Author Archive

Triad Nexus Operations Infrastructure Reborn as Threat Actor Distances Activity from FUNNULL CDN

Posted in Commentary with tags on April 14, 2026 by itnerd

Silent Push has released new research revealing that following US Treasury sanctions in 2025, Triad Nexus has matured its operational security, employing geographic fencing to blind US investigators while simultaneously laundering its infrastructure through account muling and a rotating network of “clean” front companies. 

Triad Nexus is responsible for $200M+ in reported losses, driven largely by sophisticated “pig-butchering” and virtual currency scams. Individual victim losses average $150K, highlighting the high conversion nature of its operations. Despite federal sanctions in 2025, the group has reinstated its global fraud engine, shifting its focus toward emerging markets while maintaining a persistent threat to Western enterprise assets. 

Triad Nexus continues to pose a direct risk to corporate brand integrity and customer trust. The group manages an industrialized catalog of impersonation assets targeting: 

Banking and Fintech: Payment portals for more than 25 global institutions (including Wells Fargo and Bank of America) used for large-scale credential harvesting and “pig-butchering” scams. 

Luxury Retail: High-fidelity clones of brands such as Tiffany and Cartier to intercept high-value consumer transactions. 

Global Logistics: Exploitation of services, including the Vietnam Post, to facilitate regional personally identifiable information (PII) theft. 

You can read the research here: https://www.silentpush.com/blog/triad-nexus-funnull-2026

TrustCloud Launches Native ServiceNow Application to Deliver Enterprise-grade Continuous Control Monitoring for GRC and IRM customers

Posted in Commentary with tags on April 14, 2026 by itnerd

TrustCloud today announced the TrustCloud Continuous Control Monitoring for the ServiceNow Store — the first AI native continuous control monitoring engine built and distributed natively through the ServiceNow Store. The application syncs validated, deterministic control signals directly with ServiceNow IRM (Integrated Risk Management), SecOps (Security Operations), Configuration Management Database (CMDB), and AI Control Tower, closing the signal quality gap that has long limited the ability for enterprise security teams to correlate security operations data with risk and GRC outcomes.

This marks a significant expansion of the strategic relationship between TrustCloud and ServiceNow to accelerate AI-native GRC transformation for CISOs, post ServiceNow’s strategic investment in TrustCloud in 2025.

Proven to Deliver Accurate and Continuous Technology Risk Governance for Enterprise CISOs
The TrustCloud Continuous Control Monitoring Application for ServiceNow is already live, bringing value to CISOs across multiple Global 2000 enterprises. A top 10 pharmaceutical customer increased application assessment throughput from 20 apps per year to 200–300 apps per year with the same team and budget. A  Fortune-500 technology software provider eliminated sampling-based technology risk assessments with 100% risk surface monitoring, replacing low-confidence risk workflows with high-confidence risk planning and reporting. .

The Problem: Point-in-Time Manual GRC Workflows Cannot Keep Pace With Modern Risk
Enterprise CISOs that use ServiceNow as their system of record for Enterprise Risk Management (ERM) and IRM came to TrustCloud looking to solve 4 problems that existed in their ServiceNow IRM workflows. 

  1. Difficult to handle Enterprise Scale: CISOs could not analyze millions of records from 100s of security and IT tools for control assurance validation,
  2. Long timelines to handle Complexity: GRC teams need to validate custom technical, documentation, and process controls quickly, and assess many GRC objectives.
  3. Manual Workflows: Users need to replace 10s of 1000s of manual workflows with accurate agents that work 24×7,
  4. Low-confidence output: CISOs want confidence in the risk posture analysis of their IT and business environment. CISOs do not want their security and risk programs to run on snapshots. Point-in-time assessments and attestation-based dashboards were designed for a world where risk moved slowly enough to be captured annually. That world is gone. AI adoption, expanding attack surfaces, and shrinking security teams have made the status quo not just inefficient, but indefensible. ServiceNow IRM is the system of workflows for 60% of the Fortune 500 but the data and signals used for risk assessments has remained subjective, sampled, and slow. CISOs have realized that AI on bad data — is bad AI.  They need a better way

The Solution: A Continuous Assurance Engine for ServiceNow IRM
The TrustCloud Continuous Control Monitoring Application for ServiceNow closes four structural gaps for enterprise CISOs.

  1. Hybrid Data Fabric to sync terabyte and petabyte level enterprise data:  TrustCloud replaces periodic sampling — a statistical slice of the control landscape that leaves material risk unobservable between cycles, with 100% landscape-based continuous testing across applications, infrastructure, vendors, and documents at enterprise scale.
  2. AI-native agents to deliver fast Time-To-Value (TTV):  Where traditional IRM implementations require 12–24 months and millions in spend before producing meaningful signal, the TrustCloud Continuous Control Monitoring Application deploys natively into existing ServiceNow environments. Findings create incidents and tasks inside workflows teams already own, without re-platforming or lengthy SI engagements.
  3. Multi-faceted control testing: The Continuous Control Monitoring Engine analyzes structured and unstructured telemetry from cloud and on-premises environments at millions of records of scale — enabling automated testing of technical, documentation, and process controls.
  4. High-confidence business impact reporting: TrustCloud’s Control Graph connects every finding from control testing to GRC artifacts, business exposure, and prioritized remediation paths. Trusty, TrustCloud’s AI agent, executes deterministic checks, validates evidence with citations, and generates auditable remediation tasks — with no hallucinations.

Availability
The TrustCloud Continuous Control Monitoring Application for ServiceNow is available now through the ServiceNow Store. The integration supports ServiceNow IRM, SecOps, CMDB, and AI Control Tower.

CData on Claude Managed Agents: Anthropic’s Bet on the Meta-Harness

Posted in Commentary with tags on April 13, 2026 by itnerd

In a new blog post, Amit Naik, VP of Artificial Intelligence at CData, explores Anthropic’s “Claude Managed Agents” and what the concept of a “meta-harness” reveals about the next phase of enterprise AI. While much of the market focus remains on model performance, Naik argues that the real shift is happening at the infrastructure layer that enables agents to operate reliably at scale.

The post examines how managed agent platforms abstract the complexity of orchestration, memory, security, and tool integration, allowing organizations to accelerate development without building everything in-house. At the same time, Naik highlights key trade-offs, including potential vendor lock-in and reduced control over data and agent behavior.

In Naik’s opinion, managed agent infrastructure is a critical battleground for enterprise AI, where success will depend not just on model quality, but on how effectively organizations can operationalize and scale intelligent agents.

Read the full blog here: https://www.cdata.com/blog/claude-managed-agents-anthropic-meta-harness

SOCRadar Puts Out A Research Report On The Stealer Ecosystem

Posted in Commentary with tags on April 13, 2026 by itnerd

The stealer ecosystem has matured into a professionalized criminal economy that most organizations are simply not monitoring closely enough.

While the industry fixates on household names like Lumma and RedLine, a growing class of lesser-known, actively deployed stealers, Void, a C++ infostealer that emerged in late 2025, Datura, Misericorde, Saturn, and others, are quietly collecting credentials, session cookies, and crypto wallet data from victims worldwide, feeding logs into underground markets that fuel ransomware, account takeovers, and business email compromise.

In a just-released research report The Unknown Stealers: From Dark Web to Log Markets, SOCRadar researchers identify up to six simultaneous active campaigns running on the Void infrastructure. Each campaign used slightly modified binaries, a natural artifact of different affiliates configuring their own builds, but all shared the same underlying C2 relay architecture and Steam-based resolution mechanism. Some Steam accounts used in earlier campaigns had already been deleted, indicating active infrastructure rotation. Void is a textbook example of how low-profile, under monitored stealers can operate at scale before anyone is paying attention.

You can read the research report here: https://socradar.io/resources/whitepapers/stealer-dark-web-log-markets

DataBee Posts Blog On Context Aware AI For AI Governance

Posted in Commentary with tags on April 13, 2026 by itnerd

DataBee has a new blog post on context-aware AI for AI Governance that aims to help leaders to deliver defensible, audit-ready decisions in real time across expanding attack surfaces and rapidly evolving regulatory landscapes. 

You can read the blog post here: Context-Aware AI for AI Governance, Threat Detection and Defensible Compliance Documentation

OpenText and S3NS Partner to Deliver European Sovereign Cloud Solutions with Google Cloud

Posted in Commentary with tags on April 13, 2026 by itnerd

OpenText today announced a strategic partnership with S3NS, an alliance between Thales, a French leader in cybersecurity in Europe, and Google Cloud, to bring European organizations a trusted cloud platform based on Google Cloud technology, that meets the highest security and compliance criteria in France to offer strict data residency, regulatory compliance, and operational controls. 

The partnership delivers a hybrid trusted cloud architecture for Europe out of France, enabling organizations to keep their most sensitive data workloads within a locally governed environment, while securely leveraging hyperscaler cloud services for non‑sensitive workloads, innovation, and scale. 

This approach is designed to preserve full interoperability with global cloud platforms, ensuring French and European organizations can continue to benefit from hyperscaler innovation while meeting local regulatory obligations. 

The OpenText and S3NS trusted cloud capabilities meet stringent regulatory and operational requirements, leveraging OpenText’s operational and security experience from delivering government-grade cloud environments in multiple jurisdictions including FedRAMP-authorized, IRAP-assessed, and Protected B-aligned deployments and based on S3NS SecNumCloud qualified Platform, PREMI3NS, to create a hybrid trusted cloud offering designed specifically for France’s regulatory and jurisdictional requirements. This enables organizations in highly regulated industries, such as those managing sensitive citizen, patient, or financial data, to adopt cloud services while maintaining full compliance and control. 

With additional solutions to be evaluated for inclusion over time, the initial hybrid sovereign offering will include:

  • Dedicated Private Cloud: OpenText Content Management and Documentum Content Management for highly sensitive data. 
  • Sovereign SaaS: OpenText Core Archive for SAP Solutions offered as a multi-tenant service with European data residency. 
  • Regulatory Compliance: Supports GDPR, SecNum 3.2, and other European data sovereignty requirements. 

OpenText Enterprise Data and AI Solutions to be Available on AWS European Sovereign Cloud

Posted in Commentary with tags on April 13, 2026 by itnerd

OpenText announced today that it will make a number of its world-leading enterprise data and AI solutions available on the AWS European Sovereign Cloud, a new independent cloud for Europe. 

By making its hybrid sovereign cloud offering available via the AWS European Sovereign Cloud, Canadian-based OpenText expands its ability to provide a hybrid sovereign cloud in Europe, giving customers the flexibility to leverage the cloud capabilities of AWS while keeping sensitive data and governance firmly anchored within European boundaries. 

OpenText Content Management, OpenText Documentum Content Management, OpenText Core Application Security and OpenText Core Service Management will be available on the AWS European Sovereign Cloud, further supporting OpenText’s growing European client base. OpenText’s solutions deliver structured, secure content management, making data ready for AI-powered analytics and automation that accelerate data-driven decision-making; while providing clients with the same security, availability, and performance they expect from AWS. This enables OpenText customers to meet stringent operational autonomy and data residency requirements within the European Union (EU). 

The AWS European Sovereign Cloud is a fully featured, independently operated sovereign cloud backed by strong technical controls, sovereign assurances, and legal protections designed to meet the needs of European governments and enterprises. The AWS European Sovereign Cloud infrastructure is entirely located within the EU and operates independently from existing Regions. Customers using the AWS European Sovereign Cloud will benefit from the full power of AWS including the same service portfolio, security, availability, performance, familiar architecture, APIs, and innovations such as the AWS Nitro System. 

Customers can begin planning their transition to the AWS European Sovereign Cloud today. 

Flashpoint Discusses Tax Refund Fraud in 2026

Posted in Commentary with tags on April 10, 2026 by itnerd

There’s a new blog post from Flashpoint that covers tax refund fraud in 2026 and how threat actors are weaponizing identity data, verification systems, and cash-out channels at scale. The piece breaks down how fraudsters move from sourcing “fullz” and clients to bypassing government identity verification, inflating refunds, and rapidly converting payouts into cash or cryptocurrency while using highly structured, repeatable workflows.

In the piece, the Flashpoint Intel Team explains how tax refund fraud has evolved into a mature, community-driven fraud ecosystem, where identity theft, social engineering, and verification bypass techniques are continuously refined and shared across Telegram channels, dark web forums, and illicit marketplaces. They walk through the end-to-end fraud lifecycle from identity acquisition and return verification bypass to cash-out via banking apps, prepaid cards, and crypto exchanges, and highlight what these patterns mean for security and fraud teams trying to move from reactive detection to proactive disruption.

Additional key insights from the 2026 tax refund fraud landscape include:

  • Why high-quality identity data (“fullz”) and recruited “clients” are now foundational to refund fraud success, and how that raises risk across identity, account takeover, and broader financial crime.
  • How threat actors systematically bypass identity and tax return verification to leverage verified identity accounts, prior-year AGI, IP PINs, and scripted interactions with the IRS and government offices to make fraudulent filings look legitimate.
  • How fraud tutorials, Telegram communities, and dark web forums accelerate the spread of new methods, including false wage submissions that pre-populate tax records before filing, and increasingly streamlined cash-out workflows that move funds quickly into crypto and digital banking platforms.

The full post can be found at: https://flashpoint.io/blog/tax-refund-fraud-in-2026-how-threat-actors-exploit-identity-verification-and-cash-out-channels/.

Samsung Canada Launches ‘Samsung True North Tunes’ 

Posted in Commentary with tags on April 9, 2026 by itnerd

Samsung Electronics Canada has launched Samsung True North Tunes, an artist-first contest that gives emerging Canadian musicians a new opportunity to share their original music and reach listeners across the country. 

Through the contest, selected artists will be featured on the Samsung True North Tunes website and gain access to opportunities — from curated playlists, exclusive experiences and swag, to mentorship and broader exposure for the top selected artists. Submissions are open to artists of all genres, with a focus on originality and creative expression. 

Samsung True North Tunes is developed in partnership with Collective Arts, bringing together cultural and media voices to amplify emerging talent and connect artists with fans across Canada. 

Open Call for Emerging Canadian Artists 

Starting March 20, emerging artists across Canada can submit their original music through the True North Tunes website: truenorthtunesmusic.ca. Submissions are open to artists of all genres and backgrounds, and are free to enter, with a focus on originality and creative expression. 

The program will take place across three stages. A panel of judges will first select the Top 100 artists, followed by two rounds of public voting to determine the Top 20 and final Top 3. As artists advance, they’ll gain access to mentorship, studio recording time, and live performance opportunities, including a series of live sessions and events curated and hosted by Collective Arts, alongside Samsung technology and additional prizing. For full program details and timing, please visit our website. 

Program timeline: 

  • March 20 – May 15: Artist submissions open 
  • June 15: Top 100 announced, curated by judges 
  • July 14: Top 20 announced following public voting 
  • August 11: Top 3 announced following public voting 

ServiceNow moves beyond the sidecar AI era

Posted in Commentary with tags on April 9, 2026 by itnerd

ServiceNow today announced that its entire product portfolio will be AI-enabled. Every ServiceNow product now includes AI, data connectivity, workflow execution, security, and governance built-in. This shift enables organizations to accelerate their AI ambitions and help ensure they get the most value from AI by bringing together the critical components required for enterprise-scale delivery: a conversational front door (ServiceNow EmployeeWorks), connected data for cross-enterprise context (Workflow Data Fabric), visibility and governance (AI Control Tower), and autonomous workflows that can move from assisting people to acting on their behalf. ServiceNow also unveiled Context Engine, an enterprise context solution that connects relationships, policy, and decision history behind every AI agent decision, and new ServiceNow Build Agent skills that open the platform so that developers can build from any tool they already use and deploy directly to ServiceNow.

The enterprise software landscape has a fragmentation problem. The average enterprise runs hundreds of applications, each with its own data model, security perimeter, and governance logic. Most providers are making it worse, bolting intelligence onto disconnected systems as a sidecar that can’t execute across the enterprise with real context or accountability. ServiceNow is moving beyond a patchwork of AI add-ons towards a unified platform, combining intelligence that understands context with workflows that can act on it.

Context Engine: enterprise context for every AI decision

Every AI agent is only as good as the context it operates in. Context Engine gives ServiceNow AI and workflows the context to sense what’s happening across the enterprise, decide the right course of action, act with precision, and govern every outcome accountably. For example, it knows which asset is tied to a regulated process, which approval chain applies to a given cost threshold, and which vendor history should inform how a request is handled.

With 85 billion workflows and seven trillion transactions, ServiceNow is uniquely positioned to ground LLMs in an organization’s specific strategy and make better decisions with AI. Context Engine compounds intelligence with every human and agent decision made, growing smarter about how a business works, not just about language. Built on ServiceNow’s Service Graph, Knowledge Graph, and data inventory, Context Engine draws from a breadth of enterprise signals, including identity relationships, asset dependencies, business intelligence, and data lineage that AI queries in real time.

ServiceNow SDK and Build Agent skills open ServiceNow to every developer, from any tool

On April 15, developers will be able to build with any tool they already use — including Antigravity, Claude Code, Cursor, OpenAI Codex, Windsurf, and others — and deploy directly to the ServiceNow AI Platform. The ServiceNow SDK and new Build Agent skills work across every major AI development environment, so developers stay in their preferred integrated development environment (IDE) while citizen developers describe a workflow in plain language. The result is a working app on ServiceNow in minutes, based on testing scenarios.

For teams developing on top of the company’s pre-built apps, ServiceNow Studio with embedded Build Agent delivers the deepest AI-native development experience on one platform. Fully instance-connected, it understands live data models, active scopes, table relationships, and business rules in real time, enabling it to surface the right fields, dependencies, and extension points as developers build.

Every custom app and AI agent is governed by AI Control Tower and App Engine Management Center, and inherits the same identity framework. To get started, customers will receive 100 free Build Agent calls, and personal developer instances will include 25 free Build Agent calls.

AI, data, security, and governance now in every product offering for customers of any size

ServiceNow is releasing a new tiered offer model that spans AI assistance, agentic automation, and fully autonomous operations across the entire portfolio. For midsize companies that need enterprise-grade service management without months-long deployment, ServiceNow is introducing Enterprise Service Management (ESM) Foundation. ESM Foundation brings together IT, HR, legal, finance, procurement, and workplace services onto the ServiceNow AI Platform, which can be live in weeks. With AI-driven setup, AI assistance for employees, and automation to improve service team performance, organizations get fast ROI on a scalable foundation that grows with them.

Every ServiceNow customer now starts with a complete AI package — no separate purchase, no procurement project, and no integration required. From AI-powered automation capabilities to more agentic AI features, customers can choose the level that’s right for them. ServiceNow is model agnostic by design, giving customers the flexibility to leverage their preferred provider. Intelligence will keep getting cheaper. Trusted execution will keep getting more valuable.

Availability

ESM Foundation and the new packaging model are now available for all customers. Build Agent skills will be available to developers on April 15. Context Engine is available for preview with select customers, and full availability details will be shared at a later date.