Archive for October 1, 2026

Comparitech: Which countries are seeing the fastest growth in data centres?

Posted in Commentary with tags on October 1, 2026 by itnerd

Comparitech researchers have published a new study looking at which countries are seeing the fastest growth in data centers. 

Data centers are, for the first time, being targeted in military conflicts as a means to disrupt daily life and damage economies. A Russian attack recently hit a Datagroup facility in Ukraine. A series of strikes by Iran in March damaged AWS facilities in both Bahrain and the UAE. A month later, an Oracle data centre in Dubai was damaged.

To find out how the data centre landscape was changing – and where these changes were concentrated – Comparitech analysed the concentration of and increases in data center numbers of 143 countries between 2023 and 2026. 

Key findings include: 

  • The US saw the biggest increase in data centres (by numbers reported), rising from 5,300 in 2023 to 5,427 in 2026
  • The Netherlands has the greatest concentration of data centres by landmass (8.9 per 1,000 km²) and population (16 per 1 million people)
  • A quarter of the countries experiencing the highest data centre growth suffer from ‘extremely high’ water stress
  • The US has more than 10 times more data centres than any other country
  • Three of the top countries for data centre growth have an internet penetration of less than 50% of the population
  • Five of the countries experiencing the highest data centre growth have more than doubled their data centre counts in the past three years

Read more here: https://www.comparitech.com/news/which-countries-are-seeing-the-fastest-growth-in-data-centres/

October Is Cybersecurity Awareness Month

Posted in Commentary on October 1, 2026 by itnerd

Cyber Security Awareness Month (Cyber Month) is an internationally recognized campaign held each October to help the public learn more about the importance of cyber security. The campaign helps people stay secure online by teaching them simple steps to protect themselves and their devices.

Eric Polet, Director of U.S. Operations at Arcitecta:

Data Integrity Is the New Security

As data becomes the foundation for research, innovation, and critical decision-making, organizations need more than secure storage; they need confidence in the data itself.

Data security and governance begin with knowing what data exists, where it came from, who can access it, how it is being used, and what happens to it throughout its lifecycle. Metadata provides the intelligence to make that possible, turning data management from a collection of disconnected controls into an integrated, policy-driven capability.

Data security is no longer simply about protecting where data lives. It is about protecting the integrity, context, and trustworthiness of the data itself. Organizations that thrive will be those that design for resilience, building zero-trust, metadata-rich, immutable data environments that protect both integrity and reputation.

Don Boxley, CEO and Co-Founder, DH2i (https://dh2i.com/):

“The biggest cybersecurity threat may not be the attack you don’t see coming. It may be the aging infrastructure you already know is there. 

Organizations are still running critical applications and databases on systems that are years behind, and accumulating technical debt because they continue to work. “It still works” is a dangerous standard for production infrastructure supporting the business. Cybersecurity Awareness Month should be a wake-up call that encourages us to look beyond the latest threats and ask more fundamental questions. Is the infrastructure serving as the virtual backbone of the business truly resilient? Can workloads be moved quickly and safely? Is there a single platform or environment that the organization is dangerously dependent on? Who and what can access critical systems, and is that access limited to only what is actually necessary?

Modernization doesn’t mean immediately ripping and replacing everything. It means eliminating unnecessary technical debt… reducing infrastructure complexity… and building in the flexibility, security, and availability needed to keep critical systems running and safe when something goes wrong. Because when that worst-case scenario actually happens, that is definitely not the time to find out your infrastructure just wasn’t ready for it.”  

Richard Copeland, CEO, Leaseweb USA (https://www.leaseweb.com/):

“One of the most dangerous things a company can discover during a cyberattack is that it has nowhere else to go. If critical applications, data, and infrastructure are concentrated with one provider or on one platform, a single incident can quickly become a business-wide crisis. Cybersecurity Awareness Month should be a reminder that cyber resilience isn’t only about keeping attackers out. It’s about making sure that when something does go wrong, one compromised environment, outage, or provider problem can’t take the entire business down with it.

Organizations consequently need to start thinking about infrastructure differently. Every workload does not belong in the same cloud, platform, or provider. Security, sovereignty, availability, performance, and risk should determine where a workload lives. Certainly, not vendor loyalty or convenience. Infrastructure should follow the workload, not the vendor. Because the worst time to discover that you’ve put all your eggs in one basket is after someone has already kicked over the basket.”

Estelle Azemard, CEO, Leaseweb Canada (https://www.leaseweb.com/):

“For Canadian organizations, Cybersecurity Awareness Month should raise a question that is becoming increasingly difficult to ignore: do you actually know where your critical data is, who ultimately controls the infrastructure underneath it, and what laws could reach it? A cyberattack is frightening enough. Discovering during a crisis that your most important workloads are tied to a single provider, governed by another jurisdiction, or difficult and expensive to move can turn a security incident into a much larger business problem. Canadian companies need to think about cybersecurity not simply as protecting data, but maintaining control over it.

That means resisting the idea that every workload should automatically go to the same cloud or provider. Some applications may belong in public cloud, while sensitive data may be better suited to private or Canadian-based infrastructure, and other workloads may require dedicated environments. The point is having the freedom to make that decision based on security, sovereignty, compliance, performance, and business requirements — and to change it when those requirements change. Infrastructure should follow the workload, not the vendor. For Canadian businesses, maintaining that independence isn’t simply an infrastructure strategy anymore. Increasingly, it’s part of protecting the business itself.”

Gina Cardelli, Principal Security Strategist at Fortra:

“Most attackers still succeed through the old, familiar weaknesses: compromised credentials, excessive privileges, exposed systems, and poor security hygiene. AI may make attackers faster and more scalable, but it doesn’t make those fundamentals less important. If anything, it raises the cost of ignoring them. 

“Organizations should assume something will eventually go wrong and focus on limiting the blast radius. Whether the entry point is phishing, stolen credentials, prompt injection, or an abused AI agent, the goal should be containment. Understand what your AI can reach and do, and consider the worst-case scenario for each use case. Least privilege, segmentation, human approval for actions, logging, and continuous monitoring can make every step of an attack harder, noisier, and less consequential.” 


Nicole Beckwith
, Senior Director of Security Engineering & Operations, Cribl:

  • “For Cybersecurity Awareness Month this year, it’s time for enterprises to go beyond the usual tasks of reviewing risks, patching systems, and testing backups. Expect budgets for AI to come under greater scrutiny over the next 12 months, as leaders focus on tangible ROI and which spending needs to be reined in where. In tandem, AI will be a primary factor in why the cybersecurity threat landscape will keep accelerating given that agents are gaining greater autonomy and access to enterprise systems. The time is now for security teams to have an honest conversation about the best use of AI, its risks, what the threat model is internally, and whether or not current budget and staffing plans are going to be enough. As AI reaches its inflection point this Cybersecurity Awareness Month, leaders need to identify where AI delivers real value, eliminate waste, and invest in the people and controls to manage autonomous systems. The organizations best prepared for the next phase will be those that treat AI as critical infrastructure that must be continuously measured, monitored, and secured.”

Chris Bevil, Principal, Global Cyber Resilience & AI, Commvault: 

  • “AI is forcing us to rethink what ‘cybersecurity awareness’ actually means. For years, we taught people to look for the tells: the misspelled word, the strange email address, the suspicious link. AI is steadily taking many of those tells away. The skill we need to build now is not just recognition; it’s verification. But I would also take Cybersecurity Awareness Month one step further. Awareness cannot stop with the employee. Attackers do not care how we drew the organizational chart. An incident can move from identity to applications to data to infrastructure very quickly, yet many organizations still have security, IT, disaster recovery, cyber recovery and business continuity operating in separate lanes. That is where cyber resilience becomes really important.
  • “For 2027, I would be thinking seriously about two things: the rise of the machine workforce and the ability to prove recovery. Agentic AI is creating a new class of identity inside the enterprise. We have spent decades thinking about what employees, administrators, and service accounts should be allowed to do. Now we have AI agents that may be able to access data, interact with applications, use credentials, and take actions on our behalf. I would treat an AI agent much like a privileged employee. Know who it is. Know what it can touch. Know what it is allowed to do. Watch what it actually does. And have a way to take away the keys when something goes wrong. The other investment I would make is in recovery that can be proven, not assumed.”

Vidya Shankaran, Field CTO – Head of Americas, Commvault:

  • “In the AI context — smart and robust identity resilience is core to protecting your estate against both humans and agents looking for vulnerabilities in your armor to penetrate. Discovering gaps in identity, such as identifying systems that have unfettered access to high value data, need to be remediated as soon as possible. This level of audit-ability and remediation will decide which enterprises can survive this decade and thrive in the next decade. Security leaders must also budget for PQC preparation, which includes evaluating a C-BOM (cryptography bill of materials) and creating a crypto inventory, as well as ensuring that certificate lifecycle management and crypto agility are top priorities for businesses in the new year. 2029 PQC readiness, per the White House Executive Order, makes it highly critical and preparation needs to start sooner than later.”

Rishi Bhargava, Co-Founder, Descope:

  • “Cybersecurity Awareness Month should prompt organizations to consider how identity and security fundamentals apply to AI agents, not just human users. Every agent should have a verifiable identity, task-specific permissions, a designated owner, and a complete audit trail of its actions. High-impact decisions should require human approval, especially when an agent is acting on behalf of a customer or employee. AI agent adoption may look fast right now, but without the proper identity guardrails and infrastructure in place, this adoption will be short-lived and won’t reach its full potential.”

Chris Boehm, Field CTO, Zero Networks: 

  • “The number that should reset every roadmap heading into October is 29 minutes. Average eCrime breakout time fell to 29 minutes in 2025, the fastest observed case took 27 seconds, and AI-enabled adversary operations rose 89% year over year. In 2021 that figure was measured in hours. AI compressed the reconnaissance and credential testing that used to give defenders a day of runway into a coffee break, and no SOC triages a ticket that fast at 2 a.m. So security operations are shifting from finding the intruder to making sure the intruder has nowhere to go. That’s why network and identity segmentation moved from the project nobody wanted to the one on every zero trust plan. Analysts project that by 2026, 60% of enterprises pursuing zero trust will use more than one form of microsegmentation, up from less than 5% in 2023. They’re also saying static, IP-based rules can’t hold against AI-driven attacks and that identity has to govern reachability now. A rule tied to an IP protects a location. Attackers steal identities.
  • “Where this goes next is consolidation, and it’s overdue. Buyers announced 426 cybersecurity acquisitions in 2025, with disclosed value reaching $92.5 billion, an 82% jump over the prior year, and the first half of 2026 logged 219 deals, the fastest half on record. My prediction for the next twelve months: the winners won’t be the broadest platforms but the narrowest controls that actually stop lateral movement, because a 29-minute window rewards prevention over correlation. Expect more identity and network isolation deals, more pressure on the SOC to shrink blast radius instead of the alert queue, and a new class of problems as AI agents get provisioned with credentials nobody scoped. We’ve always had unknowns around the corner. In 2026 the corner is closer, and the environments that hold up will be the ones where a compromised login reaches almost nothing.”

Nicholas DiCola, Chief AI Security and Customer Officer, Zero Networks: 

  • “AI is turning many things on its head including cybersecurity from a few perspectives. One, Mythos / Glasswing is producing a high number of vulnerabilities that companies need to respond to, adding unexpected work and a backlog of vulnerabilities to fix, hopefully before someone else finds it. Two, AI is changing the way security analysts work, enabling enhanced investigation and response, but human-in-the-loop continues to slow AI ability to help. Three, attackers are using AI to speed up attacks. This means attackers still have the advantage when looking across these three.”

Max Gannon, Cyber Intelligence Team Manager at Cofense:

“Cybersecurity Awareness Month comes at a time when artificial intelligence is rapidly changing how phishing attacks are created, customized, and carried out. AI has made it easier for attackers to produce convincing, highly personalized emails at speed and scale, eliminating many of the traditional warning signs employees were once taught to look for. While defensive AI is an important part of modern email security, models are ultimately trained on previously seen threats and can struggle to identify new tactics as they emerge.

That makes the human layer increasingly important. Employees should not be treated as the weakest link in cybersecurity. When properly trained and empowered to report suspicious messages, they become a source of real-time threat intelligence. A reported phishing email can give security teams visibility into an attack that has already bypassed automated defenses, helping security teams identify and remove related threats before additional users engage.

Cybersecurity Awareness Month is an opportunity to move the conversation beyond simply teaching employees not to click. Organizations should build a culture where employees understand evolving threats, feel confident reporting suspicious activity, and receive training based on what is actually reaching inboxes. As AI reshapes both attacks and defenses, combining the speed and scale of technology with human judgment and reporting will be critical to keeping pace with emerging phishing threats.”

 Michael Centrella, Head of Public Policy at SecurityScorecard:

“Cybersecurity Awareness Month is taking on new meaning in the age of AI. As organizations rapidly adopt AI, threat actors are using the same technology to identify weak links, exploit third-party access, and move through interconnected systems faster than ever before.

Security leaders need to understand how AI is reshaping the technologies, vendors, and dependencies their businesses rely on. Organizations cannot manage today’s supply chain risk with monthly or even weekly assessments. They need continuous visibility into their third-party ecosystems, an understanding of where points of failure exist, and the ability to detect and respond as risk changes.

AI may accelerate the threat landscape, but the underlying lesson is the same. You cannot protect what you cannot see. Cyber resilience increasingly depends on knowing your entire ecosystem and being prepared to act before a weakness in one partner becomes a problem for everyone.”

Christopher DeBrunner, CISO at CBTS:

“This Cybersecurity Awareness Month comes at a time when AI is continuing to accelerate the speed of cyberattacks. Attackers are using AI to move faster and scale techniques that once required more time and effort, leaving, us, the defenders with less time to identify and contain a threat. That puts more pressure on all organizations to understand where they are exposed and how quickly they can respond when something changes.

Identity is one of the biggest areas (if not the biggest) that needs to change. As organizations introduce more AI and automated workflows, they are also creating more non-human identities with access to systems and data. Those identities need to have more scrutiny and discipline around permissions, monitoring, and lifecycle management that organizations already apply to employees. Without that visibility and governance, AI can make small gaps very large.

On the flip side, AI is also helping defenders keep up by taking some of the manual work out of investigation, mitigation and response. The goal should be measurable improvement in how quickly teams identify, investigate, and contain risk. The priority now is making sure AI strengthens the security program you already have rather than adding complexity to gaps that have not been addressed.”

Farooq Khan, VP of Software Security NETGEAR:

“Cybersecurity Awareness Month is a reminder that small and medium-sized businesses are not too small to be targeted. Attackers can use automation and AI to look for weak credentials, outdated systems, misconfigurations and other openings across a large number of organizations at once.

Adding another standalone security product is not always the answer. Security needs to be built into the network, with access control, visibility and threat prevention working together. That matters even more for smaller IT teams that do not have the time or resources to manage a growing collection of disconnected security tools.

Businesses also need to assume that at some point, something will get through. Someone may click a malicious link, credentials may be compromised or an unpatched device may become an entry point. The goal is to keep that initial compromise from spreading. In a flat network, an attacker may be able to move from one system to another. Segmentation, zero-trust access and better network visibility can help contain the threat and limit the damage.”

Joseph Perry, Cybersecurity Researcher and Advanced Services Lead at Arcova:

“What is the point of cybersecurity awareness month? Not rhetorically, but genuinely. If you are a cybersecurity leader or practitioner for whom the phrase “cybersecurity awareness month” has meaning, what does a successful month look like? Do we want people to be more aware? Of what? Is it threats? If so, surely we should broaden it from the cyber and call it Threat Awareness Month (or my preferred name, “Ahh!ctober”). If it is cybersecurity threats in particular, why?

A few years ago, an elderly relative was tricked over the phone into driving to her bank, obtaining a cashiers’ check for several thousand dollars, and driving to a seedy gas station in a dangerous neighborhood. The threat actor kept her on the phone the entire time, often screaming abuse and threats. When she arrived at the gas station, the clerk asked her what she was doing there, heard the story, and physically hung up her phone for her and told her to immediately drive to the police station. There is no doubt in my mind whatsoever that a bored gas station clerk saved a life that afternoon, and that they saved it from a threat which meets every single description of cyber threat except one: it didn’t use a computer.

Here’s our controversial take: Cybersecurity Awareness Month is not about making the general public aware of cybersecurity threats. Or at least, it shouldn’t be. Cybersecurity Awareness Month should be about us, the cybersecurity community, being aware of how we touch the world and how we can make it safer, even when we’re not behind a screen. How we can use our unique knowledge and experience to help those who lack the same.

This October, give your talks, run your tabletops and your drills, even (if you really must) send your fake phishing emails to test employee attentiveness. But while you’re going through those motions, give yourself a goal as well. Find some concrete way to make the world you touch a little bit safer, to help the people whose lives intersect with yours in the way a cybersecurity professional is best equipped to do. Talk to your family and community not just about hackers and cyber threats, but about extortion and all the tools in a manipulator’s toolkit. Not just about ransomware and business email compromise, but about asking for help when they’re afraid and trusting you to protect them from those who threaten to bring the sky down on their heads.

Don’t try to scare them; they’re plenty scared as it is. Instead, give them something far more useful than fear. Give them a plan.”

Ben Bernstein, Manager, Cybersecurity Advisors Team, Huntress

Right now, the industry news cycle is heavily focused on autonomous AI attacks and LLM breakouts. While threat intelligence teams certainly see these edge cases in their research, the public narrative makes them sound exaggerated. The reality is far less dramatic. Even when attackers do experiment with these concepts, they are not doing anything fundamentally new under the hood. Long before the current AI hype wave, static scripts, automated scanners, and script kiddies were already doing the exact same thing: looking for the path of least resistance through internet-exposed, vulnerable, and misconfigured assets. If you look at what is actually driving volume and impacting organizations of all sizes today, from local SMBs up through the enterprise, the threats are grounded in standard tradecraft: ClickFix variants, fake e-signature lures, Adversary-in-the-Middle (AiTM) phishing, and RMM abuse.

There is nothing inherently malicious about remote monitoring and management software. IT administrators rely on these exact tools every day to perform routine maintenance and troubleshoot user systems. However, that utility is exactly why threat actors choose them. Because many RMMs come with built-in persistence mechanisms and frequently run with elevated administrative rights, attackers can gain deep access without ever deploying custom malware. Legacy AV and traditional security tools struggle to trigger alerts on this activity because RMM applications carry valid digital signatures from legitimate vendors. When an attacker operates through software like AnyDesk or ScreenConnect, standard security controls simply see an approved application executing routine commands. That makes detection difficult since the malicious behavior blends directly into daily administrative traffic, masking an intrusion as standard IT work.

Building true resilience against the threats hitting networks every day comes down to pragmatic execution. Focus on the fundamentals: minimize your attack surface, patch your infrastructure, and validate your controls with regular red teaming. Operate under an assumption of compromise, back that up with 24/7 behavioral monitoring, and never assume an action is safe just because it originates from an approved application.

Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ:

“A security control that has never been tested against the behavior it’s supposed to stop is still an assumption. Cybersecurity Awareness Month should encourage organizations to challenge more of those assumptions.

Would an endpoint control catch the lateral movement technique your threat model says you’re worried about? Would an identity control interrupt privilege escalation? If one defense failed, would another detect or stop the attack before sensitive data was reached? These questions can, and should, be tested before an incident.

CTEM gives organizations a continuous way to identify and prioritize exposure. Adversarial exposure validation adds evidence by testing defenses against real-world attacker tactics and techniques. The result goes beyond a theoretical risk score. Teams can see where tested protections work, where they fail and whether remediation closed the gap.

Awareness helps you understand what attackers might do. Validation shows how your defenses respond when those behaviors are tested.”

Ross Filipek, CISO at Corsica Technologies:

“A company can have endpoint protection, backups and MFA and still have a very bad day if nobody knows who is supposed to make the first call. It’s that part of cybersecurity, the dysfunction, that often gets overlooked.

For midmarket businesses, incidents land in the hands of small IT teams every day, and they’re expected to suddenly investigate the attack, keep employees working, communicate with leadership and coordinate recovery at the same time.

Preparation should reflect that reality. Organizations need to know which systems absolutely have to stay running. They need recovery plans people have actually practiced. Leadership should understand when outside help gets involved. Employees should know where suspicious activity gets reported without having to hunt for the right process during an emergency. Cybersecurity awareness isn’t only knowing how attacks happen. It’s also knowing how your organization will function after one does.”

Steve Povolny, Vice President of AI Strategy & Security Research at Exabeam:

“The security industry has spent years teaching people what suspicious looks like: bad grammar, strange links, logins from impossible locations. Attackers have been adapting to those lessons, too.

A stolen session token can authenticate normally. A compromised employee can use applications they’re supposed to use. A North Korean IT worker can enter through the hiring process rather than an exploit chain. An AI agent can take authorized actions and still produce an outcome nobody intended.

That’s why individual events are less meaningful in isolation. Modern detection has to understand behavior over time. What does this identity normally access? Which systems and applications does it use? How does today’s sequence compare with its behavior over the past several months?

The signal may not be one dramatic action. It may be a series of legitimate actions that have never occurred together before. Employees can and should report an unusual request or interaction, but we can’t expect them to recognize a valid login, an approved tool or a sequence of routine actions that only becomes concerning in context. Security programs and detection need to account for that ambiguity. Sometimes the credentials are valid, the tools are approved, and each action looks normal. Behavioral context is what gives security teams a chance to see when those normal-looking pieces stop adding up.“

Katie Paxton-Fear, Staff Security Advocate at Semgrep:

“There’s an awkward reality coming to light in the cybersecurity world: developers are being told to ship faster at the exact moment security teams need more scrutiny over what gets shipped. Most developers want to build securely, but they’re also under real pressure to get code out the door.

AI has poured gasoline on that tension. A developer can now generate a feature, integration or entire block of application logic before a traditional security review would have even started. The model may produce perfectly functional code. It may also choose an insecure function, misunderstand a trust boundary or introduce a vulnerability the developer doesn’t know to look for.

“Write this securely” isn’t enough context for an LLM. Security has to move closer to creation. Code should be checked while it’s being written. AI-generated changes should get the same scrutiny as human-written ones. Findings also need enough context to explain whether a weakness is genuinely exploitable instead of burying developers in another pile of warnings. The goal is to help developers move quickly without making security another obstacle to getting good code out the door.

AI isn’t removing developers from the security process. It’s making good developer guardrails more important. If software creation is going to accelerate, secure development can’t remain the part everyone waits on at the end.”

Nick Tausek, Lead Security Automation Architect at Swimlane:

“The modern SOC doesn’t have an information problem. It has a decision problem.

Analysts already have alerts, threat intelligence, identity data and endpoint telemetry. The slowdown happens when someone has to figure out which signal deserves attention, what context is missing and what should happen next.

The AI SOC needs to earn its keep. Not every incident needs the same level of intelligence. Routine cases can move through deterministic automation. More ambiguous activity may need AI-assisted investigation. A smaller group of complex threats can justify fully agentic analysis. Human judgment stays focused on the decisions where experience matters most.

Cybersecurity Awareness Month is a useful reminder that faster detection alone isn’t enough. Security operations need a way to turn what they know into action without forcing analysts to manually rebuild context every time something goes wrong.”

Piyush Sharrma, co-founder and CEO at Tuskira:

“Picture two vulnerabilities. One carries a critical severity score but sits on an isolated system with strong controls around it. The other looks far less dramatic. It happens to connect an exposed application to a privileged identity and then to production.

Which one gets fixed first?

For years, vulnerability management has made it too easy to answer that question with severity alone. Attackers aren’t working from a sorted CVE list. They’re looking for combinations of weaknesses that get them somewhere useful.

AI-assisted attack-path analysis can trace those combinations across identity, cloud, network and application environments. It can show which weaknesses are actually reachable. It can also identify whether an existing control cuts off the path before an attacker reaches something valuable.

Organizations don’t need more awareness of how many vulnerabilities they have. Most already know the number is uncomfortable. They need a better understanding of which ones can become a breach.”

Maximor Rebrands as Hyphenate After 86x YoY Growth, Expanding Across the Office of the CFO

Posted in Commentary with tags on October 1, 2026 by itnerd

Maximo today announced it has rebranded as Hyphenate. The new name reflects the company’s expansion across the office of the CFO and follows 86x revenue growth over the past 12 months. 

Finance software spent the last decade breaking the office of the CFO into point solutions: one for close, another for billing, another for cash, and another for nearly every workflow after that. Each made its corner of finance easier. Together they left finance teams running a stack of disconnected systems, with people doing the work of connecting them. Finance didn’t get automated. It got subdivided. Hyphenate is built to put it back together.

Why Hyphenate 

Finance already runs on hyphens. Order-to-cash, procure-to-pay and record-to-report are named for the connections between steps, and those connections are where the work gets stuck. A hyphen does two things: it connects, and it modifies. Hyphenate connects finance through one unified context and changes how the work gets done, with agents executing it instead of people carrying it between systems.

Customers are consolidating finance 

Hyphenate now spans five areas of the finance function: order-to-cash, treasury, GL accounting and close, procure-to-pay, and reporting and insights. The average Hyphenate customer now runs six modules, and 40% of customers expand within the first year of their contract, well before a typical renewal conversation.

That behavior reflects how finance actually works. Collections shape cash forecasts, procurement feeds accruals, bank activity drives reconciliation and revenue recognition changes the close. When those workflows sit in separate systems, people are forced to carry context between them; when they run on one platform, each area can inform the others and Hyphenate can take responsibility for more of the function.

A new category 

Hyphenate calls the category autonomous finance, where the distinction is not simply whether software can automate a task, but whether it can own the work through to an outcome.

Traditional automation still depends on people to decide what happens next, resolve exceptions and move information between systems. Hyphenate instead learns how a company actually runs finance, including the controls, historical precedent and judgment that often live in workpapers, spreadsheets and people’s heads, then turns that context into audit-ready agents that execute the work, show what they did and bring a person in when the call genuinely requires judgment.

Because those agents operate across the finance function rather than inside a single point solution, they can carry context from one workflow into the next and get sharper as they see more of the business. A collections issue can flow into cash forecasting, procurement activity can inform accruals, and bank activity can feed reconciliation without a human rebuilding the connection each time.

Hyphenate sits on top of the ERP, banks, payroll and other systems companies already use, which means finance teams can automate increasingly large parts of the function without replacing their underlying stack or going through a migration.

Looking ahead

Operational finance is the first chapter, while the larger opportunity sits upstream in the decisions CFOs make about pricing, margin, investment and capital allocation.

Finance is the dollar translation of the enterprise, because every hiring decision, product decision and procurement decision eventually shows up in revenue, cost, cash or margin. 

Today, companies often spend weeks closing the books, assembling reports and piecing together those relationships after the fact, sometimes with entire analyst teams or outside consultants doing the work.

Hyphenate’s ambition is to collapse that lag. As the underlying finance operation runs continuously, the books can stay reconciled through the month, the numbers can be current on an ordinary Tuesday and reporting can move with the business rather than looking backward after the close.

That changes the economics of the function as much as the workflow. Finance teams can scale without scaling headcount at the same rate, spend less time producing the numbers and use more of their time deciding what the business should do next.

That is the idea behind Hyphenate’s new tagline: Finance that runs itself, so you can sprint ahead.

Use.ai reaches 1 million monthly active users less than a year after launch

Posted in Commentary with tags on October 1, 2026 by itnerd

Every new AI model creates another reason to switch. For users who have already built up months or years of conversations, preferences, files and personal context inside one platform, moving to a better model can also mean starting again.

Use.ai was built around the idea that people should be able to switch between the intelligence they use without changing the interface or losing their context. Less than a year after launch, the all-in-one AI workspace has reached one million monthly active users, giving consumers access to more than 10 leading AI models, including GPT, Claude, Gemini, Grok and DeepSeek, all within a single conversation.

The origin

Use.ai grew out of Co-Founder Ihor Herasymov’s own frustration with jumping between AI platforms. A former M&A and tech investment banker, Herasymov went on to launch seven businesses before building a tech company to 100+ employees and $3 million in annual revenue within two years. After ChatGPT was released, AI quickly became central to how he researched, analyzed and made decisions. He began testing models obsessively and quickly found that each built up context he didn’t want to lose.

The core offering 

Use.ai turns a fragmented AI landscape into one workspace. Instead of juggling separate subscriptions, users can access all of them in a single consumer workspace and switch between them mid-conversation. Research, writing, planning and creation all happen in the same thread, with users able to pull in different models as the task evolves.

At the heart of Use.ai’s offering is its free Answer Engine, built on open-weights models that the company configures and optimizes. More advanced frontier models are available under a paid subscription when a task calls for deeper reasoning or more advanced capabilities. 

The bigger ambition is to make choosing a model disappear entirely. Use.ai is building automatic orchestration that can route each task to the most suitable intelligence, alongside tools that allow the platform to understand more of a user’s world over time. Instead of asking people to follow model launches, study benchmarks or decide which AI belongs to which task, Use.ai wants them to focus on one thing: what they want to get done.

Why model choice matters

As people use AI more, the context trapped inside each platform becomes more valuable and harder to leave behind. Use.ai’s research suggests users already want the freedom to move between models: in a survey of more than 5,000 users, 42% said they switch for better quality or deeper reasoning, while 36.5% switch depending on the task. One user even compared the same investment question across four models, using where they agreed and disagreed to decide what needed more research.

Use.ai is betting that the biggest opportunity is still ahead. In a separate survey of more than 30,000 users, 54% said they were either using AI for the first time or had only tried it a few times. With the company estimating that roughly four billion more people could become regular AI users over the next decade, its aim is to become the place where those users build their AI context from day one.

Looking ahead 

Use.ai’s next phase is about moving from answers to action. The goal is a personal assistant that understands a user’s preferences, routines, schedule and context, then coordinates models and connected apps to get things done.

That could be as simple as saying, “Book me a haircut next week.” With permission to access the user’s calendar, the assistant could know their usual salon, check available appointments against their schedule, make the booking, add it to the calendar and set a reminder.

The same approach could apply to shopping. A user looking for new running shoes could ask Use.ai to research suitable models based on their preferences and training habits, compare prices and availability across retailers and, eventually, complete the purchase once the user confirms.

Over time, that could mean finding and booking appointments, researching products, comparing prices and availability, and completing purchases with confirmation. The underlying idea is that users should be able to describe an objective while Use.ai handles more of the research, coordination and model selection required to complete it.

FBI Tells ShinyHunters To Turn Themselves In

Posted in Commentary with tags , on October 1, 2026 by itnerd

From the “there’s zero chance that this will ever happen” department comes this message from the FBI to the hacker group known as ShinyHunters:

The assistant director of the FBI’s Cyber Division, Brett Leatherman, starred in a video on the FBI’s X feed on Tuesday that warned ShinyHunters members the longer they operate, the more the FBI learns about them.

And:

He also suggested the gang just give up and surrender.

“The longer you stay in this, the more we learn about you,” Leatherman warned. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”

What he’s referring to is this arrest by the group who apparently have pwned the FBI in a massive way. Now I don’t know any of the inner workings of the ShinyHnters group. But it is a pretty safe best that ShinyHunters is laughing right now. Yes, the arrest in Holland may have hurt them. But there’s not a chance that it will stop them. Chances are that they make way too much money hacking. And even a broad takedown of the group is not likely not stop them. So everyone should expect that this group will continue to hack anything and everything that they can see.

AppleTV Not Working For “Some Users”

Posted in Commentary with tags on October 1, 2026 by itnerd

Since yesterday at 4 PM Pacific time, AppleTV is out for “some users”. Proven by this screenshot from this page:

The cynical side of me says “some users” really means “most users.” but a check on my iPhone shows that it is working for me. Still, if it isn’t working for you, know that it is them and not you. In the meantime, it is unusual for Apple to have such a long outage. Thus you have to wonder what the issue is and when it will be fixed.

Classie launches Supervise to track, control and account for enterprise AI agents in real time

Posted in Commentary with tags on October 1, 2026 by itnerd

Classie today unveiled its AI supervision platform, giving CIOs and CISOs a unified view of AI agent activity across the enterprise. With Classie Supervise, now generally available, organizations can monitor sanctioned and unsanctioned agents as they run and enforce policy in real time.

AI agents are moving rapidly into enterprise applications and workflows. Gartner predicts that 40% of enterprise applications will include task-specific AI agents by the end of 2026, up from less than 5% in 2025. Coding agents can already write and deploy code, while knowledge-worker agents connect to business applications and act on behalf of employees, creating a new operating challenge as software begins to make decisions and take actions at runtime.

Governance has not kept up. Gartner reports that only 13% of organizations believe they have the right AI agent governance in place, while warning that growing agent sprawl is increasing IT complexity and exposing enterprises to risks including oversharing and data loss. Gartner recommends that organizations establish centralized agent inventories and maintain ongoing visibility into agent usage and behavior.

Runtime Security and Supervision for Agents Already at Work

Supervise provides runtime security for sanctioned and unsanctioned agents, combining AI posture assessment with inline monitoring and control. Supervise follows agent activity across endpoints, browsers and enterprise compute environments, creating a runtime transcript as the workflow happens. That transcript connects agent and user identity with the context, intent, data accessed and actions taken during the session. 

Because Classie can tie activity and token consumption back to the people, agents and environments involved, organizations gain real-time attributable spend alongside a chain-of-custody record of agent activity.

Organizations define rules through an Open Policy Agent (OPA) policy engine. Lightweight sensors enforce those rules inline. Signals from sensitive-data detectors and Classie’s Supervisor agents allow the platform to stop or redirect an action before it becomes an incident.

Classie can be installed in 15 minutes and begins discovery immediately. The platform is designed to deliver a monitored enterprise posture within five days.

Key capabilities of Classie Supervise include:

  • Real-time intervention. Alert, restrict, reroute or stop an agent action as it happens.
  • Cross-surface visibility. Follow sanctioned and unsanctioned agent activity across endpoints, browsers and corporate compute environments.
  • Real-time attributable spend. Connect AI activity and token consumption to the users, agents, sessions and environments that generated it, giving enterprises visibility into where AI spend originates.
  • Policy enforcement. Apply consistent operating rules through an OPA-based engine and lightweight sensors.
  • Agentic chain of custody. Create a traceable and auditable record connecting agent activity with identity, context and intent, providing tamper-evident provenance for investigation, compliance and governance.
  • Private deployment. Keep enterprise data inside the customer’s environment.

One Platform, from Visibility to Control

The general availability of Supervise follows the release of Classie Discover in April 2026 and Classie Analyze in July 2026. Together, Discover, Analyze and Supervise take organizations from discovering AI activity and understanding its behavior, to applying controls in real time:

  • Discover. Find sanctioned and unsanctioned AI tools, agents and models, then map the people and data connected to them.
  • Analyze. Examine agent behavior and intent, replay interactions and identify activity that needs attention.
  • Supervise. Apply enterprise rules in real time and intervene when an agent moves outside approved boundaries.

The sequence is critical because controls are only reliable when teams first know what is running and understand how it behaves. Classie creates that context before enforcement begins. The platform works across AI vendors, allowing companies to carry one set of operating rules across a heterogeneous environment.

Classie runs its continual learning infrastructure in customers’ private cloud, allowing them to retain control of the data used to adapt supervision models and the resulting model weights. This approach keeps institutional knowledge inside the enterprise and helps automate the development of new guardrails over time.

Customer Use Case Examples

Healthcare company: Classie was deployed in 15 minutes and, within 24 hours, identified the full range of known and previously unknown AI tools being used by employees. The security team could see complete sessions and files being accessed, including previously unseen use of personal AI applications and instances where sensitive information was being shared with AI tools the company had neither licensed nor sanctioned. The findings gave the security team a concrete view of AI activity it could take to leadership and use to inform its governance approach.

High-growth AI company: Classie surfaced every live AI session within five minutes of installation, including several agent harnesses the company had not previously tracked. The company now uses Classie to bring agent transcripts and spend into one place, giving leadership a consolidated view of AI activity as it works to supervise agents and understand how effectively they are being used.

Availability

Classie Supervise and the complete Classie platform are generally available today. Observability pricing starts at $99 per user. For deployment and pricing information, contact Classie at letstalk@classie.ai.

Xopero Software Acquires Vigil Guard

Posted in Commentary with tags on October 1, 2026 by itnerd

Xopero Software today announced the acquisition of Vigil Guard—a cybersecurity company behind a proprietary platform designed to monitor, control, and secure interactions with AI systems. This acquisition marks a pioneering step in combining data resilience with real-time AI threat mitigation, directly addressing an emerging class of risks: prompt injection attacks and sensitive data leakage via autonomous AI agents. 

Security Systems Fail to Keep Pace with AI Development

The rapid, widespread adoption of AI-driven tools and autonomous agents across developer and enterprise environments (such as Jira, Confluence, and code repositories) has exposed the limits of legacy security systems. Risks tied to artificial intelligence are escalating at an unprecedented rate. Corporate emails, internal documentation, and source code—frequently containing sensitive data—are routinely embedded into prompts sent to external large language models (LLMs). Simultaneously, prompt injection threats are mounting, where malicious instructions concealed within text can hijack AI assistants and exfiltrate critical corporate IP (as highlighted by recent vulnerabilities in enterprise AI tools like Atlassian Rovo).

In response, Xopero Software—a global provider of backup and data protection solutions, including DevOps protection via GitProtect.io—is joining forces with Vigil Guard to deliver an end-to-end AI security framework. This strategic expansion moves Xopero’s portfolio beyond traditional backup and Disaster Recovery toward a unified data protection and AI Governance stack.

From Backup to AI Security: A Unified Global Platform

Vigil Guard operates as an AI Detection and Response (AIDR) platform, delivering firewall and EDR-like capabilities specifically engineered for AI interactions. The technology provides instant detection of prompt injection attacks and granular control over AI agents, ensuring they do not breach operational boundaries. It prevents real-time data leaks by automatically masking Personally Identifiable Information (PII), financial data, and credentials before prompts hit external LLMs. Crucially, all verification occurs directly on-premises or within the customer’s private infrastructure, ensuring complete data privacy.

Xopero Software delivers enterprise-grade backup, disaster recovery, and data protection software, scalable hardware appliances, and a dedicated MSP platform. Its GitProtect.io brand is recognized globally as an advanced backup solution for DevOps environments, protecting source code and intellectual property. Nearly 2,000 organizations across more than 60 countries—including Fortune 500 enterprises—rely on Xopero to maintain business continuity.

As part of the transaction, Vigil Guard’s core team will fully integrate into Xopero Software. Operating under the Xopero umbrella, the team will continue advancing its proprietary AIDR engines while leveraging Xopero’s global R&D, operational scale, and international distribution network.

Setting a New Standard for Enterprise Data Protection

The synergy between Xopero and Vigil Guard creates a comprehensive security ecosystem tailored for highly regulated sectors, including financial services, insurance, telecommunications, healthcare, and public administration. The integrated solution enables organizations to safely accelerate AI adoption while ensuring auditability (ISO 27001, SOC 2) and compliance with international regulatory frameworks such as NIS2 and DORA.

The acquisition sends a clear signal to the global market: securing artificial intelligence requires a new generation of tools. Together, Xopero and Vigil Guard will empower organizations worldwide to unlock the full power of AI without compromising on data sovereignty, privacy, or resilience.