Archive for October 8, 2026

New FIRE Report: 475% Increase in Phishing Attacks Using Remote Access Tools

Posted in Commentary with tags on October 8, 2026 by itnerd

Fortra Intelligence and Research Experts (FIRE) have observed a massive 475% increase in phishing attacks leveraging remote management tools in 2026. These campaigns are targeting banking customers with fake support pages that prompt installation of legitimate software like AnyDesk, giving criminals ongoing access to victim devices and accounts. Once installed, threat actors have the ability to monitor activity, steal credentials, deploy additional malware or ransomware, and maintain persistent access long after the initial phishing interaction.

Details here: https://www.fortra.com/blog/increase-credential-phishing-remote-management-tools

Studying or stepping away? Galaxy devices for fall reading week.

Posted in Commentary with tags on October 8, 2026 by itnerd

Fall reading week is on the horizon for most Ontario and Quebec post-secondary schools! With that in mind, I wanted to share how Samsung’s new Galaxy devices can help students maximize their time, whether that means studying or stepping away.

Reading week was about recharging. With a 4:3 aspect ratio when unfolded, the Samsung Galaxy Z Fold8 offers plenty of screen space for gaming, streaming TV shows or curling up with some non-textbook reading.

For the more studious folks, Samsung Galaxy Z Fold8 Ultra offers long-lasting battery support and an 8-inch main display, which opens up to make multi-tab researching and note-taking a breeze.

When there’s a major project to tackle, the new Samsung Galaxy Tab S12 Series offers an expansive Dynamic AMOLED 2X display and Samsung DeX for a more PC-like experience. The included S Pen also makes it easy to annotate readings, sketch out ideas or mark up content.

And since accidents happen on campus and at home, Samsung Care+ offers added protection for 24-month, 12-month and month-to-month terms on eligible Galaxy devices.

For more info, check out samsung.com.

AI Developer Tools Turned Malware Traps

Posted in Commentary with tags on October 8, 2026 by itnerd

CloudSEK researchers have uncovered NEBULA, a malicious npm supply-chain campaign involving seven fake AI SDK packages distributed through four attacker-controlled accounts. The packages deploy a modified Windows remote-access trojan (RAT) capable of stealthy surveillance and remote control.

More concerningly, two malicious packages remained downloadable on npm as of October 8, despite being flagged as malicious.

Key findings:

  • 7 malicious packages, 4 publisher accounts: CloudSEK linked seven packages to a single operator using four sequential disposable npm accounts.
  • Flagged, yet still downloadable: api-nebula and llm-nebula remained installable as of October 8. One package operated for days before receiving a formal malware advisory.
  • Stealthy RAT bypasses conventional DLL-based detection: The modified KNTRAT malware uses direct Windows system calls and an empty Import Address Table, undermining import-based security detection.
  • Invisible remote access and surveillance: Source-code analysis confirms hidden-desktop control, camera and microphone access, remote shell execution, and persistence at every user logon.
  • Convincing AI SDK disguise: The packages contain plausible AI client code, while obfuscated installation scripts secretly deploy the malware. The apparent SDK endpoint does not resolve.
  • 162,464 npm packages scanned: CloudSEK’s YARA analysis of available npm archives from September 25–27 identified only the known campaign packages, with no false positives in the scanned dataset.

An important technical finding: The recovered implant did not beacon during more than 12 minutes of controlled testing, consistent with anti-analysis protections. Its capabilities were established through analysis of the recovered binary and the subsequently published KNTRAT source code. No successful victim compromise was confirmed.

Why this matters: The campaign demonstrates how attackers can exploit the growing demand for AI developer tools to introduce malware through trusted software development workflows, potentially exposing developer workstations and corporate environments.

Full research report, technical analysis and indicators of compromise:

https://www.cloudsek.com/blog/nebula-fake-ai-sdk-npm-packages-windows-rat

Securonix Introduces Advanced Behavioral Analytics to Detect Human and AI-Driven Threats

Posted in Commentary with tags on October 8, 2026 by itnerd

Securonix, Inc., today introduced Securonix Advanced Behavioral Analytics (ABA), a new capability that helps security teams identify at machine speed, activity that is technically permitted but operationally abnormal. ABA features Agent and Entity Behavior Analytics (AEBA), which identifies when an enterprise AI agent uses an unexpected tool, accesses data outside its purpose or changes its operating pattern. It connects those changes with identity, authority, data use, asset sensitivity, timing and threat context, helping analysts understand what changed, why it matters and what to do next.

Compromised accounts, insider activity and AI agents can resemble legitimate behavior when events are reviewed in isolation. Advanced Behavioral Analytics combines AEBA with User and Entity Behavior Analytics (UEBA), which connects unusual login times, rising data access and contact with sensitive assets across systems and time. Together, AEBA and UEBA help analysts investigate developing risk instead of isolated alerts and carry context through detection, investigation, case management and governed response. Policies, approvals and audit records remain visible and enforceable throughout the process.

Detect AI-Accelerated Attacks and Govern the Response

Traditional SIEM platforms were built to collect and correlate human and machine activity before enterprise AI agents became part of the attack surface. Securonix extends behavioral baselines and risk detection across users, identities, assets, applications, cloud environments and AI agents. It correlates signals across systems and time to surface compromised identities, unusual access, privilege misuse, sensitive data exposure and abnormal agent activity. An expanding catalog of AI-threat policies helps teams detect established attack techniques such as AI compresses reconnaissance, exploit development, privilege escalation and data movement.

Sam, the AI SOC Analyst, executes repeatable Tier 1 and Tier 2 work across triage, investigation, evidence collection and case creation. The Agentic Mesh coordinates AI-supported workflows, while Agentic Guardrails keep actions policy-bound, visible and auditable. Analysts review and approve consequential response actions. By completing repeatable work, Sam helps security teams absorb growing alert volumes and expand SOC capacity without requiring linear growth in headcount.

For authorized insider-risk investigations, the Securonix Insider Intent Agent adds contextual and corroborating evidence while preserving competing explanations. Analysts review each signal as part of the broader evidence rather than treating a message, search or behavioral deviation as proof of intent.

New Research Supports Critical Need For AI Governance Pressure

Securonix research found increased AI investment alongside continued questions about governance, trust and human accountability. For The Evolution of Cybersecurity Automation: Towards the AI-Governed SOC, Securonix surveyed 1,000 global cybersecurity professionals during summer 2026.

Survey findings show that cybersecurity teams want automation and AI to advance work inside clear approval boundaries. In the survey, 96% of respondents said cybersecurity automation is important to their organization, 49% said they use AI in behavioral analytics with human approval and 99.6% said their organization had increased its budget for AI in cybersecurity automation during the past year.

Investment has moved past experimentation. Security teams want AI to advance the work inside clear approval boundaries, with evidence they can explain and outcomes they can defend. The full report and methodology will be available in November.

Independent Assurance for Governed AI

Securonix has also achieved ISO/IEC 42001:2023 certification, the world’s first AI management system standard. The certification covers the management system used to govern AI across the Securonix product portfolio, including ThreatQ, and follows an external audit with no major findings. It provides independent validation of accountability, AI risk management and human oversight and can support customer due diligence across security, procurement and AI governance reviews. The certificate is available through the Securonix Trust Center.

Availability

Securonix Advanced Behavioral Analytics is available now.

 

Research proves Volvo cars provide equal protection for women and men

Posted in Commentary with tags on October 8, 2026 by itnerd

The research, conducted by Volvo Cars Safety Centre, challenges the long-standing assumption that cars are inherently not equally safe for women and men. It demonstrates that equal protection can be achieved through data-driven safety development grounded in real-world crash research.

Comparing Volvo car models from 2010–2019 with models from 1970–1979, overall injury risk for drivers has decreased by 79 per cent. For women, the reduction is even greater, at 88 per cent, bringing injury risk to the same level as that of men.

The results also show substantial advances in occupant protection across all seating positions. Restrained rear-seat occupants in Volvo cars benefit from protection levels comparable to, and in some cases exceeding, those of front-seat occupants.

This underscores the effectiveness of decades of rear-seat safety innovation in Volvo cars, despite the lack of stringent regulatory requirements and standardised testing over the years.

The approach behind equal safety for everyone
Since 1970, Volvo Cars has collected data from over 50,000 real-world crashes involving over 80,000 occupants. Through its Circle of Life safety development approach, these insights are translated into safety requirements, testing, vehicle development, verification and production. The result is a continuous cycle of learning that helps drive innovations and improve protection for everyone.

This approach has also laid the foundation for the pioneering Volvo Cars Safety Standard. Volvo Cars sets its own benchmark for real-world safety, going above and beyond what is required in regulations or safety ratings. This includes developing and testing cars for a wider range of real-world crash scenarios across all seating positions.

And because real world crashes don’t involve standardized crash test dummies, Volvo Cars’ research involves considering a diverse range of occupant characteristics, including gender, height, body shape and weight. As a result, the company’s safety innovations are designed with the same diversity in mind.

For decades, Volvo Cars has openly shared its safety research to help raise safety standards across the industry. As part of the Equal Vehicles for All (E.V.A.) Initiative, launched in 2019, more than 50 years of safety research is freely accessible in a digital library – enabling other carmakers, researchers and policymakers to build on Volvo Cars’ unique real-world safety insights.

About the study
The study was led by Lotta Jakobsson, Ph.D. Eng. and Thomas Broberg, Ph.Lic. Eng. at Volvo Cars Safety Centre. It was published as part of the Enhance Safety of Vehicle (ESV) International Conference 2026.

Drawing on more than 50 years of real-world crash data, it is one of the most extensive long-term occupant safety studies in the automotive industry. The study analyses a broad range of real-world crash scenarios, including frontal, side and rear-end impacts, run-off-road accidents, rollovers, side-swipe collisions, large animal impacts and multi-collision crashes. It focuses on belted occupants aged 13 and older and examines injuries with moderate potential to threaten life, such as fractures and concussions, while excluding minor injuries such as bruises and pain.

The full report is available here.