Advertisement · 728 × 90

Posts by The IT Nerd

Sweden discloses failed 2025 cyberattack on thermal plant  During a press conference (link requires translation) yesterday, Sweden publicly attributed a failed cyberattack on a thermal heating plant in western Sweden in 2025 to a pro-Russian group with links to Russian intelligence and security services. The attack targeted energy infrastructure systems, though officials confirmed the attempt was unsuccessful and did not disrupt operations. Swedish Civil Defense Minister Carl-Oskar Bohlin said the incident involved efforts to carry out a destructive cyberattack against the facility, reflecting a shift from earlier activity such as denial-of-service attacks toward operations aimed at impacting industrial control systems.

Sweden discloses failed 2025 cyberattack on thermal plant 

During a press conference (link requires translation) yesterday, Sweden publicly attributed a failed cyberattack on a thermal heating plant in western Sweden in 2025 to a pro-Russian group with links to Russian intelligence and security…

10 hours ago 1 0 0 0
As AI-Powered Cybercrime Surges Past $10 Trillion, California Cyber Expert Unveils the Only Authentication System Built to Withstand It The global cybersecurity crisis has entered a new and far more dangerous phase. Artificial intelligence has handed attackers the tools to automate credential theft at unprecedented speed, and the identity systems billions of people rely on every day — passwords, biometrics, and passkeys — are falling one by one. Netlok, LLC, a California-based cybersecurity innovator, is answering with Photolok, the first and only patented identity platform engineered from the ground up to be AI-resilient.

As AI-Powered Cybercrime Surges Past $10 Trillion, California Cyber Expert Unveils the Only Authentication System Built to Withstand It

The global cybersecurity crisis has entered a new and far more dangerous phase. Artificial intelligence has handed attackers the tools to automate credential…

10 hours ago 0 0 0 0
Class of ‘26 is hard launching into the workforce and LinkedIn has the cheat sheet The Class of 2026 is graduating into one of the toughest entry-level job markets in years, where 'entry-level' roles increasingly require experience, AI is reshaping expectations, and traditional career paths feel less reliable than ever. For many new grads, the challenge isn't just competition. It's knowing where to look, and how to get started in a market that no longer follows a clear path.

Class of ‘26 is hard launching into the workforce and LinkedIn has the cheat sheet

The Class of 2026 is graduating into one of the toughest entry-level job markets in years, where 'entry-level' roles increasingly require experience, AI is reshaping expectations, and traditional career paths feel…

11 hours ago 0 0 0 0
AgingFly Malware used in attacks on Ukraine government and hospitals A new malware family named 'AgingFly' has been identified (the link requires you to translate into English) in attacks against Ukrainian governments and hospitals that steal authentication data from Chromium-based browsers and WhatsApp messenger. Commenting on this news is Ensar Seker, CISO at SOCRadar: "AgingFly reflects a continued shift toward credential-centric operations, where attackers prioritize access over disruption in the initial stages.

AgingFly Malware used in attacks on Ukraine government and hospitals

A new malware family named 'AgingFly' has been identified (the link requires you to translate into English) in attacks against Ukrainian governments and hospitals that steal authentication data from Chromium-based browsers and…

11 hours ago 0 0 0 0
EPA proposes $19M cybersecurity funding increase to protect U.S. water systems  The U.S. Environmental Protection Agency (EPA) has proposed $19.1 million in funding for its Information Security Program in fiscal year 2027, representing a $9.6 million increase over 2026 levels, to strengthen cybersecurity protections across water systems, support controls and secure implementation of emerging technologies, including AI. The proposal would expand the EPA's Drinking Water Infrastructure Resilience Grant Program to include dedicated cybersecurity funding, enabling water systems to upgrade infrastructure, improve defenses, and enhance operational resilience against cyber threats.

EPA proposes $19M cybersecurity funding increase to protect U.S. water systems 

The U.S. Environmental Protection Agency (EPA) has proposed $19.1 million in funding for its Information Security Program in fiscal year 2027, representing a $9.6 million increase over 2026 levels, to strengthen…

11 hours ago 0 1 0 0
McGraw Hill Pwned with 13.5 million accounts affected The ShinyHunters extortion group has leaked data from 13.5 million edtech giant McGraw Hill user accounts, stolen after breaching the company's Salesforce environment earlier this month. You can get more details here: Data breach at edtech giant McGraw Hill affects 13.5 million accounts Commenting on this news is Paul Bischoff, Consumer Privacy Advocate at Comparitech: "Most of the compromised data is contact info like addresses, phone numbers, and email addresses.

McGraw Hill Pwned with 13.5 million accounts affected

The ShinyHunters extortion group has leaked data from 13.5 million edtech giant McGraw Hill user accounts, stolen after breaching the company's Salesforce environment earlier this month. You can get more details here: Data breach at edtech…

13 hours ago 0 0 0 0
Fortra Launches Defense Tech Unit Fortra today announced the launch of its new Defense and Intelligence Unit (DIU), a dedicated business focused on delivering advanced, integrated cyber capabilities to critical infrastructure, defense, intelligence, and national security organizations around the world. Building on its strong momentum in this space, the DIU will operate with its own leadership and a dedicated operating model.  Leading the new unit is John Grancarich, appointed EVP, Head of Defense and Intelligence. 

Fortra Launches Defense Tech Unit

Fortra today announced the launch of its new Defense and Intelligence Unit (DIU), a dedicated business focused on delivering advanced, integrated cyber capabilities to critical infrastructure, defense, intelligence, and national security organizations around the…

15 hours ago 1 0 0 0
ESET Finds that SMBs Currently Leverage Cyber Insurance to Arm Against Attacks, Report Incidents and Improve Resilience ESET today released its 2026 SMB Cyber Readiness Index – North America edition. This new report surveyed hundreds of small and medium-sized businesses (SMBs) from across the United States and Canada to uncover new insights into their cyber resilience, incidents and reporting, perceived threats, and investments – while analyzing the current appetite for managed services, cyber insurance and AI-powered applications.

ESET Finds that SMBs Currently Leverage Cyber Insurance to Arm Against Attacks, Report Incidents and Improve Resilience

ESET today released its 2026 SMB Cyber Readiness Index – North America edition. This new report surveyed hundreds of small and medium-sized businesses (SMBs) from across the…

15 hours ago 1 0 0 0
Advertisement
Hacker Claims To Have Pwned Lacoste, Ralph Lauren, Canada Goose, and Carter’s A threat actor surfaced on a popular hacker forum, claiming to possess data belonging to Lacoste, Ralph Lauren, Canada Goose, and Carter's. The threat actor shared a small batch of sample images, roughly three to four per brand. The Cybernews research team has gone through the files provided. These screenshots appear to include employee details such as full names and work email addresses.

Hacker Claims To Have Pwned Lacoste, Ralph Lauren, Canada Goose, and Carter’s

A threat actor surfaced on a popular hacker forum, claiming to possess data belonging to Lacoste, Ralph Lauren, Canada Goose, and Carter's. The threat actor shared a small batch of sample images, roughly three to four…

15 hours ago 1 0 0 0
Exclaimer launches Workday integration Exclaimer today announced a new integration with Workday, enabling  organizations to use employee data from their HR system to automatically populate email signatures and video meeting themes. Workday counts more than 75 million users under contract globally, all of them sending emails with little to no direct connection between their HR record and their email signature. For many of these organizations, Workday is the primary system of record for employee information, from job titles to contact details.

Exclaimer launches Workday integration

Exclaimer today announced a new integration with Workday, enabling  organizations to use employee data from their HR system to automatically populate email signatures and video meeting themes. Workday counts more than 75 million users under contract globally,…

15 hours ago 1 0 0 0
Users Not Warned of Credential Theft in Claude Code, Gemini CLI, and GitHub Copilot Agents Three of the most widely deployed AI agents on GitHub Actions can be hijacked into leaking the host repository’s API keys and access tokens — using GitHub itself as the command-and-control channel. Anthropic's Claude Code Security Review, Google's Gemini CLI Action, and Microsoft's GitHub Copilot were targeted and disclosed the flaws but did not assigned CVEs or publish public advisories. …

Users Not Warned of Credential Theft in Claude Code, Gemini CLI, and GitHub Copilot Agents

Three of the most widely deployed AI agents on GitHub Actions can be hijacked into leaking the host repository’s API keys and access tokens — using GitHub itself as the command-and-control channel.…

17 hours ago 1 0 0 0
Certinia Launches Veda Certinia, today announced the launch of Veda: an enterprise-grade intelligent operations engine built to transform services organizations from reactive, manual workflows to autonomous professional services. As Certinia’s suite of AI specialist agents and intelligent actions, Veda delivers rules-bound, trusted and ROI-focused autonomous workflows, combining Certinia’s decades of institutional memory with advanced AI reasoning. Built alongside Certinia’sleading Professional Services (PS), Customer Success (CS), and Financial Management (FM) Cloud solutions, Veda’s flexibility allows it to be accessed through, and seamlessly integrated into, existing business workflows to drive immediate and measurable value.

Certinia Launches Veda

Certinia, today announced the launch of Veda: an enterprise-grade intelligent operations engine built to transform services organizations from reactive, manual workflows to autonomous professional services. As Certinia’s suite of AI specialist agents and intelligent actions,…

1 day ago 1 0 0 0
NotebookLM alternative kills source caps Recall, an AI encyclopedia that knows users better than the questions they ask, has launched version 2.0, an upgraded version of the original knowledge base. It’s a major improvement on NotebookLM: Recall automatically captures and connects everything the user consumes (think YouTube, podcasts, PDFs, TikToks, articles) to create a personal knowledge graph with no source caps. What’s new: Recall 2.0 also adds an agentic AI chat that queries both the open internet and a user's private knowledge base in a single conversation, with model choice among Claude, GPT, and Gemini.

NotebookLM alternative kills source caps

Recall, an AI encyclopedia that knows users better than the questions they ask, has launched version 2.0, an upgraded version of the original knowledge base. It’s a major improvement on NotebookLM: Recall automatically captures and connects everything the…

1 day ago 1 0 0 0
Cookeville Regional Medical Center warns 338,000 people of data breach Comparitech is reporting that Cookeville Regional Medical Center in TN yesterday confirmed it notified over 337K people of a July 2025 data breach that compromised names, SSNs, financial account numbers, medical treatment info, health insurance info, and much more. Commenting on this is Rebecca Moody, Head of Data Research at Comparitech: "This data breach becomes the eighth-largest on a US healthcare provider from 2025 (following a ransomware attack), and highlights how we often don't realize just how extensive these attacks are until months (or sometimes years) after the event.

Cookeville Regional Medical Center warns 338,000 people of data breach

Comparitech is reporting that Cookeville Regional Medical Center in TN yesterday confirmed it notified over 337K people of a July 2025 data breach that compromised names, SSNs, financial account numbers, medical treatment info,…

1 day ago 1 0 0 0
Sparq Designs Named Preferred Marketing Partner for Content Recovery Specialists Sparq Designs (Sparq) has been named the Official Preferred Marketing Partner of Content Recovery Specialists (CRS). The collaboration was announced at the CRS 2026 Annual Conference and establishes Sparq as the approved local marketing execution partner for CRS franchise owners nationwide. Through this affiliation, Sparq will support local marketing execution across CRS's network of franchise locations, working within the systems and infrastructure already in place at the corporate level.

Sparq Designs Named Preferred Marketing Partner for Content Recovery Specialists

Sparq Designs (Sparq) has been named the Official Preferred Marketing Partner of Content Recovery Specialists (CRS). The collaboration was announced at the CRS 2026 Annual Conference and establishes Sparq as the…

1 day ago 1 0 0 0
Auctor Raises $20M Led by Sequoia Capital to Build the AI System of Action for the Enterprise Software Implementation Market Hundreds of billions are spent on software implementation each year*, yet 50 percent of projects fail to meet deadlines, and one out of every six exceeds budgets by over 200 percent*. Today, Auctor emerges from stealth. It enables professional services teams and system integrators to deliver faster, more consistently, and smarter with every project. Auctor has raised a total of $20 million, including a Series A led by Sequoia Capital with participation from M12, Microsoft's Venture Fund, HubSpot Ventures, Workday Ventures, OneStream, Y Combinator, Tercera, and Dig Ventures.

Auctor Raises $20M Led by Sequoia Capital to Build the AI System of Action for the Enterprise Software Implementation Market

Hundreds of billions are spent on software implementation each year*, yet 50 percent of projects fail to meet deadlines, and one out of every six exceeds budgets by over 200…

1 day ago 1 0 0 0
Astrolight contributes laser communication terminal technology to ESA’s HydRON Element 3 mission led by prime contractor Kepler Communications Kepler Communications is leading a group of industry partners, including Astrolight, a Lithuanian space and defense technology company developing laser communication solutions for space, ground, and maritime applications. The companies have been awarded a multimillion-euro contract under the European Space Agency's (ESA) High-throughput Optical Network (HydRON) to develop HydRON's user-terminal segment, known as Element 3. HydRON is a project under ESA's Optical and Quantum Communications – Scylight programme, within the Agency's Advanced Research in Telecommunications Systems (ARTES).

Astrolight contributes laser communication terminal technology to ESA’s HydRON Element 3 mission led by prime contractor Kepler Communications

Kepler Communications is leading a group of industry partners, including Astrolight, a Lithuanian space and defense technology company developing laser…

1 day ago 1 0 0 0
Advertisement
Bitdefender Launches Powerful Email Security Solution for Businesses and MSPs Bitdefender today announced Bitdefender GravityZone Extended Email Security, unifying email and endpoint protection within a single platform. Built for organizations, managed service providers (MSPs) and their customers, it leverages an Integrated Cloud Email Security (ICES) approach to deliver continuous protection before and after delivery against modern email-borne threats including phishing, business email compromise (BEC), ransomware, impersonation, and insider-driven attacks.

Bitdefender Launches Powerful Email Security Solution for Businesses and MSPs

Bitdefender today announced Bitdefender GravityZone Extended Email Security, unifying email and endpoint protection within a single platform. Built for organizations, managed service providers (MSPs) and their customers,…

1 day ago 1 0 0 0
CSA issues “Building a Mythos-ready Security Program” “The ‘AI Vulnerability Storm’: Building a Mythos-ready Security Program” was just issued by the Cloud Security Alliance (CSA) CISO Community, co-authored with SANS, prompted, the OWASP Gen AI Security Project and several CISOs. (See direct links at bottom.) The Strategy Brief recognizes the increased likelihood of attackers discovering new vulnerabilities, creating new exploits, and using them in complex automated attacks at scale, offers advice for dealing with the spike in risk, and offers some immediate steps to ready organizations for the next waves of threats.

CSA issues “Building a Mythos-ready Security Program”

“The ‘AI Vulnerability Storm’: Building a Mythos-ready Security Program” was just issued by the Cloud Security Alliance (CSA) CISO Community, co-authored with SANS, prompted, the OWASP Gen AI Security Project and several CISOs. (See direct…

1 day ago 1 0 0 0
April Patch Tuesday Commentary From Fortra By Tyler Reguly, Associate Director, Security R&D, Fortra With 165 Microsoft CVEs and another 82 non-Microsoft CVEs combining for a total of 247 CVEs, I can't help but wonder who angered Microsoft this month. Here's hoping that admins everywhere are well hydrated with snacks available because I feel like this mess will take a few days to fully detangle. There are two vulnerabilities that Microsoft has called out as either exploited or disclosed.

April Patch Tuesday Commentary From Fortra

By Tyler Reguly, Associate Director, Security R&D, Fortra With 165 Microsoft CVEs and another 82 non-Microsoft CVEs combining for a total of 247 CVEs, I can't help but wonder who angered Microsoft this month. Here's hoping that admins everywhere are well…

2 days ago 0 0 0 0
Guardsquare to Address the Growing Piracy Risk Targeting Streaming Apps at NAB Show Las Vegas Guardsquare will present at NAB Show Las Vegas on Monday, April 20, in the Tech Chat Theater at the Las Vegas Convention Center. In a session titled "When Your Streaming App Is the Attack Surface: Stopping Piracy at the Source," Guardsquare will examine how attackers increasingly target mobile streaming applications to bypass traditional content protection controls. WHAT: Guardsquare Tech Chat Session at NAB Show Las Vegas…

Guardsquare to Address the Growing Piracy Risk Targeting Streaming Apps at NAB Show Las Vegas

Guardsquare will present at NAB Show Las Vegas on Monday, April 20, in the Tech Chat Theater at the Las Vegas Convention Center. In a session titled "When Your Streaming App Is the Attack Surface:…

2 days ago 0 0 0 0
Today is Identity Management Day Today is Identity Management Day and this year's theme is "Finding Identity: The Search for You, Me, and the Machines," reflecting the reality that machine and agentic identities now vastly outnumber human ones. Identity Management Day used to be a useful prompt to remind people to turn on two-factor authentication and audit their passwords. However, this year, the more urgent conversation is one most organizations haven't had yet: do you know who, or what, actually has access to your systems?

Today is Identity Management Day

Today is Identity Management Day and this year's theme is "Finding Identity: The Search for You, Me, and the Machines," reflecting the reality that machine and agentic identities now vastly outnumber human ones. Identity Management Day used to be a useful prompt to…

2 days ago 0 0 0 0
Orbital sets date for first test mission to put AI data centers in low Earth orbit The demand for AI compute is surging, but the bottleneck is no longer chips, it's the power required to run them. Orbital was founded on the belief that the only way to scale compute and unlock future progress on artificial intelligence is to stop competing for power on Earth and generate it in orbit. Today, the company announced funding from a16z Speedrun to support Orbital-1, the company's first test mission on its aim of deploying data centers in space.

Orbital sets date for first test mission to put AI data centers in low Earth orbit

The demand for AI compute is surging, but the bottleneck is no longer chips, it's the power required to run them. Orbital was founded on the belief that the only way to scale compute and unlock future progress on…

2 days ago 1 0 0 0
TrustCloud Launches Native ServiceNow Application to Deliver Enterprise-grade Continuous Control Monitoring for GRC and IRM customers TrustCloud today announced the TrustCloud Continuous Control Monitoring for the ServiceNow Store — the first AI native continuous control monitoring engine built and distributed natively through the ServiceNow Store. The application syncs validated, deterministic control signals directly with ServiceNow IRM (Integrated Risk Management), SecOps (Security Operations), Configuration Management Database (CMDB), and AI Control Tower, closing the signal quality gap that has long limited the ability for enterprise security teams to correlate security operations data with risk and GRC outcomes.

TrustCloud Launches Native ServiceNow Application to Deliver Enterprise-grade Continuous Control Monitoring for GRC and IRM customers

TrustCloud today announced the TrustCloud Continuous Control Monitoring for the ServiceNow Store — the first AI native continuous control monitoring engine built…

2 days ago 1 0 0 0
CData on Claude Managed Agents: Anthropic’s Bet on the Meta-Harness In a new blog post, Amit Naik, VP of Artificial Intelligence at CData, explores Anthropic's "Claude Managed Agents" and what the concept of a "meta-harness" reveals about the next phase of enterprise AI. While much of the market focus remains on model performance, Naik argues that the real shift is happening at the infrastructure layer that enables agents to operate reliably at scale.

CData on Claude Managed Agents: Anthropic’s Bet on the Meta-Harness

In a new blog post, Amit Naik, VP of Artificial Intelligence at CData, explores Anthropic's "Claude Managed Agents" and what the concept of a "meta-harness" reveals about the next phase of enterprise AI. While much of the market…

3 days ago 1 0 0 0
SOCRadar Puts Out A Research Report On The Stealer Ecosystem The stealer ecosystem has matured into a professionalized criminal economy that most organizations are simply not monitoring closely enough. While the industry fixates on household names like Lumma and RedLine, a growing class of lesser-known, actively deployed stealers, Void, a C++ infostealer that emerged in late 2025, Datura, Misericorde, Saturn, and others, are quietly collecting credentials, session cookies, and crypto wallet data from victims worldwide, feeding logs into underground markets that fuel ransomware, account takeovers, and business email compromise.

SOCRadar Puts Out A Research Report On The Stealer Ecosystem

The stealer ecosystem has matured into a professionalized criminal economy that most organizations are simply not monitoring closely enough. While the industry fixates on household names like Lumma and RedLine, a growing class of…

3 days ago 1 0 0 0
DataBee Posts Blog On Context Aware AI For AI Governance DataBee has a new blog post on context-aware AI for AI Governance that aims to help leaders to deliver defensible, audit-ready decisions in real time across expanding attack surfaces and rapidly evolving regulatory landscapes.  You can read the blog post here: Context-Aware AI for AI Governance, Threat Detection and Defensible Compliance Documentation

DataBee Posts Blog On Context Aware AI For AI Governance

DataBee has a new blog post on context-aware AI for AI Governance that aims to help leaders to deliver defensible, audit-ready decisions in real time across expanding attack surfaces and rapidly evolving regulatory landscapes.  You can read…

3 days ago 3 0 1 0
Advertisement
OpenText and S3NS Partner to Deliver European Sovereign Cloud Solutions with Google Cloud OpenText today announced a strategic partnership with S3NS, an alliance between Thales, a French leader in cybersecurity in Europe, and Google Cloud, to bring European organizations a trusted cloud platform based on Google Cloud technology, that meets the highest security and compliance criteria in France to offer strict data residency, regulatory compliance, and operational controls.  The partnership delivers a hybrid trusted cloud architecture for Europe out of France, enabling organizations to keep their most sensitive data workloads within a locally governed environment, while securely leveraging hyperscaler cloud services for non‑sensitive workloads, innovation, and scale.

OpenText and S3NS Partner to Deliver European Sovereign Cloud Solutions with Google Cloud

OpenText today announced a strategic partnership with S3NS, an alliance between Thales, a French leader in cybersecurity in Europe, and Google Cloud, to bring European organizations a trusted cloud platform…

3 days ago 1 0 0 0
OpenText Enterprise Data and AI Solutions to be Available on AWS European Sovereign Cloud OpenText announced today that it will make a number of its world-leading enterprise data and AI solutions available on the AWS European Sovereign Cloud, a new independent cloud for Europe.  By making its hybrid sovereign cloud offering available via the AWS European Sovereign Cloud, Canadian-based OpenText expands its ability to provide a hybrid sovereign cloud in Europe, giving customers the flexibility to leverage the cloud capabilities of AWS while keeping sensitive data and governance firmly anchored within European boundaries.

OpenText Enterprise Data and AI Solutions to be Available on AWS European Sovereign Cloud

OpenText announced today that it will make a number of its world-leading enterprise data and AI solutions available on the AWS European Sovereign Cloud, a new independent cloud for Europe.  By making its…

3 days ago 1 0 0 0
Flashpoint Discusses Tax Refund Fraud in 2026 There's a new blog post from Flashpoint that covers tax refund fraud in 2026 and how threat actors are weaponizing identity data, verification systems, and cash-out channels at scale. The piece breaks down how fraudsters move from sourcing "fullz" and clients to bypassing government identity verification, inflating refunds, and rapidly converting payouts into cash or cryptocurrency while using highly structured, repeatable workflows.

Flashpoint Discusses Tax Refund Fraud in 2026

There's a new blog post from Flashpoint that covers tax refund fraud in 2026 and how threat actors are weaponizing identity data, verification systems, and cash-out channels at scale. The piece breaks down how fraudsters move from sourcing "fullz" and…

6 days ago 0 0 0 0