SIOS Technology to Showcase High Availability Clustering Solutions at Key Events Across the US, Europe, and Middle East in Fall 2025

Posted in Commentary with tags on September 11, 2025 by itnerd

 SIOS Technology Corp. has announced it will demonstrate its high availability clustering software for business-critical applications at three premier technology events this fall, including: 

At each event, SIOS experts will demonstrate how SIOS LifeKeeper and DataKeeper software deliver high availability and disaster recovery for critical applications such as SQL Server, SAP, and Oracle. Attendees will discover how SIOS clustering solutions help ensure application uptime, eliminate data loss, and simplify HA/DR operations across physical, virtual, cloud, and hybrid environments.

SIOS clustering software enables IT teams to create highly available application environments without the need for shared storage. Through intelligent application monitoring, real-time data replication, and automated failover and recovery, SIOS ensures business continuity with minimal complexity and reduced cost. With support for Windows and Linux in any infrastructure, SIOS solutions are trusted by enterprises worldwide.

Google security veterans raise $13M seed round for AegisAI to fix email security 

Posted in Commentary with tags on September 11, 2025 by itnerd

 AegisAI, a cybersecurity startup founded by former Google Safe Browsing and reCAPTCHA leaders Cy Khormaee and Ryan Luo, today announced its public launch and funding round with a radical approach to email security: autonomous AI agents that eliminate Phishing, Malware, and Business Email Compromise (BEC) attacks before they reach user inboxes — while reducing false positives by up to 90% compared to traditional solutions.

The $13m seed funding round was led by Accel and Foundation Capital. The funding will accelerate product development, expand the engineering team, and support go-to-market efforts as the company scales its autonomous email security platform.

AI has created a new wave of threats that rule-based systems are not prepared for. Adversaries can rotate graphics, messaging, and fabricate supporting content to create lures that look more real than ever. A 2024 study showed LLM-generated phishing messages had a significantly higher click-through rate (54%) than human-written ones (12%), proving their effectiveness. 

Modern attackers are also increasingly abusing trusted platforms like Salesforce, Zoom or Google to deliver malicious content, exploiting the inherent trust these services carry to bypass traditional reputation-based security filters and rules that would typically block suspicious domains or unknown senders.

AegisAI introduces a paradigm shift: an orchestrated network of real-time AI agents that inspect, analyze, and neutralize email threats autonomously, eliminating the need for static rules, extensive user training, or complex playbooks.

The AegisAI platform integrates seamlessly with Microsoft 365 and Google Workspace via API deployment. Unlike traditional rule-based gateways, its AI agents continuously learn from real-world adversarial behavior and share threat intelligence across organizations, enabling rapid detection and remediation of emerging phishing, spoofing, and executive impersonation tactics.

Core Platform Capabilities:

  • Autonomous Threat Detection – Real-time analysis of every message component including links, attachments, metadata, QR codes and behavioral patterns.
  • Intelligent False Positive Suppression – Customers in production environments have seen up to 90% reduction in False positives (good emails being quarantined) compared to traditional solutions.
  • Zero-Configuration operation – Autonomous response, escalation, and policy enforcement requiring minimal SOC setup or maintenance.
  • Security-First Design – Built with enterprise-grade encryption and data minimization principles.

The founding team brings deep expertise from Google. Following a successful stealth phase with pilot customers across fintech and tech companies, AegisAI has demonstrated significant improvements in threat detection accuracy and operational efficiency.

The Nikon ZR: A New Era of Limitless Cinematic Possibilities, Born from Nikon’s Synergy with RED Digital Cinema

Posted in Commentary with tags on September 11, 2025 by itnerd

Nikon Canada Inc. announced their first cinema camera made for filmmakers, the ZR. The ZR is an ultra-lightweight, full-frame camera that marks an audacious introduction to the Z Cinema series, a collection that invokes the best technologies and philosophies of both companies. Designed for emerging cinematographers and high-end content producers, the supremely capable Nikon ZR packs an unparalleled amount of professional video production features at a price that puts cinematic quality within reach for all types of filmmakers. 

The Nikon ZR is as versatile as it is powerful, with a multitude of original and class-leading capture and workflow features never seen before in this level of camera. The new Nikon ZR can record up to 6K/60p (59.94p) and incorporates the new R3D NE RAW video file format with RED colour science based on RED’s popular R3D RAW codec, with 15+ stops of dynamic range. This new codec uses colour science and exposure standards of RED cameras to ensure accurate colour matching, even for multi-cam shoots. The impressively huge 4 inch DCI-P3 LCD is nothing short of stunning, and bright enough to be used even in direct sunlight, while often eliminating the need for an external monitor. It also has class-leading audio capabilities such as 32-bit float audio from built-in and external microphones, plus OZO directional audio. The ZR also has 7.5 stops of built-in image stabilization (IBIS) and unlocks a whole new world of optical versatility, since the wide Nikon Z mount enables a large variety of lenses to be adapted using third-party lens adaptors.

Legendary RED Colour Science, Built-In

The new ZR features a full-frame sensor for excellent depth of field and video quality and supports internal recording up to 12-bit RAW 6K/60p. This is the first camera to use the new 12-bit R3D NE RAW codec, a new RAW format which REDCODE RAW users will find familiar. By leveraging its broad 15+ stop dynamic range, it achieves well-balanced image quality from highlights to shadows. Support for Log3G10 and the REDWideGamutRGB gamut reproduces exposure standards and colours consistent with RED colour science, with true RED colour tonality, skin tone integrity and tonal roll-off—similar to the output of RED’s cinema cameras such as the V-RAPTOR [X] and KOMODO-X. Two base ISO sensitivities are available, ISO 800 and ISO 6400, allowing users to choose the best option for a particular scene or situation such as bright daylight or lowlight interior scenes. However, just like REDCODE RAW, ISO in R3D NE files is fully adjustable in post for maximum flexibility.

Furthermore, users also have the option to shoot in N-RAW, ProRes RAW, and other formats to best suit their production and workflow. The camera also features a new view assist function which allows the user to store and select from up to ten LUTs in the camera. This will let the filmmaker preview the effect of the colour grade in real time using the monitor. Three types of LUT data (17-point, 33-point, 65-point) can be loaded into the camera. RED’s Creative LUT Kit is available for free via the RED website here

The ZR features a new Cinematic video mode, a user preset for those who want to easily enjoy the RED cinematic look with a faster workflow in less data-intensive non-RAW formats. Cinematic mode automatically adjusts the shutter angle to 180 degrees, changes the frame rate to 24 fps, and applies the RED Cine Bias Picture Control for gorgeous yet simple cinematic colour. What’s more, nine RED-curated cinematic Picture Controls based on RED creative LUTs will be available for free download via Nikon Imaging Cloud, expanding possibilities for more diverse imaging expression.

Incredible Audio: 32-Bit Float Audio Recording + OZO Audio Support for Built-In Mic

With uncompromising attention to audio capabilities, the ZR is the world’s first cinema camera to support 32-bit float audio recording with both built-in and external microphones, as well as through the 3.5 mm microphone jack. This unique ability enables the recording of clear, distortion-free sound from quiet to loud, without requiring on-location gain adjustment. It supports recording a wide range of sound sources, from interviews to live concerts, with maximum audio flexibility in post. The three high-performance mics built into the camera use Nokia’s OZO Audio technology to realize cutting-edge audio recording. Filmmakers can choose from one of the five polar pickup patterns — [Front (Super directional)], [Front], [All directions], [Rear], and [Stereo (binaural)] — that best suits the situation, from interviews or product tutorials to immersive audio applications.

The ZR is also the first Nikon camera to feature a digital accessory shoe, which enables two-way digital communication between the camera and compatible accessories, allowing for advanced functionality such as tally lamp and microphone LED control. Additionally, the camera can supply power directly to supported accessories, eliminating the need for separate batteries or cables. The newly designed rubber shoe cover provides excellent dust and drip resistance, ensuring reliable performance in a variety of shooting environments. Going forward, Nikon will collaborate with third-party accessory manufacturers to offer a wide range of solutions that meet the diverse needs of filmmakers.

High-Performance Autofocus with Nikon’s Deep Learning-Based AI Technology

The impressive processing power of the EXPEED 7 image-processing engine installed in Nikon’s flagship camera Z9 and AI technology that utilizes deep learning enables more accurate subject detection and tracking for optimal image processing in accordance with the subject, scene and situation. This makes capturing the intended subject with greater accuracy much easier, significantly expanding possibilities for film production. The camera also detects nine types of subjects automatically, including people, animals and vehicles. It even detects small faces occupying as little as 3 per cent of the long side of the frame for precise focusing on distant human subjects. Users can also adjust AF speed and sensitivity to suit their creative style, enabling a slow rack for cinematic effect or fast-paced focus for action. 

Designed to Thrive in any Production Environment

The ZR uses an innovative fanless design, with the entire camera body contributing to efficient heat dissipation and thermal management. This design decreases audible noise, enhances battery life and increases durability. The ZR can shoot uninterrupted recording for up to approximately 125 minutes. Additionally, USB power delivery capability allows for long takes and worry-free shooting at events that require extended recording, such as weddings, concerts and interviews. 

With its magnesium alloy chassis, the ZR inherits the same rugged durability standards of Nikon’s Z6III. This means it’s designed to handle the pressures of professional production environments—indoors or out. The body is resistant to dust, sand and moisture, thanks to careful sealing at critical points like buttons, seams and ports. It’s a tool designed for real-world filmmaking—resilient under pressure and ready to shoot on location. The controls on the ZR also reflect a new filmmaker-oriented UI, with familiar menus, a new quick menu for filmmakers, as well as customizable button placement made for a cinematographer’s most used features. 

Additional Features of the Nikon ZR

  • Super lightweight with small footprint at just 1.19 lb (body only).
  • A short 16mm flange focal distance (the shortest among full-frame cameras) offers greater flexibility in the lenses that can be used, allowing filmmakers to make the most of their existing lens assets.
  • The shutter angle can be adjusted from 5.6° to 360° for video recording. Shutter speed is also available.
  • The brightness of the information display (histogram/waveform monitor size, transparency and position, and zebra pattern colour) can be changed.
  • Automatic rotation of vertical video for social media content creation.
  • A front tally light /rec lamp lets subjects know you are recording. Additionally, it receives tally control signals input via HDMI-CEC and displays the status of each camera when multiple cameras are used.
  • A superior dust- and drip-resistant, durable construction expands shooting possibilities.
  • Equipped with advanced still photography features inherited from the Z6III, as well as new features such as a preset for starscape photography and a new dehaze function. 
  • Slow-motion presets: Instant access to 4K/119.88p and Full HD/239.76p cinematic motion, as well as user modes for 4x and 5x slow-motion. 
  • It also supports Frame.io Camera to Cloud using NX MobileAir, automatically transferring video data directly to the cloud for a faster and more efficient post-shooting workflow.

RED Digital Cinema, Inc. Releases the V-RAPTOR XE

RED Digital Cinema, Inc., a subsidiary of Nikon Corporation, is pleased to announce the release of the new V-RAPTOR XE digital cinema camera, which was released on September 9, 2025. The newest addition to its acclaimed Z CINEMA camera lineup, this streamlined version of the revolutionary V-RAPTOR [X], curates the essential tools for cinematic storytelling. Designed for independent creators who demand uncompromising image quality, the V-RAPTOR XE delivers large-format, cinema-grade features at a more accessible price point. The new camera retains RED’s industry-leading 8K large format (VV) global shutter sensor found in the V-RAPTOR [X] series, ensuring cinematic image fidelity, dynamic range, and low-light performance that filmmakers trust. Nikon and RED will meet a wide range of needs in film production with an extensive lineup of cinema-oriented products under the Z CINEMA series.

New ME-D10 Shotgun Microphone

The ME-D10 is a 32-bit float shotgun microphone compatible with the new digital accessory shoe developed for the ZR. It requires no battery or cable and has built-in shock mounts to minimize any interference. It offers two recording modes, PURE and FOCUS, which can be selected with a switch on the microphone. PURE mode features a wide dynamic range and a sound design true to the original source, allowing natural and accurate capture of raw audio, including the ambient atmosphere. FOCUS mode accurately captures the intended voice, even in noisy surroundings such as those outdoors, ensuring clear audio for product presentations and live streams.

Price and Availability

The new Nikon ZR Cinema Camera will be available in late October 2025 for a manufacturer’s suggested retail price (MSRP) of $2,999.95 for the body only. The ME-D10 shotgun microphone, also scheduled for release in late October, has a suggested retail price of $459.95.

40% Alerts Ignored, 57% Rules Suppressed + The Alert Breaking Point Reached Says New Report

Posted in Commentary on September 10, 2025 by itnerd

SOCs don’t struggle with visibility anymore; they’re buried in it. This report from Prophet Security puts hard numbers behind what many in the field already see: the alert problem has reached breaking point, and AI is being applied first where it matters most triage, investigation, and tuning. It captures both the urgency and the practical direction of where SecOps is heading.

A few of the findings from the research survey include:

  • Average of 960 alerts generated daily
  • 40% of which are never investigated
  • 57% companies suppress detection rules
  • 55% use AI for alert triage & investigations.

The 30+ page report includes responses from a mix of CISOs, SecOps VP/Directors, SIRT/Threat Mgrs, and SOC analysts/engineers across a variety of industry segments at organization sizes ranging from 1000+ to more than 20,000+.   The report is divided into three main areas: The Alert Problem, The Pain in Organizations and the AI SOC Shift. 

The report is more than a collection of statistics, its serves as a call to action with insights to arm security teams with guidance to navigate another transformative era in security. With recent incidents such as the Palo Alto data breach, teams who implement AI in the SOC are better prepared to focus their skills/time on proactive threat hunting and investigations.

You can read the report here: https://www.prophetsecurity.ai/ai-soc-adoption-trends

ServiceNow supercharges AI adoption for enterprises with secure, scalable AI platform 

Posted in Commentary with tags on September 10, 2025 by itnerd

ServiceNow today unveiled its new Zurich platform release. This release delivers breakthrough innovations with faster multi-agentic AI development, enterprise-wide AI platform security capabilities, and reimagined workflows. New intelligent developer tools enable secure vibe coding with natural language to help turn employees into high-velocity builders and creators and lower the barrier to app creation. Built-in security capabilities, including ServiceNow Vault Console and Machine Identity Console, natively secure sensitive data across workflows and govern integrations to help organizations scale agentic AI and innovations with confidence. The introduction of autonomous workflows turns data into action through agentic playbooks, uniquely offering the flexibility to apply AI and human input in workflows where and when it’s needed for greater control and efficiency. 

Enterprise leaders are racing to move beyond table-stakes AI implementations to unlock transformative, tangible results. According to Gartner®, “By 2029, over 60% of enterprises will adopt AI agent development platforms to automate complex workflows previously requiring human coordination.” The ServiceNow AI Platform delivers this transformational promise across the enterprise and underpins a new era of highly efficient human-AI collaboration. 

Vibe coding meets enterprise scale 

According to Gartner®, “Agentic AI features will be near ubiquitous, embedded in software, platforms and applications, transforming user experiences and workflows.” The introduction of ServiceNow Build Agent and developer sandbox provides resources for employees to work with AI more efficiently, conversationally, and at scale to solve real problems in every corner of the business. 

  • Build Agent is a breakthrough for enterprise app creation—bringing vibe coding to the rigor of the ServiceNow AI Platform. In seconds, employees can turn an idea into a production-ready application by asking in natural language. Say, “Create an onboarding app that assigns tasks to HR, IT, and Facilities,” and Build Agent handles the rest—design, build, logic, integrations, testing, and industry-leading governance included. What sets it apart is enterprise discipline: every app comes with audit trails, security, and compliance built in. Developers and citizen creators alike get the speed of AI with the confidence of enterprise-grade control, in a streamlined interface. 
  • Developer sandbox empowers developers to build better applications, faster, while maintaining the highest standards of quality. Sandboxes provide isolated environments within a single instance, so multiple teams can collaborate, build, and test new features without conflicts, and rapid scale doesn’t come at the cost of control. Teams can version, iterate, and deliver without waiting in line for developer resources. Developers can safely experiment with vibe coding, test AI-powered workflows, and resolve version control issues before changes go live. This reduces rework, shortens feedback loops, and helps teams ship higher-quality applications rapidly with lower risk. 

Security that enables AI strategy 

As enterprises adopt autonomous workflows powered by agentic AI, securing how these systems access data and communicate across environments is essential. Zurich introduces new built-in AI platform security capabilities to make it easier to protect sensitive information, govern integrations, and manage growing AI footprints. 

  • The new ServiceNow Vault Console provides a guided experience to discover, classify, and protect sensitive data across workflows. For example, an admin managing customer service operations can now identify personal data across tickets, apply different types of protection policies, and track compliance activity. The console also offers recommendations for protecting newly discovered sensitive data, along with customizable dashboards to monitor key metrics. What used to require manual configuration across multiple tools can now be managed in one place, with intelligent insights and a streamlined experience. 
  • Machine Identity Console addresses the need for integration security with enterprise-grade authentication and authorization, delivering control over bots and APIs head on. As the ServiceNow AI Platform scales, every API connection, including those from AI agents, introduces another identity to manage and determine what it can access. This console gives platform teams visibility into all inbound API integrations using machine identities such as service accounts and keys, flags outdated or weak authentication methods, and provides clear steps to strengthen security. If an integration is using basic authentication or hasn’t been active in 100 days, the console spots it and helps resolve it. 

Without built-in security and trust, scaling AI comes with risk. These new security features in Zurich build upon ServiceNow’s AI Control Tower, announced in May 2025, which provides enterprise-wide visibility, embedded compliance, and end-to-end lifecycle governance for agentic AI systems. By centralizing oversight of every AI agent, model, and workflow—native or third-party—the AI Control Tower ensures organizations can scale AI with confidence, aligning innovation with enterprise-grade security and trust. 

Turn data into outcomes with autonomous workflows 

As organizations rapidly scale AI, they face the added challenge of delivering solutions consistently, reliably, and responsibly. Enterprises need the right guardrails, full visibility, and strong governance to achieve service delivery, or they risk eroding trust and slowing results. ServiceNow’s AI Platform does all this in a single platform, setting a new standard for how organizations can create autonomous workflows to turn data into action and AI into measurable business impact. 

  • Agentic playbooks from ServiceNow bring people, automation, and AI together seamlessly, powering autonomous workflows. A traditional playbook is a structured sequence of automated steps based on predefined business rules and processes—ideal for ensuring consistency, efficiency, and trust. Agentic playbooks amplify this model by embedding AI into the trusted framework. AI agents eliminate manual effort, completing tasks in seconds and accelerating execution. This frees employees to focus on higher-value work where human judgment matters most. For example, in a credit card support situation, an agentic playbook can guide an AI agent to verify someone’s identity, freeze the card, send a replacement and notify the customer while allowing a human agent to step in as necessary. The result: governed, efficient, and trusted work—supercharged by AI to deliver faster, smarter outcomes. 
  • The ServiceNow Zurich platform release also seamlessly combines Process and Task Mining insights within a unified platform. These new capabilities give organizations an end-to-end understanding of how work gets done—revealing where human expertise is essential, and where AI agents can deliver the greatest impact. With process intelligence built directly into the platform, customers can move seamlessly from insight to action—streamlining operations, applying AI where it matters most, and accelerating real business outcomes without the complexity of disconnected legacy tools. 

Availability 

All features announced today as part of the ServiceNow Zurich platform release are generally available and can be found in the ServiceNow Store. 

DH2i Brings Mission-Critical HA Capability to the Table for SQL Server 2025-Backed AI Applications

Posted in Commentary with tags on September 10, 2025 by itnerd

 DH2i recently announced the upcoming release of its flagship DxEnterprise software’s full readiness for public preview release of Microsoft SQL Server 2025. Designed with today’s and the future’s AI-driven, dynamic businesses in mind, this update gives both customers and channel partners the power to tackle next-gen workloads with unmatched flexibility, reliability, and ease.

With this release, DxEnterprise not only continues its tradition of seamless high availability and disaster recovery (HA/DR) across Windows, Linux, and Kubernetes, but also delivers full readiness for public preview release of SQL Server 2025 including advanced AI and scalability features. This includes maintaining high availability for databases support embeddings and function as vector stores. This ideally positions DH2i channel partners to guide customers through modernization initiatives, deploy end-to-end resilient infrastructures, and elevate their standing as strategic advisors offering the most innovative data management solutions available.

With DxEnterprise’s support for the public preview release of SQL Server 2025, enterprise end customers can now confidently build and run AI apps in development environments across any mix of infrastructure, including on-prem, cloud, hybrid, and Kubernetes environments. Once SQL Server 2025 is GA, customers will be able to take this capability straight to their mission-critical production environments. This release removes longstanding roadblocks related to deploying SQL Server Availability Groups (AGs) in containers, maintaining HA for vector databases, and scaling securely with the latest platform innovations. It enables organizations to embrace modern workloads like Retrieval Augmented Generation (RAG) and operational AI with the assurance of continuous uptime, simplified failover, and seamless integration with their existing HA/DR strategies. In short, enterprises can now modernize faster, innovate more freely, and meet aggressive AI and digital transformation goals, while maintaining the rock-solid reliability their businesses demand.

Key updates include:

  • SQL Server 2025 Ready – Ensures compatibility with the AI-ready, mission-critical RDBMS reimagined for the cloud and fabric era
  • Vector Database HA Support – Unlocks reliable deployment of AI applications with embedded semantic search, vector indexes, and RAG pipelines
  • DH2i DxOperator Enhancements – One of the most efficient Kubernetes-native SQL Server Availability Group deployment methods – now fully aligned with SQL Server 2025’s peak performance ambitions
  • AG HA for Kubernetes – This solution provides fully automated failover for SQL Server AGs on Kubernetes

With AI workloads becoming the new norm and the push toward containerization and hybrid infrastructure accelerating, DxEnterprise’s new capabilities will empower organizations to not only keep up, but lead.

A Perspective On National Insider Threat Awareness Month

Posted in Commentary on September 10, 2025 by itnerd

This is National Insider Threat Awareness Month. Here’s what this is about:

First held in 2019, NITAM is an annual, month-long campaign during September that brings together thousands of U.S. security professionals and policy makers from government and industry, located in 25 countries around the globe, to educate government and industry about the risks posed by insider threats and the role of insider threat programs.

Craig Birch, Principal Technologist for Cayosoft has this perspective:

As we observe National Insider Threat Awareness Month, it’s crucial to recognize that insider threats extend far beyond malicious actors within our organizations. A significant and often overlooked category of insider risk emerges from the very people tasked with protecting our systems: IT administrators whose everyday actions can unintentionally create serious security and operational vulnerabilities.

There’s a real issue related to privileged group membership changes. Every day, administrative actions can unintentionally create serious security and operational risks. For example, an IT admin might temporarily disable multi-factor authentication (MFA) for a user under pressure to complete a critical task.

 If that exclusion is forgotten, the account becomes a weak point, vulnerable to phishing and potentially granting attackers access to sensitive applications.While not malicious in intent, these everyday admin changes are a form of insider-driven risk, arising not from attackers, but from human error, pressure, or incomplete understanding of the impact of a configuration change.

Similarly, small configuration changes in tools like Intune can have wide-ranging effects. Accidentally disabling encryption, for instance, could leave every corporate laptop unprotected, exposing the business to data theft if devices are lost or stolen.

These scenarios highlight how tenant-level settings and quick band-aid fixes, even when well-intentioned, can either: Weaken the security posture by introducing vulnerabilities, or create operational risks by over-restricting access and disrupting business processes.

To address this issue, organizations should implement continuous monitoring and automated controls around privileged group membership and administrative configuration changes. To reduce this risk, enterprises should:

  • Enforce policy guardrails to ensure critical security requirements cannot be disabled without approval.
  • Enable continuous visibility through deployment of monitoring and alerting tools that detect and report privileged group membership changes in real time.
  • Automate recovery through automated rollback or policy enforcement to rapidly restore secure defaults when unauthorized or risky changes occur.
  • Educate administrators through ongoing training to help IT staff understand the broader security implications of everyday admin actions.

Now is a good time to look at your environment and make sure that you don’t get pwned by an insider.

Plex Warns Users To Reset Their Passwords ASAP

Posted in Commentary with tags on September 10, 2025 by itnerd

I posted a guest post yesterday that media streaming platform Plex is warning customers to reset passwords after suffering a data breach in which a hacker was able to steal customer authentication data from one of its databases. Related to this, Martin Jartelius, CTO at Outpost24, provided the following comment:

“In situations like this, the safest approach is to automatically invalidate all user passwords and force a reset. While this prioritizes security and privacy over usability and business convenience, it’s often the best way to minimize risk.

The biggest concern is for people who reuse the same password across multiple sites. Even if Plex passwords were securely hashed, weak or reused credentials may eventually be cracked and then exploited in password spraying attacks elsewhere. Users should not only reset their Plex password but also change it anywhere else it may have been used.”

Consider this a today a today problem. If you have a Plex account, you should take measure to protect yourself now.

Wayne Memorial Hospital Pwned… A Year Ago

Posted in Commentary with tags on September 10, 2025 by itnerd

Georgia-based Wayne Memorial Hospital says it suffered a May 2024 data breach and has notified 163,440 people whose SSNs, credit cards and medical records were compromised.

Here’s the filing: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/a180a42c-3998-4208-a65a-aa095d7166fb.html

Lidia López, Senior Threat Intelligence Analyst at cybersecurity company Outpost24, commented:

“The hospital has not confirmed the threat actor’s identity, but Monti claimed responsibility and threatened to leak data by July 8, 2024. Monti is a ransomware group that emerged in mid-2022 and operates a double-extortion model: encrypting files while exfiltrating data for publication on its Data Leak Site (DLS). 

The ransomware group has primarily targeted government, transportation, technology, and healthcare sectors, with prior healthcare victims including Spine West and Excelsior Orthopaedics. Historically, Monti has abused edge vulnerabilities and VMware ESXi servers, reusing portions of Conti’s tooling before shifting to a newer Linux encryptor. The DLS is currently offline, with the last victim listed on May 8, 2025. Given the Wayne Memorial breach exposed Social Security numbers, payment cards, and medical records, patients now face long-term risks of identity theft, medical fraud, and targeted scams.”

This is another hack that won’t end well for their victims. There will be secondary attacks that will go after these victims, and it will cost those victims. This is not a good situation. What even worse is that this happened over a year ago. Which means that the bad guys have had a head start.

Retailers Face Rising Threat of AI-Powered Email Scams, New Report From Valimail Warns

Posted in Commentary with tags on September 10, 2025 by itnerd

As phishing scams become more sophisticated and harder to detect, a new analysis from Valimail, the leading provider of email authentication and anti-impersonation solutions, reveals that retail brands are among the top targets. They are increasingly attacked not only for fraud, but for brand impersonation campaigns that erode consumer trust and open the door to disinformation.

In the past year alone, Valimail blocked over 123 million suspicious emails, highlighting the scale of attempted brand abuse aimed at customers’ inboxes. These are no longer the clunky, obvious attacks of the past. They’re clean and well-crafted, designed to replicate the tone, design and cadence of trusted retail brands. The goal is often to get customers to click, share credentials or even unknowingly spread misinformation.

While many retailers have taken steps to implement email authentication protocols the report shows that significant gaps remain:

  • Even though 95% of retail domains have a DMARC record in place, many aren’t enforcing it. Nearly 30% still use a policy that effectively does nothing.
  • 6% don’t receive any reporting at all, leaving them blind to how their domains are being used or misused.
  • If new sender authentication requirements from Gmail, Yahoo! and Outlook were fully enforced today, 3 million retail emails would be blocked for failing compliance.
  • Despite these gaps, the report notes a 40% year over year increase in BMI adoption in the retail sector – a sign that more brands are looking to protect both security and visual trust in the inbox.

Valimail’s findings underscore a key shift: email security is no longer just about fraud prevention – it’s brand protection. In an era when AI can mimic tone, logos and layouts with alarming accuracy, authentication tools like DMARC and BMI are among the few tools that give brands control over who can send on their behalf.

Valimail offers free resources for organizations to check the protection status of their email domains through the Valimail Domain Checker, allows companies to explore and provides DMARC reporting visibility through its Monitor solution.

The full “2025 Winning (and Keeping) Shopper Trust – The Retail Email Threat You Can’t See” report can be accessed here.