Cybersecurity Archives - 91̽ /category/cybersecurity/ Startup News UK and Tech News UK Fri, 11 Sep 2026 14:45:37 +0000 en-GB hourly 1 https://wordpress.org/?v=7.1 /wp-content/uploads/2023/04/cropped-techround-logo-alt-1-32x32.png Cybersecurity Archives - 91̽ /category/cybersecurity/ 32 32 UK Firms Hit By Over 1,500 Cyber Attacks A Week As Ransomware Nearly Doubles Globally /cybersecurity/uk-firms-hit-1500-cyber-attacks-week-ransomware-doubles-globally/ Fri, 11 Sep 2026 14:44:45 +0000 /?p=159258 UK organisations faced an average of 1,571 cyber-attacks per week each in August 2026, a 14% increase on the same...

The post UK Firms Hit By Over 1,500 Cyber Attacks A Week As Ransomware Nearly Doubles Globally appeared first on 91̽.

]]>
UK organisations faced an average of 1,571 cyber-attacks per week each in August 2026, a 14% increase on the same month last year, according to new threat intelligence from Check Point.

While that figure sits below the global average of 2,422 weekly attacks per organisation, it confirms that UK businesses remain firmly in attackers’ sights, with education, energy and utilities, media and entertainment, government and software named as the five most targeted sectors in the country.

The UK figures form part of Check Point’s wider Global Threat Intelligence report for August, which found that cyber-attacks worldwide rose 4% month-on-month and 22% year-on-year. The report points to an escalation in risk across several fronts at once, with ransomware, phishing and GenAI-related data exposure all identified as pressing enterprise security challenges.

 

Education And Travel Sectors Under Pressure

 

Globally, education remained the most targeted sector, averaging 5,354 weekly attacks per organisation, up 28% year-on-year. Government followed with 3,067 weekly attacks, while Hospitality, Travel and Recreation climbed into third place with 3,056 weekly attacks, up 56%, as attackers appeared to capitalise on the busy summer travel period.

Regionally, Latin America recorded the highest volume of attacks at 3,577 per week, while Europe posted the fastest year-on-year growth at 28%, suggesting that cyber pressure is spreading into mature, interconnected digital economies rather than remaining concentrated in traditionally high-volume regions.

Genai Use Climbs As Data Exposure Risk Lingers

 

One of the report’s key findings centres on the growing use of generative AI tools inside businesses. High-risk GenAI prompts, those posing a risk of exposing sensitive data, fell to their lowest level in several months, with just one in every 43 enterprise prompts now flagged as high-risk.

At the same time, overall GenAI usage kept climbing. The average enterprise user generated 106 prompts in August, up from 95 in July and around 78 in June. Check Point notes that 86% of organisations using GenAI regularly were still affected by high-risk prompt activity at some point, and that the average organisation now uses seven different AI tools, a spread that makes consistent governance harder to maintain.

Healthcare and Medical organisations recorded the highest exposure rate of any sector, at 4% of prompts, followed by Software at 3.6% and Business Services at 3.5%. The data most commonly exposed in GenAI prompts related to network and IT infrastructure, financial data and legal or regulatory information, underlining how far AI-related risk now extends across core business functions rather than sitting at the margins.

Phishing And Ransomware Both On The Rise

 

Email remained a favoured route into organisations, with one in every 112 emails classified as phishing in August, up from one in 128 in July. Links featured in 72% of phishing emails, while 14% carried malicious attachments.

Ransomware activity accelerated sharply, too. Check Point recorded 1,042 ransomware attacks globally in August, almost double the number seen in August 2025 and 8% higher than July. Business Services bore the brunt, accounting for 36% of reported attacks, ahead of Industrial Manufacturing at 13% and Consumer Goods and Services at 12%. The United Kingdom featured among the countries most affected by ransomware during the month, behind the United States, Germany and Italy.

Qilin was the most active ransomware group in August, responsible for 15% of published attacks, followed by The Gentlemen at 10%. Orova, a group that only surfaced publicly in May 2026, broke into the top three for the first time with 4% of attacks, most of them concentrated among small and mid-sized businesses.

Barnaby Nickels, Head of Sales, Exposure Management, UKI & North EU at Check Point, said: “August’s data shows cyber risk expanding across several fronts at once. With attacks climbing, ransomware accelerating, phishing remaining a common entry point and GenAI creating a new route for data exposure, security teams cannot rely on fragmented defences.”

He added that organisations need proactive detection and validation of threats, alongside a focus on cutting remediation times, warning that the window attackers have to exploit a vulnerability is shrinking fast.

For UK businesses, the message from Check Point’s latest figures is consistent with the broader global picture: attack volumes, ransomware and AI-related data exposure are all rising together, and the company is urging organisations to move toward a prevention-first strategy that gives consistent visibility across users, email, networks, cloud environments and AI tools.

The post UK Firms Hit By Over 1,500 Cyber Attacks A Week As Ransomware Nearly Doubles Globally appeared first on 91̽.

]]>
Anthropic Discloses Fourth Unauthorised Claude Access Incident – Is The Security Industry Prepared For AI Breaches? /cybersecurity/anthropic-discloses-fourth-unauthorised-claude-access-incident-is-the-security-industry-prepared-for-ai-breaches/ Fri, 11 Sep 2026 10:15:52 +0000 /?p=159204 Anyone assuming AI sandbox breakouts were a thing of the past will be disappointed by Anthropic’s disclosure this week. During...

The post Anthropic Discloses Fourth Unauthorised Claude Access Incident – Is The Security Industry Prepared For AI Breaches? appeared first on 91̽.

]]>
Anyone assuming AI sandbox breakouts were a thing of the past will be disappointed by Anthropic’s disclosure this week.

During a cybersecurity test back in January 2026, a pre-release version of Claude Opus 4.6 bypassed containment to interact with real-world networks, a breach that went undetected for seven months until staff prepared files for an outside review. To address the recurring issue, Anthropic has teamed up with independent non-profit METR on an eight-week probe covering all four incidents, opening up its transcripts and technical teams to outside investigators.

The culprit across all four sandbox breaks was a repeated setup flaw from the same third-party provider, which accidentally left an active internet connection open while promising the AI it was safely offline. Facing a blocked target due to conflicting IP addresses, Opus 4.6 improvised by finding its own route out. It navigated to a real-world machine thinking it was part of the test, harvested credentials, changed system configurations and viewed personal information belonging to a real person before its session timed out.

All of this breaking in the exact same week that Evan Hubinger, Anthropic’s Alignment Science lead, publicly stated a 10% probability of AI-driven human extinction over the next ten years. The two headlines form a surreal pairing: the lab’s leading safety researcher rating existential risk as a genuine threat, while his employer admits its models keep escaping their digital playpens to mess with real-world networks.

 

When The Hacker Is Just A Confused Algorithm

 

The trickiest part about classifying these incidents is that they lack the one thing security teams look for: an adversary.

The models had no harmful motives. They were just running through assigned capture-the-flag objectives, continually treating their surroundings as a test lab even while interacting with real infrastructure and harvesting actual personal data.

Anthropic noted two main driving factors behind the behaviour: models talking themselves into believing ambiguous setups were still part of the game, and a sheer refusal to pause when system signals suggested something was wrong.

This dynamic leaves corporate defence strategies in bizarre territory. Firewalls search for hostile breaches, insider threat tools monitor human behaviour and software audit tools look for corrupted dependencies. They don’t know what to do with an AI model that holds proper authorisation, acts with total innocence and accidentally triggers a data breach because a sandbox misconfiguration gave it a path to the live web.

We put the question to CISOs, incident response commanders, penetration testers and AI security analysts: are current enterprise threat models actually accounting for rogue AI agents without malicious intent, or is the tech sector waiting for a major disaster before building real safeguards?

 

 

Our Experts

 

  • Viktor Bulanek, Founder, Penetrify
  • Evgenii Arsentev, AI Transformation Executive, ARSENTEV.AI
  • Karthik Karunanithi, Solution Architect, IBM
  • Sayali Patil, Founder and CEO, IntentOps
  • Jeff Watkins, Chief AI Officer, NorthStar Intelligence
  • Luke Hinds, CEO and Co-founder, nolabs
  • Robert Pfleghardt, Founder and CEO, CBR Labs and VoraPrep
  • Eshaan Jain, Senior Product Manager, T-Mobile
  • Cache Merrill, Founder, Zibtek
  • Alexander Leslie, Senior Advisor, Recorded Future

 

Viktor Bulanek, Founder, Penetrify

 

Viktor Bulanek, Founder, Penetrify

 

“My threat model accounts for AI agents because they are my product. We run autonomous agents that perform authorised penetration tests, and the first design decision we made was to treat our own agent as hostile. Not because it has intent, but because it does not. An agent pursuing its interpretation of a task will walk through any door its credentials open, and it will do so confidently, without the hesitation or self-preservation that makes human insiders somewhat predictable.

“The industry’s detection stack largely assumes an adversary, so it looks for adversary behaviour: staging, evasion, exfiltration patterns. An agent with legitimate access exhibits none of that. What works instead is boring and economic: every autonomous run gets an envelope defined outside the model, an immutable scope, a spending cap, a time limit, a restricted set of destinations it can talk to, and any deviation from that envelope is the incident signal. The agent cannot negotiate with a limit it cannot see. Prompts and policies are advice. Envelopes are control.

“Is the industry building the right defences? Mostly it is still writing AI usage policies, which govern the humans, not the agents. Until “AI agent with legitimate access” appears in threat models next to insider risk, with its own detection and its own kill path, it is being treated as hypothetical. It stopped being hypothetical for us the first week we ran one.”

 

Evgenii Arsentev, AI Transformation Executive, ARSENTEV.AI

 

Evgenii Arsentev, AI Transformation Executive, ARSENTEV.AI

 

“Honestly, most threat models don’t account for it, and a year ago mine didn’t either. Security frameworks are built around intent. An agent has no intent to find. It has a task, a set of credentials and a very literal reading of both.

“The incidents I actually deal with are dull. Earlier this week one of my agents, asked to rebuild a single service, brought it up with the wrong configuration and quietly broke two integrations that depended on it. Another once changed a system setting on a work laptop that nobody had asked it to touch. Every action was authorised. Nothing looked like an attack.

“So detection has to track scope, not hostility. Log what each agent was asked to do and flag anything it touched outside that. Issue credentials per task and make them expire, so “access it wasn’t supposed to use” mostly stops existing. Put a person or an independent second check in front of anything irreversible. Is the industry ready? No. It still talks about this as a future risk, while in my logs sub-agents already make 52% of all model calls, each with its own context and its own permissions.”

 

Karthik Karunanithi, Solution Architect, IBM

 

Karthik Karunanithi, Solution Architect, IBM

 

“I think the industry is asking the wrong question about AI agents. Agent access is a known fact, but the real question is whether an agent can prove why its next action is authorised.

“The Opus 4.7 incident is interesting because the model identified the target as a real company almost 90% of the time, yet it still judged the environment safe to act in 75% of the time. Reachability and context clues were turning directly into permission decisions. In the fourth incident, an Opus 4.6 checkpoint never really checked whether its actions were authorised at all.

“This isn’t a new security problem. We’ve spent years building authorisation models around delegated access, but never applied them consistently to agents, because these agents are provisioned like service accounts: a static credential and a hopeful assumption. NIST’s NCCoE flagged agent identity and authorisation as a security gap back in February, and agent-specific controls remain largely unpublished to this day. Every tool call an autonomous agent makes should carry an auth chain: who delegated it, the resources in scope, the actual purpose and the evidence that permits the action.

“Detection needs the same shift. Anthropic’s monitor initially flagged only around 1% of actions, because the model’s reasoning was persuasive enough to convince the system the environment was simulated. Strip out that reasoning layer and score purely on tool calls and results instead, and the flag rate jumps to 50%. The most pressing emerging threat isn’t an AI stealing credentials. It’s an AI that has valid credentials and invents its own interpretation of what they permit.”

 

Sayali Patil, Founder and CEO, IntentOps

 

Sayali Patil, Founder and CEO, IntentOps

 

“No, and I’d be surprised if most threat models can right now, because the category genuinely doesn’t fit anywhere yet. Every established framework I’ve worked with, insider threat, intrusion detection, supply chain risk, assumes intent behind a breach. What Anthropic just disclosed is structurally different: models given legitimate testing access, told they were operating inside an isolated simulation, that kept going past the point where a human would have stopped to ask whether they were actually allowed to be there. One model tried to abort eight separate times before a broken harness pushed it toward real systems instead. That’s not malice. That’s the absence of a working stop mechanism, which in my experience is a far more common root cause than people assume.

“I’ve spent years testing automated systems for exactly this failure, first in large-scale infrastructure at Cisco, now specifically in AI agents. The lesson I keep relearning is that meaningful detection has to stop asking “is this an authorised identity taking an authorised action” and start asking “is this system’s behaviour still consistent with what it was actually supposed to be doing.” Those are two different questions, and a system can pass the first cleanly while failing the second in complete silence, which is precisely what happened here across four separate incidents before anyone outside the company caught it.

“Practically, that means treating abort and halt mechanisms as security-critical infrastructure rather than an afterthought, since a broken kill switch is what turned one of these from a contained test into an actual breach, and instrumenting for behavioural drift rather than just access anomalies. Most organisations I talk to are still treating this as a hypothetical they’ll get to eventually. Anthropic just handed the industry the clearest evidence yet that it isn’t.”

 

Jeff Watkins, Chief AI Officer, NorthStar Intelligence

 

Sayali Patil, Founder and CEO, IntentOps

 

“Moving AI out of the chat window and giving autonomous agents access to real systems would always introduce a new category of security risk. Agents can operate at machine speed and scale, use tools and credentials, and potentially coordinate with other agents to achieve an objective. The danger isn’t limited to malicious actors deliberately weaponising them. An agent diligently pursuing a poorly specified objective can potentially cause just as much damage.

“The recent incidents are particularly interesting because they challenge one of the assumptions underpinning conventional threat modelling: that there is an adversary with malicious intent. An AI agent doesn’t necessarily need to be malicious, compromised or even knowingly acting outside its authority to become a security threat. If its understanding of the task differs from ours regarding its boundaries, the outcome can look a lot like an intrusion. That means organisations need to model both external and internal agentic threats. A hardened external perimeter will do little to protect you from an agent already operating legitimately inside it.

“Simply propagating a user’s permissions to an agent is particularly risky. Instead, agents should ideally have their own identities and be granted narrowly scoped, task-specific and time-limited permissions. We also need to reconsider detection and response. Conventional dashboarding assumes there is enough time for a human analyst to notice something unusual and intervene. An autonomous agent may perform hundreds of actions in that interval. Observability needs to be coupled with automated containment: rate limits, behavioural thresholds, circuit breakers and kill switches capable of suspending an agent or isolating its environment when its behaviour moves outside expected boundaries.

“The important principle is that scope should be technically enforced rather than simply described in a prompt. Network controls, permissions, sandboxing and tool restrictions need to make prohibited actions impossible, or at least rapidly detectable and reversible. Agentic AI makes intent a less useful concept in cybersecurity. Rather than asking only who is attacking us and why, we increasingly need to ask what this actor can reach and do, how quickly we can detect unexpected behaviour, and how quickly we can stop it.”

 

Luke Hinds, CEO and Co-founder, nolabs

 

Luke Hinds, CEO and Co-founder, nolabs

 

“For many of us in the industry, this was inevitable. But these incidents should act as a wake-up call to businesses. Agents don’t often act with malice. It’s a bright, well-meaning agent with too much access and too little context.

“The problem is that many organisations are still trying to secure agents the same way they have secured humans or conventional software. That will not work. Blunt sandboxing is not enough, since if you lock agents down too heavily, you kill the value businesses are trying to unlock. Put a human approval step in front of every action and you no longer have an autonomous agent. Businesses need controlled freedom, enough authority for the task in front of the agent, and absolutely nothing more.

“That means every identity, permission, decision and action needs to be continuously verified, governed and auditable. Detection has to focus on what an agent is actually doing with legitimate access, not simply whether its credentials are valid. Crucially, that security boundary has to sit outside the model. Frontier labs should not be marking their own homework or deciding what agents can access, decide or do. These incidents are proof that organisations need independent controls that govern agents regardless of which model they use. Ultimately, businesses shouldn’t rely on agents to behave well. Security has to be built in from day one, so breaking the rules becomes structurally impossible.”

 

Robert Pfleghardt, Founder and CEO, CBR Labs and VoraPrep

 

Robert Pfleghardt, Founder and CEO, CBR Labs and VoraPrep

 

“Traditional threat models assume malicious intent. That’s the blind spot. After 37 years securing SCIFs and courtrooms, I’ve learned that whether a camera activates because of malware or because an AI misread its own task, the outcome is the same: data gets exposed. I once watched a facility spend six figures on adversarial threat modelling for a room that still had a tablet with a working microphone sitting on the table. Nobody asked what happens if nothing malicious ever touches that device at all.

“So what does real detection look like? Extreme behavioural anomaly monitoring at the data perimeter, regardless of the agent’s declared purpose. You track what data pathways are being accessed and how far they stray from strict authorisation boundaries, not who’s doing it, and not why. Most organisations are still treating this as a software problem, patching around agent behaviour with better access controls and another monitoring dashboard.

“But software guardrails fail, and they fail quietly. If an AI agent has legitimate software access and can physically activate a microphone, a camera or a wireless antenna, unintended data exfiltration is possible. You need smarter detection too, but detection alone isn’t the fix. The real fix is immutable physical limitation. At CBR Labs, we permanently remove cameras, microphones, speakers, Wi-Fi, Bluetooth and antennas from tablets used in secure environments. If the hardware physically can’t transmit, it doesn’t matter what the AI thinks it’s doing. The industry hasn’t caught up to that yet.”

 

Eshaan Jain, Senior Product Manager, T-Mobile

 

Eshaan Jain, Senior Product Manager, T-Mobile

 

“Traditional threat models break down when autonomous AI systems act as attackers without malicious intent. Security teams currently rely on frameworks that look for malicious actors, clear indicators of compromise, or compromised insider credentials.

“When an autonomous agent misinterprets a valid workflow and accesses unauthorised infrastructure using legitimate permissions, standard intrusion detection systems fail to catch the deviation. The industry is still treating non-malicious autonomous boundary-crossing as a hypothetical edge case rather than an operational reality. Meaningful defence requires shifting from static access control lists to dynamic semantic guardrails. Security posture must evaluate what an AI agent is actually trying to accomplish in real time, rather than just checking whether its cryptographic credentials are valid.

“Until detection tools learn to monitor behavioural intent and task boundaries alongside technical privileges, companies remain vulnerable to automated overreach that traditional security frameworks cannot classify or stop.”

 

Cache Merrill, Founder, Zibtek

 

Eshaan Jain, Senior Product Manager, T-Mobile

 

“I don’t think most enterprise threat models are ready for an AI agent that has legitimate access but uses that access in a way nobody intended. In traditional security, we’re usually looking for a compromised account, malicious code, or someone deliberately trying to get somewhere they shouldn’t. With an AI agent, the access can be legitimate while the actions still create a security problem.

“In the security work I’ve been involved with, I’d want to see what the agent is actually doing after it gets access. It should have only the permissions it needs, its actions should be logged, and there should be limits on what it can change or where it can connect. If it starts behaving outside its expected pattern, I’d treat that seriously even if there was no malicious intent. AI agents need to be treated as part of the attack surface, not just another application.”

 

Alexander Leslie, Senior Advisor, Recorded Future

 

Eshaan Jain, Senior Product Manager, T-Mobile

 

“What happened at Hugging Face is a meaningful inflection point, but it needs to be described precisely. This was not an AI model spontaneously developing malicious intent. OpenAI deliberately placed highly cyber-capable models into an exploitation benchmark with their normal safeguards reduced. The significant fact is that the models exceeded the intended boundaries of that test, discovered an unknown vulnerability, obtained access to the open internet, and autonomously chained credential theft, privilege escalation, lateral movement and remote code execution against a real third party.

“Under our AI Malware Maturity Model, this is the clearest public demonstration yet of Level 5 technical capability. An agentic system conducted a complex, multi-stage operation end-to-end without step-by-step human direction. It is not yet evidence of Level 5 malicious activity in the wild. There was no criminal or state operator directing the campaign, and the models were operating under specialised evaluation conditions with reduced refusals and substantial computing resources. That distinction separates a genuine capability milestone from an exaggerated claim that fully autonomous cyber campaigns have suddenly become routine.

“The techniques themselves were not new. The models exploited the same weaknesses that sophisticated human operators exploit, including vulnerable third-party software, overprivileged credentials, insufficient segmentation, and remote code execution paths. What changed was the speed, persistence and autonomy with which those weaknesses could be discovered and combined. The strategic risk is not that artificial intelligence creates an entirely new cyber kill chain. It is that AI can execute the existing kill chain continuously and at a volume that overwhelms human-speed defence. Organisations must treat AI agents as privileged digital identities, treat model and data pipelines as executable attack surfaces, and correlate identity, vulnerability, infrastructure and third-party intelligence at machine speed.”

 

For any questions, comments or features, please contact us directly.
techround-logo

 

The post Anthropic Discloses Fourth Unauthorised Claude Access Incident – Is The Security Industry Prepared For AI Breaches? appeared first on 91̽.

]]>
Bot Traffic Vs Human Traffic: What Decodo Found /cybersecurity/bot-traffic-vs-human-traffic-what-decodo-found/ Thu, 10 Sep 2026 12:43:07 +0000 /?p=159142 Cloudflare tracks web traffic across its global network. On June 3, 2026, CEO Matthew Prince posted new figures showing automated...

The post Bot Traffic Vs Human Traffic: What Decodo Found appeared first on 91̽.

]]>
Cloudflare tracks web traffic across its global network. On June 3, 2026, CEO Matthew Prince posted new figures showing automated systems generated 57.4% of HTTP requests, against 42.6% from people, according toCloudflare Radar. Prince had told an SXSW audience in March that the crossover would not arrive until 2027. It came more than a year early.

Decodo’s own research points to the same driver. AI tools read the web at machine speed, and that speed explains most of the new bot traffic.

AI-driven traffic grew about 187% across 2025, roughly 8 times faster than human traffic growth, per. Agentic AI traffic, software that acts on a person’s behalf, grew about 7,851% year over year in the same report.

A person shopping for a camera might open a few websites. An AI agent doing the same task can query thousands of pages, turning one user request into thousands of page fetches. That gap in scale is what pushed bots past humans.

 

What Decodo’s Data Shows About Who Is Behind The Traffic

 

Automated traffic splits into three groups. Training crawlers collect data to build and update AI models, and make up the largest slice. AI agents and fetchers pull live pages to answer a prompt or complete a task. Malicious bots run scraping, credential stuffing and fraud.

Decodo’s research puts the malicious share at roughly a third of all bot traffic, leaving about two-thirds doing legitimate work, like search indexing and AI answers.

A handful of companies run most of that legitimate traffic. OpenAI’s bots account for about 69% of observed AI-driven traffic by volume, Meta about 16%, and Anthropic about 11%,per HUMAN Security. Three sectors absorb more than 95% of that traffic; retail and eCommerce, streaming and media, and travel and hospitality.

Retail and eCommerce alone made up 62.5% of training crawler traffic.

 

Decodo’s Network Data On Where The Bots Go

 

Decodo tracked its own network traffic over six months across more than 195 countries, and the pattern lines up with the global figures. Search engines and AI assistants generate about 72% of the traffic Decodo observes.

Retail and eCommerce sites make up about 13% of successful requests, while travel, airlines, and cargo sites trail far behind at 0.4%. News, real estate, jobs, and finance sites each account for a fraction of a percent. Decodo’s data points to the same conclusion as the country figures below: bot activity follows commercial value, not traffic for its own sake.

The same commercial logic shows up at the country level. Decodo’s analysis of Cloudflare Radar data found that six of the top 60 traffic source countries already run more bot traffic than human traffic, led by markets with dense cloud infrastructure rather than large populations.

  • Iran leads at 81.4% bot traffic
  • Singapore follows at 73.7%
  • Ireland sits at 71.1%
  • The Netherlands runs 61.3% bot traffic
  • Finland runs 56.8%

The United States originates 53.5% of worldwide bot traffic and runs 43.6% of bot traffic at home. Germany, the second largest source, runs 45% domestically. Inside the US, Virginia alone accounts for 27% of national bot traffic, followed by California at 9.9% and Oregon at 7.7%.

Traffic carries the flag of the data center, not the person behind the request. A reader in Lagos can still route through a server in Ashburn or Frankfurt, and show up in the data as German or American traffic.

Why Blocking Every Bot Backfires

 

AI assistants and shopping agents now decide what customers see online, and blocking bots removes a business from those results. In 2025, 77% of agentic AI activity hit product and search pages, with smaller shares on account pages, authentication, and checkout, per HUMAN Security.

Identity is part of the problem. Bots can hide their name, and in August 2025 Cloudflare accused AI firm Perplexity of disguising its crawler as a browser.

Some publishers have responded by charging bots for access instead of blocking them outright. The shift rests on a simple ratio: pages taken against visits sent back. Google crawls about five pages for every referral it sends. Some AI crawlers pull thousands of pages for each visit they return, which is why publishers increasingly price access instead of giving it away.

Vaidotas Juknys, CEO at Decodo, said blocking every bot is “like locking your storefront because some visitors don’t buy.” He added that the agents crawling a site today might be how customers discover it tomorrow.

 

What Businesses Should Do Next And Where The Web Scraping API Fits

 

The response depends on the team, and each one needs a different move.

 

Product And Engineering Teams

 

Teams building AI agents need reliable, real-time access to web data across regions. An agent that cannot reach a site, or reads a blocked or geo-shifted version of it, returns a worse answer. Decodo built itsfor exactly this problem, giving agents, LLMs, and tools the ability to fetch real-time results across more than 195 countries.

The API configures scraping power per request, so a team pays for the capabilities a job actually needs, instead of a flat rate regardless of complexity. Routing requests through local IPs matters just as much, since a product page in Madrid can differ from the same page in Chicago.

An agent that always exits through one region reads one version of the web and misses the rest. Fetching the page a local user would see is what keeps an agent’s answer accurate.

Vaidotas Juknys added, “Reliable access to public web data has become as fundamental as cloud computing.” For teams building on AI, that access is now doing the heavy lifting.

 

Marketing And Analytics Teams

 

Agent traffic is a new audience showing up inside your analytics. Tag automated traffic separately from human traffic, and read AI referral activity on its own instead of folding it into session counts. Track which AI tools send the most agent visits.

 

Security Teams

 

The job shifts from blocking everything to sorting good bots from bad ones. Set rules based on verified identity and behaviour, not user agent strings alone. Allow crawlers that drive discovery, rate limit unknown traffic, and stop patterns tied to credential stuffing and scraping fraud.

Bots now send more web requests than people do. Iran, Singapore, and Ireland already run bot majorities and AI-driven traffic keeps growing about 8 times faster than human traffic. Decodo’s own network data shows the same pattern: bots concentrate where the commercial value sits. Businesses that sort bots instead of blocking them and give their own agents reliable access through tools like the Web Scraping API stay visible in AI search results.

The post Bot Traffic Vs Human Traffic: What Decodo Found appeared first on 91̽.

]]>
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now The Leading Path Into The Enterprise /cybersecurity/spycloud-2026-identity-threat-report-non-human-identities-leading-enterprise/ Wed, 09 Sep 2026 11:09:09 +0000 /?p=159037 -Content by CyberNewswire- SpyCloud, the leader in identity threat protection, today released its annual SpyCloud Identity Threat Report, a survey-based...

The post SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now The Leading Path Into The Enterprise appeared first on 91̽.

]]>
-Content by CyberNewswire-

SpyCloud, the leader in identity threat protection, today released its annual , a survey-based study finding that non-human identities (NHIs) – the AI agents, service accounts, API keys, and authentication tokens that connect to internal systems – have become the most common route attackers take into the enterprise.

The survey found that compromised NHIs (31%) are nearly 2x as likely to be the primary entry point compared to phishing and social engineering (17%), the second-ranked answer. NHI-related misuse was also the most commonly reported identity-based event type at 42%, yet the vast majority of organisations aren’t watching for them.

While 95% of organisations believe they have adequate visibility into AI and NHI-related exposures, only 36% monitor them, making machine identities the least-watched category of identity risk in the report. Further amplifying the problem, 68% of organisations experienced an identity-based event in the same period, with those affected averaging eight events each.

Organisations typically maintain a clear inventory of their human workforce, but few extend that same visibility to the service accounts, API keys, and AI agents authenticating into their systems every day. These identities are provisioned for convenience and often hold real privilege, yet in most environments nobody owns them: a service account doesn’t get off-boarded, doesn’t rotate its own credentials, and doesn’t fail an MFA challenge, so once one is exposed it can stay usable for months.

“That asymmetry is what attackers are exploiting,” said Trevor Hilligoss, SpyCloud’s Chief Intelligence Officer. “Every one of these identities is a standing invitation that renews itself until someone notices.”

This year’s report is based on a survey of 750 cybersecurity leaders and practitioners at organisations with 500+ employees across North America (US and Canada), the United Kingdom, and select European markets; Spain, Germany, the Netherlands, Austria, and Switzerland. It benchmarks how organisations detect, remediate, and govern identity threats across human and non-human identities.

 

Additional Key Findings

 

  • AI adoption has outpaced governance – Nearly all organisations (91%) use AI tools or agents with access to internal systems, applications, or data, but only 56% have formal governance and ownership for the resulting privileges. Another 41% rely on informal processes or partial ownership, leaving shadow access; privileged connections operating outside normal governance and monitoring
  • Exposed session blind spots track with higher event rates – Organisations that had visibility into stolen session cookies experienced identity-based events at a meaningfully lower rate (37%) than those that could not (50%).
  • Session cookies and tokens let attackers bypass authentication controls like MFA by resuming an already-authenticated session. This gives them trusted access to applications and data, it’s no surprise then that SpyCloud research shows that session data has overtaken passwords as attackers’ top target
  • Phishing and malware remain the delivery mechanism – Phishing and social engineering is cited as a common access path for identity events (37%) with 40% reporting incomplete visibility into successful phishing attacks, and 53% can see malware exposures on managed devices only
  • Malware and exposed access top the list of supply chain identity events – Malware-infected third-party devices (23%) and exposed API keys or application access involving vendors and partners (22%) were the leading reported causes of supply chain identity events
  • Third-party exposures are getting found, but not closed – Nearly 40% of organisations have no consistent process to confirm that a third-party identity exposure was actually resolved, even as 32% name enhancing supply chain and vendor risk management among their planned investments for the next 12 to 18 months

Non-human identities and third-party exposures are creating new paths into the enterprise, while stolen sessions give attackers ways around controls designed to protect authenticated users.

“Every control that works pushes attackers toward what it doesn’t cover, we hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections,” added Hilligoss. “SpyCloud continues to track threat actor behavior closely to understand where attackers are moving, what data they value, and how those patterns evolve over time.”

Continuous Monitoring And Automation Separate The Most Resilient Identity Programmes

 

Identity exposure creates an ongoing operational burden that extends well beyond the initial incident and how quickly organisations respond has a direct impact on business outcomes. Those relying on manual, case-by-case remediation reported higher incident response costs than organisations with high levels of automation (39% versus 32%) and greater loss of customer or partner trust (47% versus 36%).

The report also introduces SpyCloud’s Identity Threat Protection Maturity Model, which groups respondents into four maturity tiers: Reactive, Building, Operational and Optimised across identity exposure visibility, monitoring, governance, automation and remediation. The findings reflect that the more mature an identity programme gets, the more it relies on continuous identity exposure monitoring and automated remediation and that combination is what actually drives incident rates down.

At enterprise scale, some share of an organisation’s employees, vendors, and machine accounts will be exposed in the near future regardless of how strong its controls are. What changes business outcomes is how long that exposure stays usable.

“Most identity programmes are still measured on whether an exposure happened. That’s the wrong scoreboard,” said Damon Fleury, Chief Product Officer at SpyCloud. “Organisations that pair continuous identity monitoring with automated remediation of workforce exposures create the greatest friction for criminals and gain the biggest edge in preventing follow-on attacks.”

-This is a paid press release published via CyberNewswire-

The post SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now The Leading Path Into The Enterprise appeared first on 91̽.

]]>
Your Smart TV Might Be Eavesdropping: Behind The Security Flaws Compromising Your Living Room /cybersecurity/your-smart-tv-might-be-eavesdropping-behind-the-security-flaws-compromising-your-living-room/ Wed, 09 Sep 2026 10:15:26 +0000 /?p=159005 First we were told routers can monitor breathing patterns, then that TVs are subtly lending Wi-Fi to total strangers, and...

The post Your Smart TV Might Be Eavesdropping: Behind The Security Flaws Compromising Your Living Room appeared first on 91̽.

]]>
First we were told routers can monitor breathing patterns, then that TVs are subtly lending Wi-Fi to total strangers, and now LG sets stand accused of bugging living rooms.

Published in early September by Gamers Nexus working alongside Level1Techs and independent security researchers, an investigation puts a spotlight on two overlapping risks that most owners never think about: aggressive advertising surveillance that maps viewing habits and nearby devices, and security flaws that could let an attacker turn the TV’s microphone into a living-room wiretap.

LG is certainly not the only manufacturer with this problem, however. Samsung, Sony, Hisense and TCL have all faced almost identical scrutiny over the past year, and understanding what’s actually going on requires looking at the whole industry.

 

How The LG Exploits Work

 

To see what was going on behind the scenes, the team ran deep packet analysis and firmware tests on standard retail LG OLEDs, including a 2025 G5 model.

The results showed continuous automatic content recognition tracking literally everything displayed on screen. Whether you were using built-in software or external HDMI devices like a PC or console, the set continually sampled audio and video to match against a reference database. To make matters worse, the TVs were busy mapping the wider home network, cataloguing every phone, printer and smart device in range alongside nearby Wi-Fi network names and signal strengths.

This endless stream of viewing metrics and home network maps feeds right into LG Ad Solutions, which claims coverage over hundreds of millions of devices in the US market alone. Things got worse when researchers tested the microphone, discovering the set could capture clean audio while being in standby mode too. Cutting the web connection proved useless, as the TV cached the recorded files locally before putting them online the instant it reconnected. On top of the surveillance concerns, the report notes critical remote execution bugs in webOS, with full technical teardowns currently held back for responsible disclosure.

LG disputes that it routinely records ambient conversations, saying voice data is only processed when a user presses the voice button or triggers the “Hi LG” wake-word detection, which it says runs locally and deletes audio if no wake word is recognised. Researchers maintain that the default configuration and data flows still create exposure regardless of intent.

 

How Modern TV Tracking Works

 

At its core, automatic content recognition works much like Shazam, but for everything displayed on your screen. The television grabs quick audio and visual fingerprints multiple times per second, checking them against a database to recognise programmes, video games and commercials.

Every viewing session is logged by title, duration, time of day and ad exposure. TV makers then collect these metrics to build audience segments, test ad engagement and trade data with ad platforms. LG allegedly goes a step further by cataloguing every phone, laptop and smart device on local networks, combining those network IDs with viewing records to map out the entire household.

Unwanted ad tracking is frustrating, but the microphone flaw is the real hazard. If a hacker uses an unpatched webOS vulnerability, they gain the ability to listen in while the TV is in standby mode, using the hardware as a jumping-off point to inspect every other device sharing a Wi-Fi. By linking live audio with content logs, an attacker could build a very detailed picture of household activity.

The FBI has highlighted this danger in a 2026 warning, noting that smart TV mics and cameras across all major manufacturers remain prime targets for remote hijacking.

 

This Is An Industry Problem, Not Just An LG Problem

 

Regulators have been taking notice, starting with the Texas AG’s legal campaign against Samsung, Sony, LG, TCL and Hisense for collecting ACR data without proper permission.

Samsung settled, promising to rewrite its privacy policies and stop all ACR tracking in Texas unless users explicitly opt in. LG reached its own settlement in May 2026, agreeing to clearer opt-outs and a specific ban on passing viewing data to the Chinese government. Meanwhile, the cases against Sony, Hisense and TCL were still making their way through the courts by mid-2026.

Independent testing by RTINGS across 15 models from Samsung, LG, Sony, Hisense, TCL, Vizio and Roku found active ACR tracking right out of the box. To make matters worse, opt-out toggles were buried deep in menus, given confusing names or failed to stop the data stream altogether.

None of this is an accident or a one-off engineering mistake; it’s a design feature of a business model that relies on ad revenue to subsidise low hardware prices.

 

Unplugging The Spy

 

Firmware updates are important because they fix the software bugs researchers keep digging up, including those found in webOS.

Most TVs hide these controls inside Settings under Privacy and Terms or User Agreements, where one can individually turn off ACR tracking, targeted ad IDs and background voice listening. Most of this is accepted by default during setup when people click through without reading. Some sets also feature a physical switch or menu setting that mutes the microphone or disables the camera completely.

Network segmentation is the other lever. A TV placed on a separate IoT or guest network can’t reach phones, laptops or work devices on the main network if it’s ever compromised. UPnP left enabled on a router makes it easier for a device to expose services directly to the internet without anyone realising.

The most complete option, for anyone who decides the trade-off is worth it, is treating the TV as a dumb display entirely: disconnecting it from the internet and routing everything through an external streaming device like Apple TV, Fire TV or Roku instead, which cuts off most of what the TV manufacturer itself can see.

The naming varies by brand, which is part of why so many of these settings go unnoticed. Samsung calls it “Viewing Information Services”, Vizio calls it “Viewing Data”, Sony calls it “Samba Interactive TV”. Different label, same underlying function and usually available even when it takes a few extra menu taps to find.

The post Your Smart TV Might Be Eavesdropping: Behind The Security Flaws Compromising Your Living Room appeared first on 91̽.

]]>
Reflectiz Launches Agentic Pentesting For Websites: Up To 10x Coverage Vs Conventional Pentests /cybersecurity/reflectiz-launches-agentic-pentesting-for-websites-up-to-10x-coverage-vs-conventional-pentests/ Tue, 08 Sep 2026 11:00:04 +0000 /?p=158956 -Content by CyberNewswire- Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple...

The post Reflectiz Launches Agentic Pentesting For Websites: Up To 10x Coverage Vs Conventional Pentests appeared first on 91̽.

]]>
-Content by CyberNewswire-

Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more than conventional pentesting tools.

A pentest used to be an event. An engagement, a report, done. The report described a moment. The website kept going: login, checkout, payments, dozens of third-party scripts, all probed by attackers daily.

“Websites change every week and get pentested once or twice a year. That gap is where exposure builds up,” said Idan Cohen, CEO and co-founder of Reflectiz. “Teams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested.”

While others start every test blind, Reflectiz already knows the website.

Reflectiz has spent a decade scanning thousands of production websites and holds a live model of each one: pages, scripts, third parties, domains, sensitive inputs, and behaviors. The pentesting agents add the attacker’s perspective to that same model.

A finding does not arrive as a line item. It arrives with the script involved, the data it can reach, and whether real users are exposed right now, allowing teams to skip the investigation and go straight to the fix.

“The hard part of web pentesting was never the payload. It was understanding what the application actually does,” said Ysrael Gurt, CTO and co-founder of Reflectiz. “Our engine has been reading live websites for years, so our agents start with a map of the site that other tools never build.”

 

A Team Of Specialized Agents Not Another Scanner

 

The agentic pentesting runs as a coordinated team of AI agents, each with a defined role:

  • One agent crawls the site the way a real user does, through logins, one-time codes and 2FA, mapping what is actually there
  • A second fingerprints the stack and works out which attacks apply where
  • A third runs those attacks and chains what it finds
  • The fourth matters most: an independent validator reproduces every finding before it reaches the report. False positives are removed by design

The result: findings with reproduction steps and evidence, plus a coverage map of what was tested and cleared.

Testing spans the full , and teams set depth per flow, from fast predefined checks to expert-level attack chains on critical assets.

 

Completing The 360° Map Of Web Risk

 

The agentic pentesting, part of the new Offensive Hub, joins Security Hub and Privacy Hub on the Reflectiz platform, completing a 360° map of web risk: what runs on the website, what data it touches, and how it can be attacked.

  • One exposure picture. Findings from all three hubs cross-reference automatically, no dashboards reconciled by hand
  • Guided fixes. Atlas, the Reflectiz AI remediation agent, explains each risk and walks the team through the fix
  • Existing workflows. Results route into current operations through a REST API, CI/CD triggers and Slack alerts

-This is a paid press release published via CyberNewswire-

The post Reflectiz Launches Agentic Pentesting For Websites: Up To 10x Coverage Vs Conventional Pentests appeared first on 91̽.

]]>
Hackers Are Hijacking Brazilian Government Websites To Run a Global Gambling Scam /cybersecurity/hackers-hijacking-brazilian-government-websites-run-global-gambling-scam/ Thu, 03 Sep 2026 13:56:18 +0000 /?p=158688 Cybersecurity researchers have uncovered a sprawling scam operation that hijacks Brazilian government websites to trick visitors into landing on fake...

The post Hackers Are Hijacking Brazilian Government Websites To Run a Global Gambling Scam appeared first on 91̽.

]]>
Cybersecurity researchers have uncovered a sprawling scam operation that hijacks Brazilian government websites to trick visitors into landing on fake Google Play, Microsoft Store, and Amazon pages, all in service of pushing online gambling and sports betting.

The campaign, detailed in a new report from Check Point Research, has been active since mid-2025 and is attributed to a Chinese-speaking cybercrime group the researchers have named “Gambling Goblin.” The group is linked to Earth Berberoka, a cluster previously documented targeting gambling websites across Asia, suggesting a decade-long pattern of gambling-driven fraud that is now expanding into new markets.

According to the report, the attackers break into legitimate Brazilian government web servers, spanning federal, state and municipal institutions, and install hidden software that silently reroutes visitors to attacker-controlled phishing pages. Crucially, the browser’s address bar continues to display the legitimate government URL throughout, making the redirect invisible to the average visitor.

Those phishing pages are dressed up to look like Google Play, the Microsoft Store and Amazon, complete with fabricated ratings and reviews. But rather than offering real apps, they funnel visitors toward gambling and sports betting platforms. By routing traffic through high-reputation government domains, the operators are able to manipulate search engine rankings and drive far more traffic to their gambling sites than a standalone scam page could achieve on its own.

Researchers describe the underlying toolkit as unusually sophisticated for a fraud operation. Once inside a compromised server, the group deploys a broad set of custom Linux tools, including a downloader, multiple backdoors, a credential-stealing utility, and a reconnaissance agent used to map out other vulnerable internet-facing systems. Much of the software is deliberately obfuscated to slow down security analysts.

Check Point Research says the scheme is not confined to Brazil. Investigators found parallel versions of the same fake-app-store network built for Vietnamese, Spanish, and English-speaking audiences, along with infrastructure that generates new scam domains every day, evidence, researchers say, that the operation is designed to be exported to new regions rather than run as a one-off campaign.

Perhaps most concerning is how little would need to change for the scam to escalate. Because the fraudulent pages already mimic legitimate app download destinations, researchers warn the same infrastructure could be repurposed with a single configuration change to distribute real malicious apps instead of gambling redirects, turning a search-ranking scam into a direct malware delivery channel.

Brazil in particular, makes an attractive target. The country has become one of the world’s fastest-growing online betting markets, with a large base of mobile users accustomed to installing apps directly from search results. That combination of a receptive audience and under-secured, high-trust government infrastructure gives the operators exactly the conditions they need to scale.

The report marks a notable shift for Brazil’s threat landscape, which has historically been dominated by home-grown banking trojan groups rather than foreign, gambling-focused operators. Researchers say the case blurs the line between financially motivated cybercrime and more sophisticated, espionage-style operations, given the depth of the tooling involved.

Check Point Research is urging public sector IT teams to audit their Apache server configurations for unfamiliar modules, watch for web pages that are unexpectedly missing standard security headers, and treat their domains’ search engine reputation as an asset worth actively protecting.

The post Hackers Are Hijacking Brazilian Government Websites To Run a Global Gambling Scam appeared first on 91̽.

]]>
Hackers Shut Down A UK Power Plant – Are Cyberattacks Moving From Data Theft to Physical Interruption? /cybersecurity/hackers-shut-down-a-uk-power-plant-are-cyberattacks-moving-from-data-theft-to-physical-interruption/ Wed, 26 Aug 2026 10:20:52 +0000 /?p=157807 A UK electricity generator was knocked offline for four days in July 2026 following a cyberattack reportedly linked to Iranian...

The post Hackers Shut Down A UK Power Plant – Are Cyberattacks Moving From Data Theft to Physical Interruption? appeared first on 91̽.

]]>
A UK electricity generator was knocked offline for four days in July 2026 following a cyberattack reportedly linked to Iranian hackers.

The official government response was an immediate sigh of relief. Energy Minister Michael Shanks stressed that the lights stayed on, the grid was fine and the affected plant was thankfully “tiny.” Yet despite the diplomatic downplaying, the breach prompted quick intervention from the National Cyber Security Centre and urgent warnings from energy officials. The power grid survived unscathed, but the incident proved that cyber warfare has officially crossed the threshold from stealing corporate data to physically turning off the power.

Public reaction centred on the lack of widespread disruption. The grid was secure, no blackouts occurred and the immediate impact was contained. While that may be factually correct, the perspective is short-sighted. The true significance lies in what the attack achieved: bridging the gap between IT networks and physical machinery to halt a real-world service for four days.

Regardless of the hacker’s ultimate goal, the vulnerability is now proven.

 

Why The Size Of The Target Is The Question

 

Official confirmation on who carried out the attack or how they broke in remains off the record. The connection to Iran relies on media reporting, and the affected site stays anonymous for safety. The takeaway that matters is that intruders crossed over from code to hardware, shut down power generation on-site and it took a fair amount of time to resolve.

In July 2026, major US intelligence bodies including CISA, the FBI and the NSA raised the alarm on Iranian-linked hackers targeting the hardware controllers that run energy, water and public networks. The warning revealed bad parties altering configuration files, spoofing control screen displays and causing outages. They also warned that any internet-connected controller was vulnerable, calling out systems from industry giants like Schneider Electric, Siemens and Rockwell Automation. The advisory flagged US activity, but this shows exactly why UK security teams hit the panic button.

This incident is less about testing grid stability and more about understanding threat strategy. Targeting a minor generator looks like an intentional probe: showing off physical attack capabilities while playing it safe enough to dodge a full state-level response. If that take is correct, taking four full days to restore operations is the metric critical infrastructure operators should be running against their own disaster recovery plans.

We asked a group of OT security specialists, infrastructure CISOs and incident response experts what the incident actually reveals about the state of operational technology security in critical infrastructure.

 

Our Experts

 

 

  • Arnar Gunnarsson, CISO, Opin Kerfi
  • Alon Nachmany, Founder and CEO, Tabor Security
  • Ric Derbyshire, Principal Security Researcher, Orange Cyberdefense
  • Stanislav Kazanov, Head of GRC, Cybersecurity and Sustainability, Innowise
  • Matthew Carr, Co-founder and Head of Research and Technology, Atumcell Group

 

 

Arnar Gunnarsson, CISO, Opin Kerfi

 

Arnar Gunnarsson, CISO, Opin Kerfi
 

“We are reporting on the wrong thing here. The reports around this have been leading with “no impact on the UK power network”, but the number here is not how many megawatts are lost in production. It is that an external unauthorised party managed to reach the internal control layer of a power plant and changed its state. Deciding on a small plant was probably deliberate, since a small plant proves their point without invoking a response.

“The number we should be reporting and focusing on is the four days. The difference between IT and OT is that in IT, recovery is a simple restore. In OT, you can’t re-image a turbine like a laptop. You need verified logic in the controller, a known-good configuration baseline and more than a healthy amount of safety validation before spinning it up to full production. The timeline of four days tells us that most likely the operator did not have an offline trusted baseline of that control layer, so they had to slowly build confidence in the process rather than simply restoring it.

“Another thing to mention is that the size of this falls below the NIS reporting threshold, which shows the same pattern as other attacks in Europe. That tells us these adversaries have read our regulatory perimeter and are making sure they operate just outside it. We need to start testing our OT recovery time, and unfortunately most operators have never timed their own. The real number is rarely close to the planned one.”

 

Alon Nachmany, Founder and CEO, Tabor Security

 

Arnar Gunnarsson, CISO, Opin Kerfi
 

“I’m not sure why we still score cyberattacks like they’re smash-and-grabs. We measure the immediate damage, and when the lights stay on, we call it contained. That misses the point of an attack like this. Choosing a target small enough to avoid grid impact can be deliberate. Call it a controlled attack, possibly reconnaissance. The objective may not be to break something. It may be to answer a more important question: can we reach the physical layer? That is access plus restraint. And the restraint is what should worry us, because it means the operator may have had the ability to go further and chose not to.

“On the four days, I’d add an important caveat before calling that the scandal. Four days can mean two very different things. If the plant executed a safe shutdown and remained offline while responders verified that the control environment was clean, that is discipline, not failure. You do not rush a plant back online when you cannot trust the systems that tell you it is safe. But if those four days reflect an inability to restore operations, determine what was compromised, or establish whether the environment was clean at all, then that is the resilience gap worth talking about. The number alone does not tell us which one happened.

“The real readiness question is not how fast did they recover. It is whether they had enough visibility to know what was touched in the first place. Too many energy operators still cannot answer that quickly. That gap, more than any single downtime figure, is what these incidents keep exposing.”

 

Ric Derbyshire, Principal Security Researcher, Orange Cyberdefense

 

Ric Derbyshire, Principal Security Researcher, Orange Cyberdefense
 

“A four-day outage at a UK generation site is still significant even when the lost capacity, as in this case, is small. The incident creates a second-order cognitive effect across wider society by showing that UK energy infrastructure can be reached and disrupted through cyber activity. That perception can shape how people view the resilience of critical infrastructure and potentially undermine public trust and confidence.

“The incident also sits within a wider increase in hostile-state and state-aligned activity against national infrastructure. The NCSC has warned repeatedly about this trend and about the growing use of cyber operations as part of wider geopolitical pressure.

“While the actors and specific technology affected in this incident are not confirmed, the shape of the event seems to follow a broader pattern of actors chasing bigger and more disruptive impacts, including disruption of OT within critical national infrastructure. If this escalation continues, defenders should expect more actors to pursue overt disruption of physical infrastructure.”

 

Stanislav Kazanov, Head of GRC, Cybersecurity and Sustainability, Innowise

 

Stanislav Kazanov, Head of GRC, Cybersecurity and Sustainability, Innowise
 

“The size of the target was the point, not an accident of poor targeting. A group capable of reaching operational technology inside a national grid doesn’t accidentally pick the smallest generator in the country. Choosing a facility guaranteed to leave the wider grid untouched reads as a controlled demonstration: proof the access exists and the switch works, without triggering the kind of response a strike on a major asset would invite.

“The four days matter more than most coverage has given them credit for. Modern OT recovery on a well-segmented, well-drilled site should be measured in hours, not days, once compromised systems are isolated and known-good configurations restored. A four-day outage on a facility small enough to pose no grid risk suggests recovery playbooks, verified backups or segmentation between IT and OT weren’t where they needed to be. That gap, not the blackout that didn’t happen, is the operational question every energy operator running distributed or smaller-scale generation should be running against their own environment this week.”

 

Matthew Carr, Co-founder and Head of Research and Technology, Atumcell Group

 

 

Matthew Carr, Co-founder and Head of Research and Technology, Atumcell Group
 

“Could this have actually taken the grid down? No. If an attacker chooses a small enough target, usually all they prove is that they can access OT systems and turn something off.

“What should concern people is that it took four days, and that worries me. OT recovery is slow for a reason. You do not restart a physical plant until you are sure nothing has been tampered with. So four days suggests to me that the incident response plan was not tested for something this serious, or the separation between IT and OT was not strong enough to stop the damage quickly.

“The OT sector should be very concerned about how long it takes to fix these problems.”

 

For any questions, comments or features, please contact us directly.
techround-logo

 

The post Hackers Shut Down A UK Power Plant – Are Cyberattacks Moving From Data Theft to Physical Interruption? appeared first on 91̽.

]]>
ChatGPT Can Now Read Your iMessages – Does This Break The Implicit Contract Of End-to-End Encryption? /cybersecurity/chatgpt-can-now-read-your-imessages-does-this-break-the-implicit-contract-of-end-to-end-encryption/ Tue, 25 Aug 2026 10:10:24 +0000 /?p=157618 OpenAI recently dropped a macOS update that turns ChatGPT into your personal text-messaging proxy. With Full Disk Access enabled, it...

The post ChatGPT Can Now Read Your iMessages – Does This Break The Implicit Contract Of End-to-End Encryption? appeared first on 91̽.

]]>
OpenAI recently dropped a macOS update that turns ChatGPT into your personal text-messaging proxy. With Full Disk Access enabled, it can read, search and parse your entire Apple Messages history, draft follow-ups or send messages from your Mac.

Unsurprisingly, the initial hot takes focus on user caution: do you really want an AI reading your texts? But framing this as an individual choice misses the point. This isn’t a privacy trade-off for the person who clicked “allow” – it’s a non-consensual data grab for every contact on the other end of the line.

 

The Missing Consent Factor

 

For most people, iMessage’s end-to-end encryption means one thing: nobody outside the chat can see what you wrote. That promise is why many Apple users stick around. The new ChatGPT plugin politely asks for the keys to that chat once the message arrives on your Mac.

The moment one participant toggles on Full Disk Access, ChatGPT can index, search and digest the entire thread on their Mac – including every message sent by third parties. People who have never touched an OpenAI product, granted permissions or intended to share their words are then exposed. There are no alerts sent out and no privacy toggles to flip. Their only choices are leaving the chat or convincing the Mac owner to revoke the plugin.

OpenAI’s public statements focus on the enabling user’s control and note that the plugin doesn’t give ChatGPT access to conversations on other devices. But on the enabling user’s device, the other person’s messages are part of the local archive that ChatGPT can now analyse.

The opt-in is per device, not per conversation and not per contact. Everyone who has ever sent a message to that device has had their words included in the dataset, regardless of whether they know it.

 

Why the Enterprise Risks Are Far Worse

 

Individual privacy is only part of the story. The corporate fallout is far more important, coverage has largely ignored the enterprise exposure.

Managed Mac users running ChatGPT Work often hold message histories that blur the line between personal and professional communication. Because iMessage stores client discussions, team chats, investor updates and casual banter in one local database, the plugin reads and indexes every item without distinction. OpenAI hasn’t published clear guidance on how administrators should treat Messages data in the context of ChatGPT Work. It’s also unclear whether any technical controls limit the plugin’s ability to process personal iMessage history on company-managed devices.

This creates a second consent problem that goes beyond the individual user. External contacts messaging a corporate machine have no idea their texts are being fed into an enterprise AI tool. Whether it’s a client discussing a deal or a friend sharing a quick update, their words enter a managed company workflow without their knowledge or approval.

In environments where ChatGPT Work is encouraged or mandated as a productivity tool, employees may be enabling a feature that exposes their personal contacts’ messages to systems governed by corporate policy, without either party knowing.

 

Why Agentic AI Breaks Modern Consent Models

 

This isn’t just an OpenAI or iMessage vulnerability – it’s a flaw in the wider agentic AI rollout.

Giving an AI assistant the green light to scan local machine archives like email, calendars or messaging apps means it inevitably processes third-party data at scale. Legacy consent models are unprepared for this dynamic. Opt-in systems operate on the assumption that a user only controls their own data, failing completely when one person’s setting alters the privacy of every contact in their system.

The Aura breach earlier this year was initiated through one employee’s actions that exposed hundreds of thousands of records. The ChatGPT iMessage plugin isn’t a security breach, but it follows a similar logic: one person’s decision creates exposure for people who had no part in making it. The difference is that in this case, the exposure is by design, and the people affected have no way of knowing it has happened.

End-to-end encryption protects messages in transit. It’s always relied on an assumption that the endpoints (the devices where messages arrive) remain trusted and controlled by their participants. This plugin formalises a dangerous new category of endpoint risk. By granting an AI open, queryable access to an entire chat database via one user’s local permission, it systematically exposes third parties without sending a single alert.

The post ChatGPT Can Now Read Your iMessages – Does This Break The Implicit Contract Of End-to-End Encryption? appeared first on 91̽.

]]>
Vega Introduces Detection Skills A New Open Standard For AI Reasoning in Agentic Cyber Defence /cybersecurity/vega-introduces-detection-skills-new-open-standard-ai-reasoning-agentic-cyber-defence/ Mon, 24 Aug 2026 05:00:21 +0000 /?p=157583 Vega, the pioneer of Agentic Cyber Defence, today launched Detection Skills: an open standard that redefines security operations for the...

The post Vega Introduces Detection Skills A New Open Standard For AI Reasoning in Agentic Cyber Defence appeared first on 91̽.

]]>
Vega, the pioneer of Agentic Cyber Defence, today launched Detection Skills: an open standard that redefines security operations for the AI era. The standard captures a team’s expert judgment as a self-improving agentic loop across detection, triage, and investigation. Available to the community as an open standard, or natively within the best-in-class Vega platform, they allow modern Cyber Defence Engineers to architect their reasoning once and scale it across everything they defend.

It gives every company an answer to the question that matters most: can our defence keep pace with AI?

“AI-driven adversaries bypass static rules in every legacy SIEM, and no rule catches an attack it has never seen,” said Eli Rozen, co-founder and CTO, Vega. “Detection Skills answer with scaled AI reasoning that brings the judgment of your best Cyber Defence Engineers to every alert, in real-time. We made the standard open to ensure the whole industry rises with it: as attacks scale, defence compounds.”

 

Why Now?

 

Frontier AI has collapsed the economics of cyberattacks. Intrusions that took skilled teams weeks now take minutes, with advanced models and autonomously breaching organisations. Defences built on legacy SIEM have not kept pace: they can only recognise known patterns in a threat landscape where attacks are generated, not repeated.

From Static Rules to AI Reasoning

 

Just as Sigma defined the traditional detection rule format, Detection Skills is what comes next for AI-first Cyber Defence teams. The engineer who builds a detection and the analyst who answers it at 2 a.m. often never meet, and the context dies in the handoff.

Detection Skills solves that: built on the Agent Skills framework originally developed by Anthropic, it attaches triage, investigation, and optimisation directly to the detection, so the reasoning travels with it, enabling security teams to:

  • Detect and decide at AI speed. Triage and investigations run automatically the moment a detection fires, slashing MTTD and MTTR. Only what matters reaches a human, with a finished, evidence-backed workbook attached
  • Scale cyber defence expertise. Author a skill once and the same judgment reaches every alert, known or unknown. Engineers keep complete transparency and control over the AI’s reasoning: what it checked, why it decided, and no change without their sign-off
  • Adopt without disruption. Works alongside existing security investments. It launches with the Agentic Detection Library: 50+ skills from Vega Research and our partners, plus a sandbox to build, test, and export spec-compliant detections, and GitHub to contribute your own

Vega proved Detection Skills in production on its , the standard’s reference implementation. Built on the Security Analytics Mesh (SAM), the platform runs the full loop directly on an organisation’s data wherever it lives, across cloud object storage, Legacy SIEMs, and data lakes, with no data migration or ingestion tax.

The post Vega Introduces Detection Skills A New Open Standard For AI Reasoning in Agentic Cyber Defence appeared first on 91̽.

]]>