A misconfigured database exposed 220 million traveler records tied to Vietnam

Posted in Commentary with tags on September 8, 2026 by itnerd

Security researchers found an exposed Elasticsearch cluster holding roughly 220.7 million passenger and crew records from a Vietnam-linked Advance Passenger Information System, spanning January 2017 through April 2026, reachable through a cloud-based path that accepted default credentials. Singapore Airlines’ security team helped coordinate the response, and the database was secured June 8, five days after researchers reported it, with no confirmed evidence anyone malicious got there first.

More details here: Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

Jason Brown, Director of Customer Advisory Counter Fraud Lead, iCOUNTER had this to say:

“A passport number tied to a name, date of birth, and travel history is a complete identity kit, not a fragment. Stolen card numbers get frozen the moment a bank flags fraud. A passport record doesn’t expire that way. It stays useful for building a synthetic identity or supporting document fraud years after the original trip happened, which is why nine years of records sitting in one place matters more than the headline number suggests. Fraud is only half of it. Nation-state actors use exactly this kind of collection to track individuals of interest and their movement for espionage and other targeting. Travel history at this depth is a pattern of life record, not just an identity record. 

What actually got this database exposed is almost mundane compared to what was in it. Direct access to the cluster was locked down, a second cloud path was not, and that one accepted default credentials. It is the same failure I chased for years on the law enforcement side, someone secures the route they built and never finds the one they inherited, and the route nobody documented is still running the password it shipped with. The good news here is narrower than the headlines suggest. 

Researchers reported and it was secured within five days. That is not the same as knowing nobody else got there first, as there were no server logs and scanning platforms had the host indexed as a database years before anyone reported it. But a system like this is not Vietnam’s exposure alone. Every airline that fed passenger data into it, and every country whose citizens transited through, inherited that risk the moment it was accessible, whether or not anyone malicious got there first. The response should be the same as if this had been confirmed stolen: assume the exposure window was real, and go check what else in your own vendor chain is reachable by a path nobody documented and a password nobody rotated.”

This would be a really good time to check to see if you have the same issues. Because you do not wish to be sitting on a ticking time bomb now would you.

FortiGate Post-Exploitation RAT, PivotC2 Spotted by SOCRadar

Posted in Commentary with tags on September 8, 2026 by itnerd

The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon. Successful exploitation delivers PivotC2, a Node.js RAT designed specifically as a FortiGate post-exploitation tool. PivotC2 supports features such as interactive shells, tunneling, network scanning, and configuration harvesting.

Based on the observed inline comments and usage guidance, the actors highly likely leveraged AI to develop the RAT. Active exploitation has been observed since at least July 2026 and is still ongoing. The threat actors targeted more than 30,000 IP addresses, leading to the exploitation and infection of 178 devices with PivotC2.

For full details, the analysis of this post-exploitation RAT can be read here: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/

August Ransomware Attacks Hit Record-Breaking High Says Comparitech

Posted in Commentary with tags on September 8, 2026 by itnerd

Comparitech researchers today published a study looking at August 2026 ransomware, finding that last month saw a record-breaking high for attacks at 32 attacks per day.

Key findings for August 2026

  • 997 attacks in total — 77 confirmed attacks (confirmed by the entity involved)
  • Of the 77 confirmed attacks:
    • 49 were on businesses
    • 18 were on government entities
    • 8 were on healthcare companies
    • 2 were on educational institutions
  • Of the 920 unconfirmed attacks*:
    • 812 were on businesses
    • 21 were on government entities
    • 61 were on healthcare companies
    • 22 were on educational institutions
  • The most prolific ransomware gangs were Qilin (157) and The Gentlemen (107)
  • Qilin had the most confirmed attacks (12), followed by The Gentlemen (8)
  • The US saw the most attacks (417), followed by Germany and Italy (48 each), the UK (36), and Canada (35)

Commenting on this study is Rebecca Moody, Head of Data Research at Comparitech

“Ransomware threats are escalating across most sectors and continue to have a devastating impact on those affected. One of August’s key attacks was on the government of Berlin, Germany. While the state government should be applauded for not meeting Rhysida’s ransom demand ($2.3M), the ransom looks set to be a drop in the ocean when compared to the costs the government is likely to face. Some recent statements suggest the computer rebuild could cost as much as €100 million (USD $116M) and the breach of over 1 million files is rumored to be the biggest state-level data breach in Germany to date.

Data relating to critical infrastructure is also believed to have been included in the Berlin breach. This, and the jump in attacks on utility companies, healthcare providers, manufacturers, and tech and finance companies, highlight how critical infrastructure remains a key target for hackers. By targeting these sectors, hackers are not only causing mass disruption by encrypting systems but they’re also gaining access to highly sensitive data, including personal data and information about critical systems and infrastructure.”

The full research can be read here: https://www.comparitech.com/news/ransomware-roundup-august-2026/

Focal AI Launches Agentic AI Platform for Canadian Wealth Management

Posted in Commentary with tags on September 8, 2026 by itnerd

Focal AI, the agentic AI platform purpose-built for Canadian financial advisors, today launched a set of AI agents that complete administrative work beyond meeting automation. The new Focal AI platform introduces new agentic AI capabilities which autonomously read and fill forms, read and draft emails, build client deliverables, and update your client data across advisor CRMs.

The launch addresses a critical bottleneck in Canadian wealth management. Advisors spend more than half their working time, over 20 hours a week, on non-revenue-generating administrative manual tasks across too many tools.

Focal AI is already used by advisors across major Canadian wealth networks like Financial Horizons and integrates with CRMs they rely on, including Equisoft, Maximizer, Laylah, Cloven, and more. The new agentic capabilities extend those integrations from moving information between systems to helping complete the workflows themselves.

Scale Advisor Productivity through Agentic Workflow Automation

Focal AI now expands beyond AI note-taking and meeting prep with agentic AI that automates back-office processes. The Focal AI agentic platform can embed natively inside broker-dealer infrastructure and the modern wealth firm technology stack:

  • Core Platform: Delivers time savings for advisors through AI note-taking, meeting preparation briefs, automated CRM syncing, and performance coaching.
  • Agentic AI Workflows: The Focal AI agent processes documents, emails, creates deliverables, and completes admin work advisors currently handle by hand, both inside of Focal and across other websites.

Key Capabilities of Focal’s Agentic AI

The admin overhead that fills an advisor’s evenings are now generated from the conversation itself:

  • Client-facing documents. Personalized follow-up emails, meeting recaps, discovery summaries, and client proposals, drafted in the advisor’s own voice and tone.
  • Email drafts and replies. Draft emails directly in your inbox, contextually from your email history with your clients.
  • Onboarding and account paperwork. KYC documentation, account opening forms, and custodial transition packages, can be uploaded and filled from client conversations directly.
  • Financial planning updates. More than 400 Conquest fields auto-filled after every conversation, covering family details, income, accounts, liabilities, expenses, and planning goals across retirement, education funding, and major purchases.
  • CRM and compliance records. Contact and household records, activity notes, task assignment, and audit-ready documentation pushed into the firm’s existing systems.
  • Edit outputs through chat. Chat with the Focal AI Agent to let it make direct edits to client presentations, notes, draft emails, and more.

In practice, that means advisors walk into every meeting fully prepped, with client history and open tasks already pulled together. Notes get captured and CRM records update automatically as they move from call to call. Work to be completed across client materials like proposals, and paperwork to be filled with client information are instant, instead of buried across five different systems, freeing up hours for the work to grow a practice.

Built for Canadian Wealth Management & Institutional Security

Focal AI is built on Microsoft Azure infrastructure in Canada, with client data remaining within Canadian data residency boundaries. Focal uses stateless AI architecture and does not use consumer AI application models such as ChatGPT or Claude. Focal also uses visible meeting participation rather than hidden botless transcription, helping firms maintain clear consent practices and giving advisors and clients transparency when AI is present in a conversation. The platform is SOC 2 Type II compliant and designed for the privacy, security and compliance requirements of Canadian financial institutions.

Focal AI’s Agentic platform is available today across Canada. To learn more, visit www.meetwithfocal.com

Nikon is Developing Firmware Version 2.00 for the Nikon ZR Full-Frame Sensor Camera 

Posted in Commentary with tags on September 8, 2026 by itnerd

Nikon Canada Inc. is pleased to announce the development of firmware version 2.00 for the Nikon ZR (released in October 2025), a full-frame sensor camera in the Z CINEMA series.

The following features are planned for inclusion in this firmware update, with the aim of further advancing creative capabilities and workflows for a broad range of users, from high-end filmmakers to content creators.

  • Support for Log3G10 and REDWideGamutRGB when recording in H.265 format, delivering compact file sizes with high colour-grading latitude.
  • A new option for selecting the level of [High ISO NR] available during H.265 Log recording, enabling image rendering tailored to the creator’s intent and the tone of the work.
  • Support for focus peaking display during recording in the R3D NE* format, enabling more precise focus confirmation.

Firmware version 2.00 is scheduled for release in 2026.

Nikon is also developing new firmware to support frequently requested features, including open gate recording and a desqueeze display for use with anamorphic lenses, with the goal of incorporating them in ZR firmware in 2027.

Additionally, RED is updating its remote-control applications, RED CONTROL and RED CONTROL PRO which will enable remote control capabilities for ZR.

Nikon and RED will continue to enhance its products through firmware updates that address user needs, while also contributing to the development of imaging culture in the field of cinema.

Nikon is Developing Nine Cinema Lenses in the NIKKOR Z Cinema T1.9 VV Series 

Posted in Commentary with tags on September 8, 2026 by itnerd

Nikon Canada Inc. is pleased to announce the development of the NIKKOR Z CINEMA T1.9 VV series of cinema lenses, designed for the cinema, high-end productions, and creators, aiming to provide them with high-quality solutions. The series will comprise nine lenses, including the NIKKOR Z CINEMA 50mm T1.9 VV.

The NIKKOR Z CINEMA T1.9 VV series will further enrich the visual expression of the NIKKOR Z CINEMA line through a new design philosophy that delivers both the rendering performance required by the cinema industry and the practicality needed in professional production environments. In addition, this will be the first NIKKOR lens series to feature an image circle large enough to cover the V-RAPTOR [X] VV sensor*, which is larger than a full frame sensor. The lenses will also feature a highly precise autofocus mechanism to support creators’ workflows.

Nikon will continue to contribute to the development of imaging culture that includes the field of cinema, with the hope of expanding possibilities for imaging expression. Filmmakers and content creators can expect great things from the new synergy between Nikon and RED.

Guest Post: iPhone users can remove 98% of pre-installed apps, Samsung users only 57%

Posted in Commentary with tags on September 8, 2026 by itnerd

The average smartphone user has 60 to 90 apps, using only ~10 daily and ~30 monthly. As a result, 60% to 70% of apps sit unused in the background, collecting personal data. New analysis by Surfshark revealed that bloatware begins with a brand-new phone, as manufacturers load a substantial number of pre-installed apps onto their devices before they reach the user. Samsung leads with 88 preloaded user-facing apps, followed by Google with 71, Xiaomi with 61, and Apple’s iPhone with 50. Interestingly, some of them include third-party apps like Facebook or Instagram that are privacy-invasive, especially when they are never used and just sit in the background.

“Data collection practices by popular applications, particularly social media platforms and chatbots, raise privacy concerns. While certain data points are necessary for basic operational functionality, entities may harvest information for targeted advertising or may even share it with undisclosed third parties. As a result, users are highly recommended to audit installed applications, review permissions, and remove or disable unused apps. Even never-used applications can gather personal data and link to your device,” explains Tomas Stamulis, Chief Security Officer at Surfshark.

Analysis shows that Samsung smartphones come preloaded with apps from Samsung, Google, mobile carriers, and third-party partners. In Bayton’s database of voluntarily synced Samsung smartphones, 88 user-facing apps were logged as preloaded, and 57% of those were marked by the Universal Debloater Alliance Next Generation project as safe to remove and not affecting the phone’s functionality. For example, the iPhone comes with up to 50 built-in apps, all developed by Apple, and EU users can remove up to 98% of them, compared to 88% in other countries.

35 out of 88 pre-installed Samsung apps are available on Google Play, collecting an average of 13 data types per app. This includes location-category data — such as approximate location (14 apps), precise location (12 apps), and physical addresses (11 apps) — among many other types of information.

Facebook and Instagram collect the most data among Samsung pre-installed apps, with each gathering 37 of 38 data types — accounting for 97% of the 38 data types listed on Google Play. Other third-party apps make the list too, including Netflix, Microsoft OneDrive, and Link to Windows, which collect 12, 15, and 6 data types, respectively.

In contrast, an evaluation of 47 of 50 pre-installed iOS apps available on the App Store collects an average of 8 data types. This includes location-category data, such as approximate location (19 apps), precise location (8 apps), or physical addresses (5 apps). It also includes behavioral data, user-generated content, and sensitive information.

Stamulis adds that linking your data to a single ecosystem may be convenient, but those seeking a more privacy-focused approach can minimize data collection by using third-party apps.

“Relying entirely on pre-installed applications can affect your privacy, as apps don’t always protect user data as you might expect. Shifting to third-party alternatives that are privacy-focused can help minimize data collection, limit overall exposure, and reduce unwanted targeted ads. It can also mitigate the risks associated with potential data breaches as your personal data is not stored in a single database.”

Google phones offer the least flexibility for removing pre-installed apps

Bayton’s database shows 71 preloaded user-facing apps on Google smartphones, with 38% identified as safe to remove by the Universal Debloater Alliance Next Generation project. The 40 apps on Google Play disclose an average of 13 data types collected per app, including physical addresses (15 apps), approximate location (14 apps), and precise location (11 apps).

Meanwhile, Xiaomi smartphones have 61 preloaded user-facing apps, with 57% marked safe to remove. There are 33 apps that can be found on Google Play and collect an average of 16 data types, including physical addresses (17 apps), approximate location (15 apps), and precise location (11 apps).

On both Google and Xiaomi smartphones, Google Gemini and the Google app are the most data-hungry, each collecting 29 of 38 data types. However, both manufacturers include apps that claim to collect no data: on Google devices, these include Password Manager, Pixel Screenshots, and Pixel Studio, and on Xiaomi devices – Weather, File Manager, and Mi Browser.

Lightsage raises $4M to build the growth stack for internet’software’s newest customer: AI agents

Posted in Commentary with tags on September 8, 2026 by itnerd

The next software customer might never visit a homepage or sit through a product demo. Coding agents like Claude Code, Codex and Cursor can already discover products, choose libraries, install SDKs and call APIs on a user’s behalf. Increasingly, software has to win over machines that can go from finding a product to using it.

Lightsage was built for that paradigm shift. Today, the San Francisco startup announced $4 million in funding led by Nexus Venture Partners, to build the infrastructure for what it calls Agent-Led Growth, or ALG. The round also includes backing from operators across the developer and AI ecosystem, including former Salesforce CTO Steven Tamm, Postman CEO Abhinav Asthana, Apollo CEO Matt Curl, DocuSign President and GM of Growth Robert Chatwani, former GitLab Head of Growth Hila, Resend CEO Zeno, Firecrawl Co-founder Eric, Daytona CEO Ivan, Tinyfish COO Shuhao, and Adam Frankl among others.

From product-led growth to agent-led growth

Software companies have spent decades learning how to convert humans. AI agents are creating a new buyer. A coding agent can now choose a database, API or authentication provider, then start integrating it without ever visiting a vendor’s website. That means visibility alone is no longer enough. The agent still has to understand the docs, choose the right SDK, authenticate and get the product working.

This is where existing GEO (Generative Engine Optimization) products fall short, and where LightSage closes the loop: ensuring agents can actually use and pay for the product.

How Lightsage works

Lightsage gives software companies a way to see their product through an agent’s eyes. The platform runs large-scale simulations across answer engines and coding agents, measuring where a company appears against competitors and what happens next. Agents are given real tasks that require them to navigate documentation, choose the right tooling and successfully use APIs, SDKs, CLIs, MCP servers and Agent Skills.

When they fail, Lightsage pinpoints why. The break might be discoverability, confusing documentation, authentication, an API endpoint, an SDK implementation or an incompatible MCP server. Teams can fix the issue, rerun the workflow and measure whether agent success improves.

Lightsage also provides analytics on real agent traffic: when agents visit a company’s website or docs, what they interact with and whether those journeys turn into product usage. The longer-term goal is to close the loop entirely, feeding those insights back into development and deployment workflows so products continuously improve for agents.

The platform currenty supports Claude Code, Codex, Cursor, GitHub Copilot, OpenCode and a growing range of other coding agents.

Early traction 

Lightsage is starting with developer software, where agent behavior is already easy to observe. Customers including Firecrawl, Reducto, Daytona, Rime and Tinyfish use Lightsage to understand why agents choose certain products, where integrations break and how key workflows perform after product or documentation changes.

A typical use case starts with a coding agent repeatedly recommending a competitor. Lightsage reproduces the same task across products and agents to isolate the cause: visibility, documentation or the product experience itself.

A new growth discipline for software

Agent-Led Growth creates questions traditional analytics cannot answer. Human acquisition can be traced through searches, clicks and sign-ups. Agents may discover, evaluate and use a product without following any of those paths, making their traffic and revenue much harder to attribute.

Their behavior is also less predictable. Different coding agents can approach the same product in different ways, and those patterns shift as models and interfaces change. A workflow that works in one agent may fail in another.

Lightsage believes Agent Experience — how easily AI agents can understand, use and pay for a product — will become a core part of Agent-Led Growth, much as Developer Experience became critical to winning human developers. 

What’s next

Lightsage will use this funding to deepen its agent evaluation, analytics, attribution and optimization capabilities across APIs, SDKs, CLIs, MCP servers and agent skills. Developer tools are just the starting point: as agents begin acting directly across B2B software, infrastructure and payments, Lightsage wants to become the infrastructure companies use to understand, improve and ultimately win the agent channel. To build it, Lightsage is growing its team across technical and commercial roles, and welcomes candidates who want to help define the agent channel at lightsage.com/careers.

The CISA cuts critical infrastructure security services, concerns grow over the shrinking agency 

Posted in Commentary with tags on September 5, 2026 by itnerd

The CISA is ending six free cybersecurity assessment programs used by critical infrastructure operators to identify weaknesses in their defenses against ransomware, supply-chain attacks and other cyber threats.

The cuts include Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys.

The assessments provided hands-on assistance from CISA regional advisers to organizations including water utilities, hospitals, local governments and other operators that may not have the resources to pay for comparable private-sector security reviews. CISA says it is retiring the programs to reduce redundancy and will instead direct organizations toward its Cross-Sector Cybersecurity Performance Goals.

The move comes amid broader concerns about CISA’s ability to protect U.S. critical infrastructure following significant reductions in its workforce and budget. The agency has lost roughly one-third of its workforce, while its 2026 budget was cut by approximately $300 million.

Denis Calderone, CTO, Suzu Labs:

“My apologies to those I told to leverage these free resources recently. We’ve been pointing to those how lacked the bigger budgets to the CISA’s assessment programs. All six programs are gone now. The replacement is a self-service questionnaire that the people who built the original tools say doesn’t do the same job.

“The timing here stinks. CISA is weeks away from finalizing CIRCIA, which will require critical infrastructure operators to report cyber incidents within 72 hours and ransomware payments within 24 hours, and this comes just as they take away the testing tools. But, To be fair, we don’t really know how widely adopted these programs were in the first place. The scope is huge with 50,000 small water utilities alone, we doubt that CISA’s regional staff was ever going to reach all of them, and there’s no public data showing how many operators actually used the assessments or what the measurable impact was.

“We’ve been worried about CISA’s capacity all year. The agency lost roughly a third of its workforce over the last 18 months. When DHS announced plans to hire 600 new staff and CISA started extending offers for 329 mission-critical positions, it felt like maybe the rebuilding was starting. But as of late August, it’s unclear how many of those hires have actually come on board, and now we’re watching assessment programs get cut instead. This during a year where critical infrastructure attacks are continuing to increase.

“CSET is open source and older versions on GitHub still include all six retired assessment modules. CSET measures where you actually stand against specific security standards. The CPGs that CISA is pointing everyone toward are a prioritization framework that helps you figure out where to focus. They’re complementary tools, not interchangeable ones. Use CSET to diagnose your current state, then use the CPGs to prioritize what to fix first. What you won’t get anymore is a CISA regional adviser helping you interpret the results, but using both tools together is still better than using either one alone. Several states are also stepping up direct cybersecurity support for local operators. And if you’re a water utility, keep an eye on Project Watershed 250. It just launched in Texas with free vulnerability assessments and red-teaming, and it’s supposed to expand nationally.”

John Strand, Owner, Black Hills Information Security, Inc.:

“Do the people making these decisions have any access to the news?

“Right now, our critical infrastructure is under attack at a level we simply have not seen before. Water systems, energy, telecommunications, municipalities, and other critical infrastructure are actively being targeted. CISA itself warned in July about ongoing Iranian-affiliated attacks against operational technology and PLCs across multiple U.S. critical infrastructure sectors.

“And this is the moment we decide to start cutting the programs designed to help these organizations defend themselves?

“CISA is eliminating six free cybersecurity assessment programs used by critical infrastructure organizations, including ransomware readiness, cyber resilience, incident management, and infrastructure assessments. Many of the organizations relying on these programs are exactly the organizations that do not have the money or personnel to replace them with commercial services.

“This is crazy.

“We should be dramatically increasing the resources available to critical infrastructure organizations right now. We should be expanding free assessments, threat intelligence, training, and technical assistance, especially for small municipalities, rural hospitals, water systems, and utilities that simply cannot afford large cybersecurity programs.

“Instead, we’re pulling resources away from them while the attacks are increasing.”

The White House and the US government are failing US citizens when the CISA is needed the most. And they will likely come to the conclusion after they get pwned by everyone rather than taking proactive measures to stop that from happening.

OpenAI commits $1B to AI cyber defense for critical infrastructure 

Posted in Commentary with tags on September 5, 2026 by itnerd

OpenAI has committed $1 billion in subsidized access to its AI cybersecurity tools, training and technical support through its new Daybreak for Frontline Defenders initiative, targeting organizations that protect critical infrastructure and essential services.

The initiative will prioritize resource-constrained organizations including water and wastewater systems, electric grid operators, state and local governments, community and regional banks, nonprofits and open-source maintainers. OpenAI says the $1 billion commitment is targeted to be consumed over the next six months.

OpenAI is also launching a public-sector and water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC) that will pair Daybreak access with guided training and hands-on assistance for an initial group of public-sector and water-system defenders.

The initiative comes as critical infrastructure operators face growing cybersecurity threats while many smaller organizations continue to operate with limited staff, budgets and specialized security expertise.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“OpenAI’s Daybreak for Frontline Defenders commits $1 billion in subsidized access to its cyber models for water utilities, electric grid operators, and other under-resourced critical service providers. I like the direction. I’m skeptical about the bottleneck it targets.

“I’ve been saying since GPT-5.6-Cyber launched that AI is moving the bottleneck from vulnerability discovery to remediation. Small water systems and municipal networks already know they’re running outdated systems with known vulnerabilities. They lack the engineering staff to fix what they find, the governance to deploy changes safely, and the test environments to validate fixes before production.

“Greg Brockman demoed Codex on his personal website at the summit. A personal website isn’t a water treatment Supervisory Control and Data Acquisition (SCADA) system, where a configuration change that makes security sense can break the physical process that keeps water flowing. Without engineers who understand the plant, AI becomes a force accelerant in the wrong direction, generating fixes faster than understaffed teams can review them.

“The Multi-State Information Sharing and Analysis Center (MS-ISAC) training pilot matters more than the $1 billion headline. If that training doesn’t scale alongside the credits, these organizations end up with an AI generating recommendations and nobody qualified to tell the good fixes from the dangerous ones.”

John Strand, Owner, Black Hills Information Security, Inc.:

“In all seriousness, I think it’s fantastic that they’re putting some money toward this and actually trying to get these organizations the help they desperately need. There are a lot of organizations out there that simply don’t have the budget or the resources to do this properly, so getting them some assistance is absolutely a good thing.

“But there’s also the humorous flip side of this. This is basically how you get people hooked on crack. You give them a sample. You get them set up. You show them how good it is. And then suddenly they’re hooked for life.”

Joshua Marpet, Senior Product Security Consultant, Finite State:

“OpenAI is jumping on the bandwagon to help utilities. Considering that there are over 150k water utilities in this country, and there are only several hundred in the Water-ISAC (Information Sharing and Analysis Center), theres a huge gap in the cybersecurity preparedness posture for those utilities.

“Programs like Josh Corman’s Undisruptable27, the new Texas Water coalition, ValueChainRisk’s Utility Kit, and others are all working to help these utilities, with free or discounted products, services, and guidance. In other words, this is a wonderful project for OpenAI to do, but since it’s partly their fault? Probably good optics as well.

“Understanding your cybersecurity and physical security posture is important. For small water utilities, often mom and pop shops with little time, effort, or money to spare for such items, finding and utilizing these free or discounted resources is essential to their survival on the increasingly hostile world stage.”

I guess that OpenAI needs some good news after getting hit with the fact that AI bots like the ones that hit Hugging Face are more dangerous than thought. But whatever…..