New York Blood Center notifies 194,000 people of data breach

Posted in Commentary with tags on September 17, 2025 by itnerd

Comparitech reported today that New York Blood Center Enterprises this week confirmed it notified 193,822 people of a January 2025 data breach that leaked names, SSNs, ID numbers, bank account info, health info, and test results. The attack was first reported back in January.

Commenting on this is Rebecca Moody, Head of Data Research at Comparitech

“This attack becomes the 89th confirmed attack on a healthcare company (worldwide) this year so far. Across these attacks, nearly 6.7 million records are known to have been breached with this attack on NYBCe becoming the sixth largest based on records affected.”

“To date, no gangs have claimed the attack on NYBCe, and, with the attack happening back in January 2025, it’s unlikely we’ll see a claim from a gang now. This could mean that ransom negotiations were successful but NYBCe hasn’t confirmed this. Across the 89 confirmed attacks we’ve noted for this year, the average ransom demand has been just under $627,000.”

Once again the healthcare sector is ground zero for getting attacked by threat actors. I don’t know how much clearer it will have to become before something is done to put this sector on better footing.

RegScale Raises $30+ Million to Redefine Cyber GRC for Highly Regulated Industries

Posted in Commentary with tags on September 17, 2025 by itnerd

RegScale, the leader in Continuous Controls Monitoring (CCM), today announced it has raised $30+ million in an oversubscribed Series B round led by Washington Harbour Partners, with additional investment from new investors M12, Microsoft’s Venture Fund, Hitachi Ventures, and Ankona Capital, as well as continued participation from existing investors SYN Ventures and SineWave Ventures. This raise confirms what customers and investors already know: RegScale isn’t building the next wave of cyber GRC, it’s redefining it, turning compliance from a burdensome, manual checklist process into a real-time and automated platform for the most heavily regulated industries.

The new capital will accelerate RegScale’s leadership in the $50+ billion GRC market and fuel key hires across R&D and sales, enabling the company to deliver increased impact to its growing customer base. It will accelerate RegScale’s RegML, industry-leading AI roadmap, expanding the only CCM platform with AI agents purpose-built to continuously monitor compliance, automate evidence collection/reviews, conduct audits, and analyze risk — capabilities no other provider delivers securely at scale. “RegScale’s AI-powered compliance-as-code approach delivers what today’s operators need most: faster certifications, lower costs, and a stronger security posture. This is the future of cyber GRC, and we’re excited to support RegScale as they scale to meet the growing demand,” said Todd Graham, Managing Partner at M12, Microsoft’s Venture Fund.

With this funding, RegScale is not only strengthening its value for government agencies, financial services, and high-tech organizations but also accelerating expansion into energy, utilities, and other highly regulated sectors where continuous compliance and security assurance are most urgent.

With cyberattacks escalating, nation-states and criminal groups exploiting compliance gaps, and budget cuts pushing for cost takeout and tool consolidation across all industries, CISOs can no longer rely on traditional GRC and manual labor approaches to just check a box. They need CCM to operationalize their risk program and deliver real-time control assurance against a growing set of cybersecurity threats.

RegScale is leading this revolutionary change in managing cyber GRC. Customers report 60% faster audit prep, 3–4x faster FedRAMP High authorizations, and up to 80% greater accuracy, with AI and automation delivering up to 10x staff efficiency. RegScale continues to promote industry standards, serving as the lead affiliate for the Cyber Risk Institute’s (CRI) OSCAL initiative, as a founding member of the OSCAL Foundation, a participant in the Cloud Security Alliance (CSA) Compliance Automation Revolution, and a contributor to the FedRAMP 20x initiative. Its impact has been recognized across the industry, most recently being named Best Compliance Solution by SC Media and as an industry leader by Gartner.

As proof of its platform’s maturity, RegScale achieved FedRAMP High Authorization sponsored by the DHS in half the cost and in just six months, versus the typical 18–24 months. Inside the company, the team is driving incredible growth: ARR has tripled year-over-year, key enterprise and federal customers are on board, and the team has expanded with major additions, including Devon Goforth as CTO, Rich Shirley as VP of Strategic Partnerships, Mike Kimball and Meghan Shafer as VPs of sales, Jennifer Stafford as GM of Federal, and strategic advisors Roland Cloutier and Alex Tosheff.

RegScale is a continuous controls monitoring (CCM) platform that is designed to be the operational risk tool for the CISO. Built on a compliance as code foundation, RegScale enables extreme automation with our API first strategy, self-updating paperwork, and powerful AI agents that all but eliminate manual labor, turn your program more proactive, save money, accelerate time to market, and reduce risk in your operational environment. Heavily regulated organizations, including Fortune 500 enterprises and the Federal government, use RegScale and report achieving compliance certifications 90% faster and trimming audit preparation efforts by 60%, thereby strengthening security and reducing costs. Learn more at http://www.regscale.com.

MIND Appoints New CMO, Accelerating Go-to-Market Strategy & Company Growth

Posted in Commentary with tags on September 17, 2025 by itnerd

Today, MIND announced the appointment of Jimmy Tsang as Chief Marketing Officer, whose leadership will be crucial in scaling the company’s global presence, driving revenue growth, and solidifying MIND’s brand positioning as a rising force in DLP. 

Since joining MIND in 2023, Tsang has led the company’s strategic branding efforts, significantly enhancing its market presence. With 2+ decades of experience in cybersecurity and marketing, Tsang previously served as VP of Marketing at Pondurance and led both product and content marketing for IBM Security.

This announcement comes amid a period of accelerated growth for MIND, driven by customer adoption already serving Fortune 1000 companies across diverse industries, strategic partnerships, and industry accolades. 

Recently, MIND announced $30 million in growth funding, bringing total funding to over $40 million. At this year’s Black Hat, MIND launched the first autonomous DLP platform and earned Honorable Mention in its Startup Spotlight Competition.

Microsoft Seizes 338 Sites to Disrupt RaccoonO365’ Phishing Service

Posted in Commentary with tags on September 16, 2025 by itnerd

Today, Microsoft’s Digital Crimes Unit said it disrupted RaccoonO365, the fastest-growing tool used by cybercriminals to steal Microsoft 365 credentials, by seizing 338 websites associated with the popular service and cutting off criminals’ access to victims.

Microsoft posted a blog post on the seizure here: https://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/

Erich Kron, security awareness advocate at KnowBe4, commented:

“Clearly, email phishing continues to be a major threat that organizations face on a daily basis. Phishing services make it far easier for unskilled attackers to be able to play in the cybercrime game, while not necessarily being cyber savvy themselves.

“Credential theft through phishing can be especially dangerous because people tend to reuse passwords across different accounts and services, meaning, if a bad actor can trick someone out of their password, they may not only have access to that account, but others as well.

“The social engineering threats drive home the reason that organizations need to have a well-established human risk management (HRM) program in place that will educate users on ways to spot fake login pages and help them understand why credential reuse is so dangerous. In addition, MFA should be deployed wherever possible to make things even tougher for attackers in the event they do steal someone’s credentials.”

This blog post is very much worth your time to read as it shows how threat actors are evolving to be increasingly more effective and dangerous.

Specops Research: Cracking Bcrypt: Is New-Gen Hardware/AI Making Password Hacking Faster?

Posted in Commentary with tags on September 16, 2025 by itnerd

Almost two years ago, the Specops research team analyzed how long it took to crack passwords hashed with the bcrypt algorithm.

Using newer, more powerful hardware, the researchers revisited that previous research creating a new table of Bcrypt cracking times in this just-published report Cracking bcrypt: New-gen hardware speeds up password hacking. The reason for the revisit is two-fold: the AI boom causing a glut of consumer hardware, as well as the arms-race in consumer graphics performance.

The focus on compute power for both consumers and enterprises whether for general purpose compute (GPGPU) or training LLMs has caused arguably all three major graphics vendors to focus more heavily on compute performance than they may have in the past. This shows in the performance of Nvidia’s recent 50-series, as well as AMD’s upcoming transition to the ‘UDNA’ architecture. Specops research team investigated what this boom and renewed focus on compute means for the difficulty of cracking a leaked password hash, and the future security of passwords.

Short, non-complex passwords can still be cracked relatively quickly, highlighting the huge risks of allowing users to create weak (yet very common) passwords such as ‘password’, ‘123456’, and ‘admin’. However the high cost factor of bcrypt makes longer passwords extremely secure against brute force attacks thanks to its slow-working hashing algorithm. Once a combination of characters are used in passwords over 12 characters in length, the time to crack quickly becomes a near-impossible task for hackers. This shows the value of enforcing longer passwords.

This research coincides with the latest addition of over 70 million compromised passwords to the Specops Breached Password Protection service. These passwords come from a combination of our honeypot network and threat intelligence sources.

To view the complete Specops research report, visit Cracking bcrypt: New-gen hardware speeds up password hacking

BDO Canada recognized as a Major Player in the IDC MarketScape for Canadian AI Services 2025

Posted in Commentary with tags on September 16, 2025 by itnerd

Today, BDO Canada is proud to be named as a Major Player in the IDC MarketScape: Canadian AI services 2025 Vendor Assessment (doc #CA51802124, September 2025).

BDO believes this recognition reflects the firm’s strong industry knowledge and proven track record of delivering AI solutions that are scalable and tailored to the needs of Canadian businesses. The IDC MarketScape report for Canadian AI services provides both a quantitative and qualitative look at how vendors perform in the market, helping technology buyers choose the right partners for AI-driven transformation.

With over 80 offices and more than 4,500 professionals across Canada, BDO combines industry knowledge in areas like manufacturing, financial services, energy, and infrastructure with hands-on experience to deliver AI solutions that create real impact for clients, including many of the country’s Fortune 100 companies.

BDO accelerates AI adoption for its clients through proprietary tools, strong partnerships, and sector-focused solutions. Backed by alliances with Microsoft, AWS, Google Cloud, Salesforce, Snowflake, and Databricks, and supported by a global network spanning 160+ countries, BDO Canada provides end-to-end AI services that combine technical expertise with practical, client-focused outcomes.

To learn more about BDO Canada’s Practical AI solutions, visit: Practical AI solutions to drive ROI growth.

DigiCert Acquires Valimail

Posted in Commentary with tags , on September 16, 2025 by itnerd

DigiCert, a leading global provider of digital trust, backed by Clearlake Capital Group, L.P. (together with its affiliates, “Clearlake”), Crosspoint Capital Partners L.P. (“Crosspoint”), and TA Associates Management L.P. (“TA”), today announced the acquisition of Valimail, a market leader in zero trust email authentication delivered as a service. With more than 92,000 clients worldwide, up 70% this past year, Valimail is recognized as a leader in protecting organizations from phishing, spoofing, and domain-based threats.

The acquisition advances DigiCert’s strategy of delivering end-to-end digital trust. Valimail adds leadership in zero trust email authentication to the DigiCert ONE platform that already brings together public CA, private PKI, certificate lifecycle management, and DNS to give customers a unified view of digital trust.

Valimail is a pioneer in Domain-based Message Authentication, Reporting, and Conformance (DMARC). Today, the company protects global brands, enterprises, and government agencies, and holds the industry’s most robust portfolio of DMARC-related patents. Valimail is also the only DMARC provider with FedRAMP authorization, underscoring its leadership in highly regulated environments.

DigiCert is also a leading global provider of Mark Certificates (MCs) and Verified Mark Certificates (VMCs), which enable organizations to display verified brand logos in customer inboxes. When combined with DMARC, VMCs power BIMI (Brand Indicators for Message Identification), allowing users to instantly recognize trusted emails. This not only helps prevent phishing but also reinforces brand identity with visual trust indicators such as the blue check mark alongside the sender’s name. By bringing together DMARC enforcement, VMCs, and DigiCert’s leadership in digital trust, organizations can deliver a safer and more trustworthy email experience for their customers.

Sidley Austin LLP served as legal advisor to DigiCert. Piper Sandler served as the exclusive financial advisor to Valimail while Fenwick & West LLP served as legal advisor.

Safe Software Launches 24/7 Support For FME Users Worldwide

Posted in Commentary with tags on September 16, 2025 by itnerd

Safe Software (Safe), the creator of FME, the only All-Data, Any-AI enterprise integration platform on the market with true support for spatial data today announced the expansion of its Premium Extended Support program with the launch of global 24/7 coverage. This offering ensures that FME users around the world can access expert help anytime, reducing downtime and keeping critical workflows running without interruption.

Premium Extended builds on the benefits of Safe Software’s existing Premium Support program, adding around-the-clock access to senior specialists, rapid issue escalation, and continuous coverage for critical needs.  Customers can choose the level of support that best fits their needs, whether that’s faster response during business hours, a dedicated Technical Account Manager for strategic enablement, or full global coverage around the clock.

This expansion reflects Safe Software’s commitment to supporting its worldwide customer base across industries such as government, utilities, transportation, financial services, where uninterrupted operations are critical and downtime can carry significant cost.

Are you interested in hearing more about Premium Support? You can fill out the form to get in touch with us at: https://www.safe.com/contact-sales-pricing/ 

LinkedIn + Duolingo: A new way for Canadians to flex their language skills

Posted in Commentary with tags , on September 16, 2025 by itnerd

Nearly one in three Canadians (10.7 million people!) can speak a language beyond English or French—and with more than 470 languages spoken across the country, that’s a serious superpower. But until now, there’s been no easy, credible way for professionals to show it off. 

Enter LinkedIn + Duolingo. Starting today, members can showcase their credible Duolingo Score right on their LinkedIn profile. It’s a fun, trusted, and measurable way to turn language skills into a professional edge, helping members stand out and giving employers a signal they can count on. 

For Canada’s multilingual workforce, this means those hidden skills can finally shine. Verified language ability can be the difference between being overlooked or landing the next big opportunity. 

Together, LinkedIn and Duolingo are giving Canadian professionals a simple, trusted way to showcase what they know—and connect it directly to what’s next. 

DH2i Brings Mission-Critical HA Capability to the Table for SQL Server 2025-Backed AI Applications

Posted in Commentary with tags on September 16, 2025 by itnerd

 DH2i® recently announced the upcoming release of its flagship DxEnterprise software’s full readiness for public preview release of Microsoft SQL Server 2025. Designed with today’s and the future’s AI-driven, dynamic businesses in mind, this update gives both customers and channel partners the power to tackle next-gen workloads with unmatched flexibility, reliability, and ease.

With this release, DxEnterprise not only continues its tradition of seamless high availability and disaster recovery (HA/DR) across Windows, Linux, and Kubernetes, but also delivers full readiness for public preview release of SQL Server 2025 including advanced AI and scalability features. This includes maintaining high availability for databases support embeddings and function as vector stores. This ideally positions DH2i channel partners to guide customers through modernization initiatives, deploy end-to-end resilient infrastructures, and elevate their standing as strategic advisors offering the most innovative data management solutions available.

With DxEnterprise’s support for the public preview release of SQL Server 2025, enterprise end customers can now confidently build and run AI apps in development environments across any mix of infrastructure, including on-prem, cloud, hybrid, and Kubernetes environments. Once SQL Server 2025 is GA, customers will be able to take this capability straight to their mission-critical production environments. This release removes longstanding roadblocks related to deploying SQL Server Availability Groups (AGs) in containers, maintaining HA for vector databases, and scaling securely with the latest platform innovations. It enables organizations to embrace modern workloads like Retrieval Augmented Generation (RAG) and operational AI with the assurance of continuous uptime, simplified failover, and seamless integration with their existing HA/DR strategies. In short, enterprises can now modernize faster, innovate more freely, and meet aggressive AI and digital transformation goals, while maintaining the rock-solid reliability their businesses demand.

Key updates include:

  • SQL Server 2025 Ready – Ensures compatibility with the AI-ready, mission-critical RDBMS reimagined for the cloud and fabric era
  • Vector Database HA Support – Unlocks reliable deployment of AI applications with embedded semantic search, vector indexes, and RAG pipelines
  • DH2i DxOperator Enhancements – One of the most efficient Kubernetes-native SQL Server Availability Group deployment methods – now fully aligned with SQL Server 2025’s peak performance ambitions
  • AG HA for Kubernetes – This solution provides fully automated failover for SQL Server AGs on Kubernetes

With AI workloads becoming the new norm and the push toward containerization and hybrid infrastructure accelerating, DxEnterprise’s new capabilities will empower organizations to not only keep up, but lead.