Archive for the Commentary Category

3X Surge in AI Agent Deployments Since 2025 Says Salesforce

Posted in Commentary with tags on August 11, 2026 by itnerd

Salesforce has released its 2026 Agentic Enterprise Index, which analyzes global AI usage data to uncover how businesses are deploying, using, and getting value out of AI agents. 

The index shows enterprise adoption is scaling up, with the average number of AI agents activated per enterprise nearly tripling year-over-year. Based on data from 734 million completed AI tasks, businesses are shifting from basic AI chatbots to complex, multi-step automated workflows that deliver tangible ROI.

The findings come as 27.8% of large Canadian enterprises are actively adopting AI, according to Statistics Canada, raising the question of what effective agent deployment looks like in practice. Salesforce’s data provides key insights for Canadian organizations looking to move from AI experimentation to measurable business impact.

Insights from the report include:

  • Agent Versatility: The unique skill set of an average agent grew from 2 distinct business actions to 6 by the end of 2025, turning agents into cross-functional partners for enterprises.
  • Faster Time-to-Value: Average agent deployment time dropped 53% to just 2 days, showing companies are moving past long pilot phases.
  • Industry Rollouts: Consumer sectors have scaled AI agents quickly during demand spikes (during peak shopping season, the average retail agent drove 4x the sales for companies compared to those without one and was able to act on 9 skills), while highly regulated industries, such as Financial Services, led in agent sophistication.

You can read the report here: https://www.salesforce.com/news/stories/agentic-enterprise-index-insights-2026/

Gunra ransomware group bypassing MFA and exfiltrating enterprise data via Fortinet flaws

Posted in Commentary with tags , , on August 11, 2026 by itnerd

The FBI, CISA, and South Korea’s National Police Agency issued a joint advisory Monday on Gunra ransomware, also known as Golden Community. The RaaS operation exploits two Fortinet firewall vulnerabilities, CVE-2024-55591 and CVE-2025-24472, for initial access, then runs double extortion against healthcare, financial services, and government targets worldwide.

Roman Sannikov, Global Research Coordinator, iCOUNTER

“Gunra’s exfiltration playbook is what should worry Microsoft 365 shops specifically. The advisory documents a custom executable pulling data straight out of OneDrive and SharePoint, then in at least one case moving the archived data out to Mega in volumes running into the tens of terabytes. Getting into position to do that took real infrastructure: the actors moved laterally using Impacket tools over SMB and hijacked active sessions by stealing VPN cookies, all before touching a single file. Moving that much data without tripping alerts takes real operational patience, and it fits a pattern: CISA notes the actors deliberately operate between 10pm and 6am to stay under the radar of anyone watching logs during business hours. Once they do start encrypting, it’s fast, ChaCha20 paired with RSA-4096 across a multi-threaded engine hitting multiple files at once. If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

These advisories are not made lightly. So organizations need to pay attention. Especially Microsoft 365 shops to avoid being pwned by these threat actors.

TD becomes the first bank in Canada to digitize direct deposit switching

Posted in Commentary with tags on August 11, 2026 by itnerd

TD has launched a new mobile-first experience that helps clients securely set up or switch payroll direct deposit within the TD app. With most employers, the process can be completed in about a minute, reducing paperwork and helping clients manage an everyday banking task more simply and conveniently.

The launch reflects TD’s continued focus on simplifying everyday banking by digitizing routine tasks, while delivering that convenience within the trusted, full-service banking relationship clients expect. The feature helps reduce administrative steps traditionally associated with updating payroll information, including paper forms and employer coordination.

Key takeaways:

  • Switching direct deposit is now faster and simpler: Clients can set up or switch payroll direct deposit online in about a minute, with most employers, using a guided experience in the TD mobile app.
  • A first among Canada’s Financial Institutions: TD is the first financial institution in Canada to offer a fully integrated in-app payroll direct deposit switching experience.
  • No paperwork and manual coordination: The digital process eliminates forms and reduces the need for contacting employers or payroll providers directly.
  • A more secure way to manage payroll information: The in-app experience helps reduce the need to share sensitive banking information through paper forms or email, helping lower the risk of manual data-entry errors and unnecessary exposure.
  • Making it easier for clients to establish TD as their everyday banking account: The secure, digital setup simplifies the direct deposit onboarding process, helping clients move their everyday banking with confidence, not just with speed.

For many Canadians, updating payroll direct deposit has historically involved paperwork and coordination with employers or payroll providers. TD’s new in-app experience helps simplify the process, giving clients a faster and more convenient way to update where their pay is deposited.

With the new in-app experience, clients can:

  • Set up or switch payroll direct deposit in about a minute, with most employers
  • Avoid printing, scanning or emailing sensitive financial documents
  • Reduce the risk of manual data-entry errors
  • Keep banking information secure within the TD mobile app

By simplifying a traditionally manual process, TD is helping clients spend less time on administrative tasks and more time focused on what matters most, backed by the scale, security and advice of one of Canada’s leading banks.

A first among Canada’s Financial Institutions

Built in collaboration with Atomic, a U.S.-based fintech company powering embedded banking infrastructure, including direct deposit switching, bill and subscription management and payment switching, TD is the first bank in Canada to offer a fully integrated, in-app payroll direct deposit switching experience. TD holds exclusive Canadian rights to this capability through the end of 2026, reinforcing the Bank’s focus on delivering innovative digital experiences that help meet client needs.

The launch also supports TD’s “digital first, human always” approach, combining modern digital convenience with the security, trust, advice and support that clients expect from a full-service bank.

In collaboration with Atomic, TD is making a once-manual banking task faster, simpler and more secure for Canadian clients on the mobile app, delivering an innovative digital experience that puts clients at the centre.

Q&A: Digital Direct Deposit in Canada

What is digital direct deposit switching?
Digital direct deposit switching allows TD clients to securely update where their paycheque is deposited without completing paper forms or contacting their employer directly. Clients can choose which eligible TD account, including chequing, savings or unsecured line of credit, they want their direct deposit moved to, and with most employers, the process can be completed in about a minute, within TD’s secure mobile app.

If a client’s employer or payroll provider is not currently supported, clients are guided to a pre-filled manual form to complete the process.

How do TD clients switch direct deposit in Canada?
With TD Digital Direct Deposit, clients can follow a guided process in the TD mobile app to securely update their payroll information without needing to locate account details or submit forms. With most employers, the process can be completed in about a minute within the TD app.

How long does it take to switch using TD Digital Direct Deposit?
Digital Direct Deposit is designed to be completed in about a minute, with most employers, within the TD app, allowing clients to quickly update where their pay is deposited.

Is it safe to use TD Digital Direct Deposit to change direct deposit online?
TD Digital Direct Deposit helps reduce the need to share sensitive banking information through email or paper forms by keeping the process within TD’s secure digital banking environment, lowering the risk of errors and exposure.

Do I need to contact my employer to change direct deposit when using TD Digital Direct Deposit ?
With most employers, TD Digital Direct Deposit reduces the need for manual coordination by providing a guided in-app experience. If an employer or payroll provider is not currently supported, clients are directed to complete the process using a manual form.

LexisNexis pulls data services offline after unusual activity on a third-party vendor’s servers

Posted in Commentary with tags on August 11, 2026 by itnerd

LexisNexis has taken three Nexis products, Diligence, Metabase API, and Newsdesk, offline after detecting unusual activity on a third-party vendor’s servers. No data exposure has been confirmed, and the company says it isn’t connected to last week’s separate Metabase Cloud SQL injection zero-day that hit Framework and Tally.

More details here: LexisNexis shuts down services after suspicious activity on servers

The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online.

“Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week.

“To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems.”

Amit Shuster, VP Product & Engineering, Vetric had this to say:

“An outage like this doesn’t announce itself as a security story. It shows up as teams that suddenly can’t see what they could see yesterday, even though nothing in their own environment changed. For investigators and trust and safety teams working time-sensitive cases, lost visibility means a stalled case, and threats don’t pause while service is restored. That’s why the organizations on the front lines are getting deliberate about resilience, working with partners alongside their existing sources, so one provider’s bad week never becomes their blind spot.”

This is a security story. And I hope that LexisNexis is honest about this so that we can all learn from it not to mention find out what happened and how it was addressed. Not to mention that the vendors that you work with are your weakest point and every organization needs to address this ASAP.

Encrypted Reasoning Cracked Across Anthropic, OpenAI & Google

Posted in Commentary with tags , , on August 11, 2026 by itnerd

Researchers from MATS Research, the Max Planck Institute for Intelligent Systems, the ELLIS Institute Tübingen, Snyk, and the University of Tübingen have found a way to crack encrypted reasoning logs across all three major AI providers.

The researchers found that encrypted reasoning blocks can be passed between compatible models within the same provider’s ecosystem. By feeding an encrypted reasoning block generated by a more capable, heavily safeguarded model into a weaker, less restricted one, they were able to force the weaker model to decode and reproduce the previously hidden reasoning in plain text, without ever directly attacking the more capable model.


“By porting a valid authenticated encrypted reasoning blob across this security gap, an attacker circumvents the frontier model’s alignment entirely, using the weaker, more compliant model as an unwitting decryption oracle,” researchers explain. 

The root cause is an architectural design choice: all three providers appear to use a single global encryption key shared across their entire model family. This means encrypted reasoning blocks are not tied to the session, account, or model that created them. A reasoning block generated by one user, on one model, in one session, can be picked up and decoded by a completely different user using a different model in a different session entirely.

This vulnerability was present in the latest AI models from Anthropic, OpenAI, and Google.

This vulnerability was tested in the real world as well. Researchers scraped 315,320 encrypted reasoning blocks from publicly available repositories and decrypted:

  • 367 Personally Identifiable Information (PII) artifacts
  • 182 credentials
  • 62 API keys
  • 33 passwords
  • 30 personal email addresses

They also demonstrate cases where information hidden in the model’s reasoning was significantly more sensitive than what appeared in the model’s final, visible response, including potentially harmful information that the model had refused to provide in its final answer.

You can find the full research paper here: https://arxiv.org/pdf/2608.09867

Voldemaras Kadys (https://www.linkedin.com/in/voldemaras-kadys/), the Head of Security at Cybernews, with over 15 years of experience in cybersecurity and IT infrastructure, comments:

“The most interesting part of this research is that the researchers didn’t need to ‘break’ the encryption in the traditional sense. They found that encrypted reasoning traces could be passed between compatible models within the same provider’s ecosystem, effectively turning a weaker model into a master decryption key.

The main lesson here for users and organizations is this: if you’re using AI with sensitive inputs or outputs, treat chat logs as sensitive data, even when they look like meaningless encrypted text.

Those encrypted blocks can contain credentials, personal information, and other sensitive data that isn’t visible to the person sharing the log.

As this research demonstrates, encryption doesn’t necessarily make that information inaccessible, and the barrier to decrypt it may be much lower than users expect.”

This further dents the reputation of AI. Thus it might be worth a look at your use of AI to see if anything sensitive is making its way into the public domain.

SOCRadar Named No. 542 on the 2026 Inc. 5000 List, the Most Prestigious Ranking of America’s Fastest-Growing Private Companies 

Posted in Commentary with tags on August 11, 2026 by itnerd

SOCRadar, a global leader in extended threat intelligence and cybersecurity, today announced it has been ranked No. 542 on the 2026 Inc. 5000 list, the annual list of the fastest-growing private companies in America. The list is the most prestigious ranking of the nation’s most successful independent and entrepreneurial businesses, recognizing companies that have achieved remarkable growth while driving innovation, creating jobs, and shaping the future of the economy. Past honorees include companies such as Microsoft, Meta, Chobani, Oracle, and Patagonia. 

This year’s Inc. 5000 recognizes a new class of companies redefining what growth looks like. From AI and advanced manufacturing to healthcare, consumer products, and professional services, these businesses are expanding their impact, creating jobs and proving that entrepreneurial ambition continues to fuel the U.S. economy. Among the 5,000 companies on the list, the median three-year revenue growth rate was 130%, and those companies have collectively added more than 627,208 jobs to the U.S. economy over the past three years. 

For the full Inc. 5000 list, honoree company profiles, and a searchable database by industry and location, please visit: www.inc.com/inc5000

Inc. will celebrate the honorees at the 2026 Inc. 5000 Conference & Gala, taking place October 14–16 in Dallas, Texas and the top 500 will be listed in the Fall issue of Inc. Magazine. Tickets are on sale now.

Inc. 5000 List Methodology 

Companies on the 2026 Inc. 5000 are ranked according to percentage revenue growth from 2022 to 2025. To qualify, companies must have been founded and generating revenue by March 31, 2022. They must be U.S.-based, privately held, for-profit, and independent—not subsidiaries or divisions of other companies—as of December 31, 2025. (Since then, some on the list may have gone public or been acquired.) The minimum revenue required for 2022 is $100,000; the minimum for 2025 is $2 million. As always, Inc. reserves the right to decline applicants for subjective reasons. 

Canadian SMEs Head Into Fall Optimistic But More Disciplined About Hiring and AI Investment, New Employment Hero Survey Finds

Posted in Commentary with tags on August 11, 2026 by itnerd

As Canadian businesses head into the second half of the year amid ongoing economic uncertainty, new research from Employment Hero, the global AI-powered employment platform, suggests SMEs are entering Q4 with cautious optimism – continuing to invest in talent and AI while taking a more disciplined approach to growth, hiring and productivity.  

The inaugural Employment Hero SME Pulse, a quarterly survey of 600 Canadian senior business leaders, found 58% of SMEs are optimistic about their business outlook over the next six months, compared to just 18% who are pessimistic. At the same time, businesses are taking a measured approach to growth, balancing hiring and investment decisions against continued economic uncertainty.  

Hiring remains a priority, but employers are becoming increasingly selective. More than one-third (34%) of SMEs expect to expand hiring over the next six months, while another 32% say they plan to hire selectively, suggesting businesses continue to invest in talent while taking a more deliberate approach to workforce growth.  

Technology continues to be a key part of that strategy. Nearly two-thirds (62%) of Canadian SMEs report increasing their investment in AI, signalling that businesses are moving beyond experimentation and embedding AI into day-to-day operations to drive efficiency and support future growth.

The survey also highlights the biggest challenges facing Canadian SMEs heading into Q4. Productivity (41%) ranked as the leading business pressure, followed by wages (39%) and hiring and talent acquisition (36%), underscoring the balancing act many employers face as they continue to grow while managing costs and workforce demands.  

The findings also suggest businesses remain focused on long-term growth. More than one-quarter (26%) of SMEs say expansion or growth is their primary financial focus over the next six months, while 41% are focused on maintaining a balanced approach between growth and operational stability.  

As Canadian SMEs prepare for the busy fall season, Employment Hero says the findings point to a business community that remains optimistic about future opportunities while taking a disciplined approach to hiring, investment and workforce planning. 

2,500+ Organisations and 434,000 CI/CD Pipelines Potentially Exposed in the Largest AI Supply Chain Breach of 2026

Posted in Commentary with tags on August 11, 2026 by itnerd

More than 2,500 companies and approximately 434,000 CI/CD pipelines worldwide were potentially exposed in what is believed to be the largest supply-chain attack targeting AI infrastructure in 2026.

In March 2026, threat actor group Team PCP compromised LiteLLM, a widely used open-source AI gateway. CloudSEK Threat Intelligence subsequently reconstructed the victim exposure and is now sharing details of impacted organisations to help security teams identify potential exposure and take remedial action.

The affected LiteLLM packages were reportedly available through PyPI for only around 40 minutes. However, automated CI/CD environments can download and execute dependencies rapidly, allowing even a short-lived compromise to create prolonged security risk.

Among the information potentially accessible from affected environments were AWS, Google Cloud and Microsoft Azure credentials, SSH keys, Kubernetes tokens, CI/CD secrets, repository credentials, environment variables and LLM/API keys.

CloudSEK’s exposure dataset includes high-confidence matches associated with major global organisations including NVIDIA, Samsung Electronics, Cisco Systems, Siemens, S&P Global, ServiceNow, Deloitte, Vodafone, X Corp, Zscaler, FedEx, Volkswagen, Thales and London Stock Exchange Group, among others.

CloudSEK stresses that an exposure match does not automatically confirm successful compromise, data theft or malicious use of credentials. Organisations identified in the dataset should validate their exposure and investigate relevant systems.

The Threat May Outlive the Original Attack

The significance of the incident extends beyond the malicious package itself.

Once credentials are copied from an affected environment, removing the compromised software does not invalidate those credentials. According to CloudSEK’s analysis, stolen access can potentially be reused, sold or weaponized even after the malicious package has been removed, creating the possibility of downstream attacks weeks or months later.

The FBI also issued FLASH-20260702-01 on July 2, 2026, covering cybercriminal group TeamPCP, further highlighting the continuing security concern surrounding the campaign.

CloudSEK is sharing the exposure research openly so affected organisations can identify possible exposure, rotate credentials, investigate suspicious activity and harden their environments before compromised access is reused.

AI Infrastructure Is Becoming a High-Value Target

The LiteLLM incident also reflects a broader shift in cyberattacks.

AI gateways, MCP servers, agentic systems, vector databases and other AI infrastructure increasingly sit between sensitive corporate data, identities, cloud services and systems capable of taking action.

This makes AI infrastructure an attractive target for attackers seeking access beyond a single application. CloudSEK assesses that future attacks are increasingly likely to target the AI layer precisely because of how deeply it is connected to enterprise environments.

CloudSEK AIVigil: Continuous AI Attack Surface Monitoring

The growing attack surface around enterprise AI is the security problem CloudSEK AIVigil is designed to address.

AIVigil continuously discovers and monitors exposed AI infrastructure, MCP servers, leaked AI credentials, vector databases, agentic workflows and shadow AI. It combines CloudSEK’s cyber threat intelligence with AI exposure monitoring to help security teams identify exposed assets, credentials and attack paths before they develop into wider enterprise incidents.

Check Your Exposure

Organisations can use CloudSEK’s free exposure-checking tool to determine whether credentials associated with their environment appear in the identified dataset:

Free Exposure Checker:  https://exposure.cloudsek.com/ai-supply-chain-incident 

Full Research Report: https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines 

Full List Of Exposed Companies: TeamPCP CI/CD Secret Exposure — Check if your organisation is affected | CloudSEK

China Attacks Vulnerabilities In Microsoft Software

Posted in Commentary with tags on August 11, 2026 by itnerd

China-linked hackers exploiting a critical vulnerability in Microsoft’s software and turning that access toward ransomware. While you can find out about the issue here, this is the TL:DR. Please read the entire chain:

Phillip Wylie, Chief Security Evangelist & Sr. Consultant, Suzu Labs (https://www.linkedin.com/in/phillipwylie)

“The biggest takeaway isn’t just another critical vulnerability – it’s that attackers are increasingly targeting the tools organizations trust most. RMM platforms, identity systems, and security products provide privileged access by design, making them ideal force multipliers for threat actors. Organizations should treat these platforms as crown-jewel assets, prioritize rapid patching, closely monitor privileged activity, and assume that even trusted management infrastructure can become an attack vector.”

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“This particular attack fits into China’s broader cyber great power initiative that they’ve been working on for well over a decade, building the capability to exploit and gain access to as many systems as possible. I tend to think this particular attack was triggered by the vulnerability being discovered. China may have already been exploiting it for some period of time before the vendor publicly disclosed it on July 31.

“And this gets into a larger question that I think we need to ask whenever we see nation-state attacks suddenly transition into ransomware campaigns. What were they doing before?

“Remember, with a nation state like China, Russia, or even the United States, the primary goal generally isn’t ransomware. The goal is access. They want to dwell inside environments and maintain that access for as long as they possibly can. The way this particular attack has been linked to China leads me to believe the vulnerability may have been used for that type of access and persistence for some period of time. But once the vulnerability became public and a patch was available, its usefulness for longer-term nation-state operations dropped significantly. At that point, you might as well transfer the capability over to ransomware operations and extract whatever remaining value you can from the vulnerable systems that are still out there.

“There’s another issue here involving the vendors we choose for core security technologies, especially RMM tools. We really need to question whether we should be self-hosting these systems at all. If it’s a cloud service, the provider can potentially patch and update that service very quickly across its entire customer base. If you’re self-hosting it, you’re now dependent on your own organization getting that patch deployed as quickly as possible. And that matters here. Some of the research we’ve been seeing indicates that more than 25% of these servers may still be unpatched and vulnerable to this attack.

“Once again, this highlights one of the major problems with on-premises technology when a serious vulnerability drops. Getting a patch is one thing. Getting that patch deployed everywhere fast enough to matter is something completely different.”

The threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the CISA KEV catalog on August 3, 2026. You should apply all updates to your Windows systems and Microsoft Defender for Endpoint detects this activity. So update that too.

Park Place Technologies Named to Inc. 5000 List of America’s Fastest-Growing Private Companies for Tenth Time

Posted in Commentary with tags on August 11, 2026 by itnerd

Park Place Technologies has been named to the 2026 Inc. 5000, the annual list recognizing the fastest-growing private companies in America.

Park Place earned the No. 4,874 spot on this year’s ranking, rejoining the list after narrowly missing the cutoff in 2025; it has received this recognition for 10 years. The Inc. 5000 has become one of the most respected measures of entrepreneurial success and sustained business growth in the United States, recognizing companies that have demonstrated significant revenue growth while navigating changing market conditions.

Since its founding in 1991, Park Place Technologies has built a global presence serving organizations across industries with third-party maintenance, managed services, professional services, IT asset disposition and network monitoring solutions. The company’s continued growth reflects increasing demand for flexible, cost-effective alternatives that help enterprises optimize their technology investments.

This year’s recognition marks another milestone in Park Place’s history of appearances on the Inc. 5000.

The 2026 Inc. 5000 celebrates the private companies that have achieved remarkable growth over the past three years, representing a wide range of industries that are shaping the future of the U.S. economy.