the warehouses and databases, on-premises and legacy included. One managed platform replaces the server-per-system sprawl, and MCP servers a customer already runs are governed under the same policy.
  • Context that compounds, under your control. The Gateway starts from the schemas and relationships the connectors carry, adds the metric definitions, terminology and semantic models a company already has, so Finance’s “revenue” and Sales’ “enterprise segment” resolve the same way every time, and turns approved corrections into reusable context, available to every authorized agent and user inside the environment.
  • Security and governance at every step of the request. Agents act with exactly the access their users have, and policy applies to the model, the tool and the data. Every request carries the identity behind it, person or agent, with entitlements enforced at the source down to the record. Changes are validated against the system’s own business rules before they commit, and one audit trail traces any figure in an answer back to the prompt, model, tool and policy behind it.
  • Reduced cost at every layer where tokens accrue. Schema-aware tools filter, join, and aggregate at the source, so only the answer set enters the context window, and routing sends each request to the most efficient model that can serve it. Spend is attributed and budgeted by team, agent, model, and tool.
  • No stack to steer AI toward. No warehouse to fill, no model to favor, no platform to route deeper into. Context lives in a portable graph outside any model or data platform, so frontier, open-weight and locally hosted models all inherit the same definitions and know-how—switch models, and the context arrives with it. If a model provider fails, requests can fail over to another with the context intact.

In CData Labs research, prompts run through CData’s connectors returned correct results 98.5 percent of the time across CRM, project management, data warehouse and ERP systems, against 65 to 75 percent for competing MCP approaches. A second study ran 22 models, from economy to frontier tier, against live enterprise systems. Through governed tools every model returned the same correct answer, and the least expensive did it at 178 times lower cost than the most expensive. Governed tools also kept models to the records they were authorized to change, something no model managed on raw access.

One Governed Path for Every Agent Interaction

As enterprises move beyond AI assistants and toward agents that execute business processes, organizations need visibility and control over more than the model generating a response. They need to know which systems an agent accessed, what data it used, which policies governed the interaction, and what actions it ultimately took.

Connect AI Gateway answers those questions from one place. Every agent interaction travels one governed path between the agent and the systems where work gets done: grounded in company context, checked against policy at the model, the tool, and the data, and logged from the prompt to the record it touched. Because that path is built on CData’s own connectors, organizations get this control without building and managing separate infrastructure for every system an agent reaches.

That’s what lets enterprises put agents into business-critical workflows—taking action, with data, context, security, and cost under control.

Availability

CData Connect AI Gateway is available through an early access program beginning September 29, 2026.

IDC Analyst: Enterprises Are Finally Seeing AI Returns, But the Bill for Keeping the Lights on Hasn’t Gone Away

Posted in Commentary with tags on September 29, 2026 by itnerd

Generative AI has crossed the line from experiment to return on investment for roughly half of enterprises, but the infrastructure that runs the rest of the business is still waiting for its budget. That tension is the subject of the newest episode of The Savvy CIO, the podcast from Park Place Technologies, available tomorrow wherever you get your podcasts.

Host Bradd Busick sits down with Rob Brothers, an IDC analyst who has spent nearly four decades on every side of the infrastructure lifecycle market, as a value-added reseller, as a third-party maintainer and now as an analyst covering the space. The conversation is built around a decision nearly every IT leader faces on a fixed calendar: what to do when the OEM warranty expires.

Brothers points to research showing a sharp turn in AI outcomes.

“Forty-five to 50% of enterprises are now beginning to see an ROI on their generative AI initiatives, which is great,” Brothers said. Busick notes that the same conversation a year earlier put that figure closer to 10 to 20%.

But the same budget that funds those initiatives has to come from somewhere. “A lot of the studies that we’ve done recently show that customers are really trying to use budgetary dollars for AI initiatives,” Brothers said. “And that doesn’t leave a lot for everything else.” Meanwhile, the price of the new gear has changed the math entirely.

David Kramer, President of Service Delivery at Park Place Technologies, warns that the sticker price is only the visible part of a refresh. “Your teams have to learn the new technology. You have to pay for installation and configuration of the new technology. You need time to let the new technology bake in and test in your systems and in your environments,” he said. He also notes who tends to be driving the urgency: internal campaigns for the latest hardware are “aided and abetted by the salespeople from the OEM itself, because the OEM is incentivized to sell more hardware.”

Brothers’ guidance for CIOs is to narrow the AI aperture and keep the existing estate supported while they do it. Expect 50 internal use case ideas, he says, cut to about six, and plan on two producing real outcomes, while acknowledging the constraint that outlasts every hype cycle: good quality data. “The data is generally what bogs everybody down,” he said. “It’s the same thing that bogged us down in AI is the same thing that’s bogging us down in gen AI.”

Episode 6, “The Renew, Refresh, Replace Dilemma with Rob Brothers,” is available on September 30 on Apple Podcasts, Spotify, and Amazon Music.

Kiteworks told customers to shut down to avoid pwnage

Posted in Commentary with tags on September 29, 2026 by itnerd

Kiteworks told customers to temporarily shut down certain systems after receiving credible threat intelligence about a potential attack, despite no confirmed compromise. 

Kiteworks is advising customers to facilitate a nine-hour precautionary shutdown window this weekend, in their local time zone. Customers who self-manage their Kiteworks systems—on-premises or on AWS or Azure—should shut down those systems themselves during this window. Kiteworks will shut down the customer systems it hosts, on behalf of customers, during the same window, so Kiteworks-hosted customers are not required to take any action.

Charming.

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“This is wild. This isn’t an active attack. People aren’t actively being breached, and yet the vendor is telling customers to take their systems offline. I’ve never heard of anything like this before.

“It remains to be seen whether Kiteworks is overreacting or whether this is exactly the right response, especially depending on how difficult the patch is to deploy. But wow. I cannot remember another situation where a vendor flat-out told customers to shut their systems down without a known exploit or an active attack in the wild.”

Phil Wylie, Sr. Consultant & Evangelist, Suzu Labs (https://www.linkedin.com/in/phillipwylie)

“Threat intelligence is most valuable when it gives defenders an opportunity to act before an incident occurs. The Kiteworks situation is a good example of intelligence being used proactively rather than simply explaining what happened after a breach. Kiteworks received credible intelligence from federal authorities, recommended a precautionary shutdown, and has since said it found no indication that its systems or customer environments were compromised.

“When credible intelligence suggests an attack may be imminent, organizations shouldn’t wait for a confirmed compromise before taking action. Security teams should evaluate the credibility of the intelligence, determine their exposure, increase monitoring, preserve logs, verify that systems are fully patched, review privileged access, and consider temporarily isolating or disabling systems when the potential impact justifies the disruption.

“That last part is important because cybersecurity is ultimately risk management. Taking a production system offline can have a significant business impact, but so can leaving a potentially vulnerable system exposed when there is credible intelligence that an attacker may be preparing to target it. The decision should weigh the confidence of the intelligence, the organization’s exposure, the criticality of the system, and the potential consequences of exploitation.

“This incident also highlights why threat intelligence needs to be operational. Intelligence sitting in a report or dashboard doesn’t protect anything. Organizations need processes that quickly turn intelligence into actions for SOC teams, vulnerability management, incident response, network defenders, and business leadership.

“Another important takeaway is that defenders won’t always have a CVE, an indicator of compromise, or a confirmed exploit before they need to make a decision. In this case, Kiteworks initially said all known vulnerabilities were addressed in version 9.5.1 while warning about the possibility of attacks involving vulnerabilities that weren’t yet known. Subsequent reporting says the concern was narrowed to a severe vulnerability affecting the Advanced Forms product, which Kiteworks said is enabled for fewer than 1% of its customers, with no evidence the vulnerability had been exploited.

“Security teams should also use situations like this to test whether their incident response plans actually support preventive action. Can they quickly identify every instance of an affected product? Can they isolate it? Can they preserve the necessary telemetry before shutting it down? Can they communicate the business impact to leadership? Those capabilities can make the difference between acting on threat intelligence and simply watching an attack unfold.

“One of the more interesting lessons from this incident may ultimately be that a shutdown followed by no compromise shouldn’t automatically be viewed as an overreaction. Preventive security is difficult to measure because success sometimes looks like nothing happened. When credible intelligence indicates that an attack could be imminent, temporarily accepting operational disruption may be preferable to accepting an unknown but potentially much larger security risk.”

One wonders if this issue, whatever it is, is truly addressed. Because clearly there is a credible threat out there that isn’t being spoken about.

OpenAI Does Not Release Its Latest Model Over “Safety Concerns”

Posted in Commentary with tags on September 29, 2026 by itnerd

From the file marked “duh”, OpenAI has announced that it has scrapped the release of its new GPT-6.1 Astra model after safety concerns that it showed “higher levels of deception”. The decision comes just days after OpenAI models were found to have accessed data on two US government websites.

Luke Hinds, co-founder and CEO of nolabs has this comment:

Barely a week goes by without another story like this, and each one points to the same problem for businesses. Agents are only useful when they have the freedom to act, but they are single-minded. When one route is blocked they look for another, even if that means pushing past the limits someone put in place.

Some will dismiss these ‘too dangerous to release’ announcements as marketing, and there’s a fair debate about whether a model is being deliberately deceptive or simply making mistakes. For a business, the outcome is the same. An agent with access to your code, credentials and systems can do real damage whatever its intent.

Frontier labs can’t be both the creators and the guardians of these agents. Their incentive is to make them more capable, and they have no way of knowing what your agent should be allowed to touch. Businesses need their own independent controls that give agents the access they need for the task, stop them reaching for anything more, and keep a record of what they actually did. No one should be trusting an agent to mark its own homework.”

Face it. You can have all the guardrails that you want in place and clearly it does not make a difference. Which means one inescapable truth comes to light. OpenAI and Sam Altman cannot be trusted. Ever.