Sign in

The IT Nerd

@theitnerd.ca
240 followers 75 following 4.9K posts

I am a computer nerd that speaks English. I run a computer consulting company and I have a blog that speaks to and reviews everything from smartphones to cars. Plus I cover computer security and give tips to help others to leverage the tech that they have.

PostsRepliesMedia
The IT Nerd @theitnerd.ca · 9h
AI agents expose sensitive corporate screenshots from 343 companies Glow Security researchers discovered more than 13,000 sensitive screenshots from 343 organizations that AI coding agents had uploaded to publicly accessible GitHub repositories, exposing information including credentials, personal…
itnerd.blog
AI agents expose sensitive corporate screenshots from 343 companies
Glow Security researchers discovered more than 13,000 sensitive screenshots from 343 organizations that AI coding agents had uploaded to publicly accessible GitHub repositories, exposing information including credentials, personal data, internal systems and unreleased products. The agents were performing legitimate development tasks but encountered a limitation when attempting to attach screenshots from private repositories to pull requests. Instead of stopping or asking for permission, some agents independently worked around the restriction by placing the screenshots in public repositories so developers could view them.
000
The IT Nerd @theitnerd.ca · 9h
FTC Probes OpenAI And Others The FTC has opened a probe into a bunch of AI companies including OpenAI: The Federal Trade Commission has opened an investigation into OpenAI, Anthropic and other artificial intelligence companies over the potential dangers posed by their products, an agency…
itnerd.blog
FTC Probes OpenAI And Others
The FTC has opened a probe into a bunch of AI companies including OpenAI: The Federal Trade Commission has opened an investigation into OpenAI, Anthropic and other artificial intelligence companies over the potential dangers posed by their products, an agency spokesperson confirmed to CNBC. The probe adds to the mounting scrutiny that OpenAI and Anthropic have been facing over their safety practices, especially after industry researchers warned about how the companies’ AI models could cause…
000
The IT Nerd @theitnerd.ca · 9h
RatHat banking malware exposed in new research New research from Cleafy Labs details how the RatHat Android banking malware operation has evolved into a broader Malware-as-a-Service platform, with nearly 100 C2 deployments, automated APK building and signing, shell-level device control, and Gemini…
itnerd.blog
RatHat banking malware exposed in new research
New research from Cleafy Labs details how the RatHat Android banking malware operation has evolved into a broader Malware-as-a-Service platform, with nearly 100 C2 deployments, automated APK building and signing, shell-level device control, and Gemini used both to navigate unfamiliar Android interfaces and help operators prioritize victims. Ted Miracco, CEO of Approov: "Modern mobile threats have evolved from basic signature-based malware into AI-augmented automation engines.
000
The IT Nerd @theitnerd.ca · 9h
Trump, tech CEOs sign voluntary AI safety accord President Donald Trump and executives from OpenAI, Anthropic, Google, Meta, Nvidia and xAI signed a voluntary AI safety accord…...
itnerd.blog
Trump, tech CEOs sign voluntary AI safety accord
President Donald Trump and executives from OpenAI, Anthropic, Google, Meta, Nvidia and xAI signed a voluntary AI safety accord calling on companies to implement multiple layers of controls and oversight as increasingly capable AI systems raise cybersecurity and other safety concerns. The agreement calls for companies to monitor AI models during training and deployment for dangerous capabilities, including whether models could hack or access technical systems in unintended ways, assist with biological, chemical or nuclear threats, or evade human control.
000
The IT Nerd @theitnerd.ca · 12h
Guest Post: Cycode Uncovers Account Takeover in MCP Python SDK Anthropic's MCP (Model Context Protocol) is an open protocol for connecting AI assistants to external tools and data sources, and its OAuth implementation trusts the tool server far more than it should....
itnerd.blog
Guest Post: Cycode Uncovers Account Takeover in MCP Python SDK
Anthropic's MCP (Model Context Protocol) is an open protocol for connecting AI assistants to external tools and data sources, and its OAuth implementation trusts the tool server far more than it should. We found that a malicious MCP server can hijack that login flow in Anthropic's Python SDK. It can steal the credentials your app uses to authenticate with your real login provider - your client secret, your authorization code, and the proof key that's supposed to prevent exactly this kind of theft - and use them to log in as you.
000
The IT Nerd @theitnerd.ca · 14h
Samsung expands its Galaxy lineup with the Tab S12 Series and SmartTag3 Samsung today launched the Galaxy Tab S12+, Galaxy Tab S12 Ultra and Galaxy SmartTag3, bringing new ways to work, create and keep track of what matters....
itnerd.blog
Samsung expands its Galaxy lineup with the Tab S12 Series and SmartTag3
Samsung today launched the Galaxy Tab S12+, Galaxy Tab S12 Ultra and Galaxy SmartTag3, bringing new ways to work, create and keep track of what matters. Powered by the new MediaTek Dimensity 9500 chipset, the Galaxy Tab S12 Series combines powerful performance, PC-like productivity and an immersive viewing experience for work, creativity and entertainment. For the multitasker:
010
The IT Nerd @theitnerd.ca · 17h
Malicious npm postinstall stayed undetected for 14 months CloudSEK finds  CloudSEK's Global Threat Intelligence team has uncovered MALFEX, a long-running npm supply-chain campaign linked to a single operator that used malicious packages to deploy RAT, steal credentials and maintain persistence on…
itnerd.blog
Malicious npm postinstall stayed undetected for 14 months CloudSEK finds 
CloudSEK's Global Threat Intelligence team has uncovered MALFEX, a long-running npm supply-chain campaign linked to a single operator that used malicious packages to deploy RAT, steal credentials and maintain persistence on Windows systems. What makes the campaign notable is that parts of the infrastructure remained active even after related packages were seized, while one malicious npm postinstall went undetected for…
000
The IT Nerd @theitnerd.ca · 17h
Ascerta raises $18M to help enterprises maximize AI ROI Enterprise AI has moved from experimentation to a material line item. Companies can count tokens, licenses, agent runs and lines of AI-generated code, yet many still cannot answer the question that determines what happens next: which AI…
itnerd.blog
Ascerta raises $18M to help enterprises maximize AI ROI
Enterprise AI has moved from experimentation to a material line item. Companies can count tokens, licenses, agent runs and lines of AI-generated code, yet many still cannot answer the question that determines what happens next: which AI initiatives are actually worth scaling. Ascerta was built to give them that answer. Today, the company formerly known as Pay-i announced its new name alongside an $18 million Series A led by Dell Technologies Capital, with participation from Hitachi Ventures, BGV, Wipro Ventures and earlier investors.
000
The IT Nerd @theitnerd.ca · 17h
Park Place Technologies’ New AI-Powered Platform Provides Full View of IT Infrastructure Health ParkView Asset Intelligence, an AI-powered platform that shows IT managers the health of their infrastructure and insights to act on it, launched today from…...
itnerd.blog
Park Place Technologies’ New AI-Powered Platform Provides Full View of IT Infrastructure Health
ParkView Asset Intelligence, an AI-powered platform that shows IT managers the health of their infrastructure and insights to act on it, launched today from Park Place Technologies. Called ParkView Asset IntelligenceTM, the new proprietary platform provides a detailed view into the condition of hardware devices, including servers, storage, network, security appliances and hyperconverged infrastructure, at a level previously only accessible to original equipment manufacturers (OEMs).
000
The IT Nerd @theitnerd.ca · 18h
VDURA Data Platform V12 Now Generally Available, the Hyperscaler Storage Playbook to AI Factories and Neoclouds on Supermicro VDURA today announced the general availability of the VDURA® Data Platform V12, the release that turns the platform into a multi-tenant, API-driven storage service for GPU…
itnerd.blog
VDURA Data Platform V12 Now Generally Available, the Hyperscaler Storage Playbook to AI Factories and Neoclouds on Supermicro
VDURA today announced the general availability of the VDURA® Data Platform V12, the release that turns the platform into a multi-tenant, API-driven storage service for GPU clouds and AI factories. V12 ships as a qualified solution on Supermicro Building Block Solutions®, scaling from 8 to 100,000 GPUs on one software stack. VDURA will showcase V12 at Ai Everything Abu Dhabi, 6–7 October at ADNEC Centre, Booth H3-D45.
000
The IT Nerd @theitnerd.ca · 18h
Binalyze Research: Overloaded Enterprise SOCs “Ignore” 300 Potential Threats a Day Due To Lack of Resources Enterprise Security Operations Centers (SOCs) are succumbing to an overwhelming flood of data, research from Binalyze has found....
itnerd.blog
Binalyze Research: Overloaded Enterprise SOCs “Ignore” 300 Potential Threats a Day Due To Lack of Resources
Enterprise Security Operations Centers (SOCs) are succumbing to an overwhelming flood of data, research from Binalyze has found. The leader in automated investigation and response’s report shows SOCs receive on average 2,047 alerts a day. But 300, or 15%, of these are ignored due to a lack of resources, despite being potential threats. Beyond alerts, SOCs face more information than ever before.
000
The IT Nerd @theitnerd.ca · 18h
Sauce Labs Launches the Industry’s First ARM-Native Android Testing Cloud for the Enterprise at Scale Sauce Labs, the test automation leader created by the founders of Selenium and Appium, today announced ARM-native virtual devices for Android in Virtual Device Cloud, the industry's first…
itnerd.blog
Sauce Labs Launches the Industry’s First ARM-Native Android Testing Cloud for the Enterprise at Scale
Sauce Labs, the test automation leader created by the founders of Selenium and Appium, today announced ARM-native virtual devices for Android in Virtual Device Cloud, the industry's first enterprise-grade, ARM-native virtual Android testing environment, part of AURA, the company's AI-Unified Release Assurance platform. The product runs on Google Cloud's C4A metal instances, bare-metal ARM infrastructure running on Google Axion processors, a next-generation foundation that makes this level of ARM-native performance possible at enterprise scale.
000
The IT Nerd @theitnerd.ca · 29/09/2026
OpenAI Says ‘Oops-Sorry Australia OpenAI published an open letter to Australia's government, admitting that several more governments websites that were breached & promising to "do better.”...
itnerd.blog
OpenAI Says ‘Oops-Sorry Australia
OpenAI published an open letter to Australia's government, admitting that several more governments websites that were breached & promising to "do better.” You can read the letter here. Ryan McCurdy, VP, Liquibase ( says this: “At this point, we have enough examples to know this wasn’t just one agent doing something unexpected against Medicare. Different agents accessed different government systems in ways OpenAI didn’t authorize.
000
The IT Nerd @theitnerd.ca · 29/09/2026
Ransomware attack disrupts systems at Japanese railway operator Keio Japanese railway operator Keio Corporation confirmed (Translation here) that a ransomware attack hit its group servers on September 26, causing system disruptions across some of its businesses....
itnerd.blog
Ransomware attack disrupts systems at Japanese railway operator Keio
Japanese railway operator Keio Corporation confirmed (Translation here) that a ransomware attack hit its group servers on September 26, causing system disruptions across some of its businesses. Keio immediately disconnected portions of its network and is working with police and external experts to investigate the attack. The ransomware disrupted business systems at some Keio Group companies, including hotel and payment services, although railway operations were not affected.
000
The IT Nerd @theitnerd.ca · 29/09/2026
ShinyHunters member arrested by Dutch Police Dutch police have arrested a 24-year-old Amsterdam man, believed to be Pepijn van der Stap, as part of the ShinyHunters investigation....
itnerd.blog
ShinyHunters member arrested by Dutch Police
Dutch police have arrested a 24-year-old Amsterdam man, believed to be Pepijn van der Stap, as part of the ShinyHunters investigation. Van der Stap was convicted in 2023 of multiple intrusions, data theft and extortion under the handle "Umbreon." He was on supervised release at the time of the arrest and is reportedly working as an offensive security lead at Neo Security.
000
The IT Nerd @theitnerd.ca · 29/09/2026
More than 16,000 misconfigured Supabase databases expose sensitive data  UpGuard researchers identified 16,326 Supabase databases exposing readable tables after analyzing roughly 300,000 domains showing signs of using the platform....
itnerd.blog
More than 16,000 misconfigured Supabase databases expose sensitive data 
UpGuard researchers identified 16,326 Supabase databases exposing readable tables after analyzing roughly 300,000 domains showing signs of using the platform. More than half of the exposed databases contained indicators of personally identifiable information, while smaller subsets included passwords or authentication tokens. Researchers traced the exposures to security configuration issues including missing or ineffective row-level security policies and improper use of public keys.
010
The IT Nerd @theitnerd.ca · 29/09/2026
Hisense Introduces UR8 with Natural and Real Colour Hisense is introducing the UR8 to Canada, an accessible RGB MiniLED TV series designed to bring next-generation display technology, natural and real colour, immersive entertainment and advanced gaming performance to more consumers worldwide....
itnerd.blog
Hisense Introduces UR8 with Natural and Real Colour
Hisense is introducing the UR8 to Canada, an accessible RGB MiniLED TV series designed to bring next-generation display technology, natural and real colour, immersive entertainment and advanced gaming performance to more consumers worldwide. As The Origin of RGB MiniLED, Hisense continues to push the industry toward a new pinnacle of display technology through its latest RGB MiniLED TVs. Powered by Chromagic Technology — Hisense’s proprietary optical architecture integrating a self-developed Chromagic RGB Chip, advanced Optical Design and Colour Management System — the UR8 delivers more natural and lifelike colours, covering up to 100% of the BT.2020 colour gamut while maintaining high energy efficiency and reducing harmful blue light.
000
The IT Nerd @theitnerd.ca · 29/09/2026
Anthropic IPO filing details massive AI bet while warning of existential risks Anthropic's IPO prospectus, reviewed by Reuters, lays out a sweeping bet that AI will transform the global economy more profoundly than industrialization, electricity and the internet, while simultaneously…...
itnerd.blog
Anthropic IPO filing details massive AI bet while warning of existential risks
Anthropic's IPO prospectus, reviewed by Reuters, lays out a sweeping bet that AI will transform the global economy more profoundly than industrialization, electricity and the internet, while simultaneously warning investors that increasingly powerful AI could pose "catastrophic or existential risks to humanity." At the same time, Anthropic warned those systems could develop self-preserving behaviors, including resisting shutdown, concealing or manipulating information and behavior resembling blackmail.
000
The IT Nerd @theitnerd.ca · 29/09/2026
Guest Post: AI Doesn’t Eliminate Technical Debt. It Inherits It. By Don Boxley, CEO and Co-Founder, DH2i (www.dh2i.com) AI has been dominated by one question for the last two years: How smart is the model?...
itnerd.blog
Guest Post: AI Doesn’t Eliminate Technical Debt. It Inherits It.
By Don Boxley, CEO and Co-Founder, DH2i (www.dh2i.com) AI has been dominated by one question for the last two years: How smart is the model? As a place to start, it’s understandable. Capabilities that were difficult to imagine just a few years ago have been unlocked by better models. Better reasoning, lower costs, faster inference, or more natural conversations are all now promised by every new release.
000
The IT Nerd @theitnerd.ca · 29/09/2026
Schneider Electric, SECLAB expand OT security partnership Schneider Electric and SECLAB announced an expanded OT cybersecurity partnership aimed at protecting critical industrial systems as AI accelerates the discovery of vulnerabilities and attackers increasingly target industrial processes…
itnerd.blog
Schneider Electric, SECLAB expand OT security partnership
Schneider Electric and SECLAB announced an expanded OT cybersecurity partnership aimed at protecting critical industrial systems as AI accelerates the discovery of vulnerabilities and attackers increasingly target industrial processes directly. The companies said newly discovered vulnerabilities can be exploited within days, while patching a PLC can require waiting for a maintenance window followed by testing and requalification, potentially leaving industrial systems exposed for months.
000
The IT Nerd @theitnerd.ca · 29/09/2026
Guest Post: Check Point and NVIDIA Tackle a Growing AI Security Blind Spot Check Point Software and NVIDIA announced a new integration that combines Check Point's AI security monitoring with NVIDIA's Open Agent Safety Platform and OpenShell runtime....
itnerd.blog
Guest Post: Check Point and NVIDIA Tackle a Growing AI Security Blind Spot
Check Point Software and NVIDIA announced a new integration that combines Check Point's AI security monitoring with NVIDIA's Open Agent Safety Platform and OpenShell runtime. Together, the technologies can evaluate an agent's actions before they execute, helping organizations identify and stop potentially harmful behavior in real time. Check Point's semantic monitoring engine can make those decisions in under 100 milliseconds. …
000
The IT Nerd @theitnerd.ca · 29/09/2026
CyberAcuView Selects as its CIRM Platform Advancing Cyber Resilience for the Insurance Industry CYGNVS and CyberAcuView today announced their collaboration. CyberAcuView selected and deployed CYGNVS to be the underlying platform for CyberAcuView and its member organizations to manage incident…
itnerd.blog
CyberAcuView Selects as its CIRM Platform Advancing Cyber Resilience for the Insurance Industry
CYGNVS and CyberAcuView today announced their collaboration. CyberAcuView selected and deployed CYGNVS to be the underlying platform for CyberAcuView and its member organizations to manage incident response in an out-of-band, secure, governed and compliant environment with a comprehensive audit trail and chain of custody. CyberAcuView was founded in 2021 by seven leading cyber insurance carriers, and its current 25 members represent two thirds of the global cyber insurance market.
000
The IT Nerd @theitnerd.ca · 29/09/2026
The Thanksgiving plus-one that actually help according to Samsung Thanksgiving comes with plenty to be thankful for, and a pretty long to-do list. This year, the Galaxy…...
itnerd.blog
The Thanksgiving plus-one that actually help according to Samsung
Thanksgiving comes with plenty to be thankful for, and a pretty long to-do list. This year, the Galaxy Z Fold8, Z Fold8 Ultra and Z Flip8 can be the holiday plus-ones that actually pitch in. Here’s how Samsung devices can take something off your Thanksgiving plate: 1.      Plan Like A Pro: As Thanksgiving plans come together, Galaxy AI helps keep you on track.
010
The IT Nerd @theitnerd.ca · 29/09/2026
97% of deepfake victims at schools were female, most fakes were created by student Cybernews has analyzed the Resemble AI Deepfake Incident Database and found that there have been 83 deepfake incidents at educational institutions around the globe since the start of 2025....
itnerd.blog
97% of deepfake victims at schools were female, most fakes were created by student
Cybernews has analyzed the Resemble AI Deepfake Incident Database and found that there have been 83 deepfake incidents at educational institutions around the globe since the start of 2025. Researchers then analyzed the cases to understand who is being targeted, who is creating the content, and where these cases are happening. Here are the key findings: 71% of recorded deepfakes at educational institutions involved sexual content;
010
The IT Nerd @theitnerd.ca · 29/09/2026
CloudSEK Traces 85 npm Typosquats to Infrastructure Hosting a GPU Attack Framework Targeting vast.ai CloudSEK is out with a two-part investigation — TOPHIT — uncovering a threat operation that connects a large-scale npm supply-chain campaign with an emerging GPU cryptojacking framework targeting…
itnerd.blog
CloudSEK Traces 85 npm Typosquats to Infrastructure Hosting a GPU Attack Framework Targeting vast.ai
CloudSEK is out with a two-part investigation — TOPHIT — uncovering a threat operation that connects a large-scale npm supply-chain campaign with an emerging GPU cryptojacking framework targeting the vast.ai marketplace. In Part 1, CloudSEK researchers found that a single npm account, @prime0, published 85 typosquatted packages in just over three minutes, targeting 29 of the ecosystem's most widely downloaded libraries, including chalk, semver, debug, minimatch and ajv.
010
The IT Nerd @theitnerd.ca · 29/09/2026
Dodge AI raises $2.65M from Accel and Google to fix the $600B enterprise firefighting problem Enterprise software is never finished. Once SAP, Salesforce, Oracle, or Microsoft Dynamics goes live, the business keeps changing, and thousands of company-specific rules get built into the software over…
itnerd.blog
Dodge AI raises $2.65M from Accel and Google to fix the $600B enterprise firefighting problem
Enterprise software is never finished. Once SAP, Salesforce, Oracle, or Microsoft Dynamics goes live, the business keeps changing, and thousands of company-specific rules get built into the software over years. When something breaks, the answer is rarely in one place. Keeping it all running costs enterprises more than $600 billion a year. Dodge AI has raised $2.65 million to change how that work gets done, with an AI platform that resolves incidents and change requests across enterprise applications while documenting the custom logic that makes each system unique.
010
The IT Nerd @theitnerd.ca · 29/09/2026
CData Launches Connect AI Gateway, One Control Point Between AI and the Systems That Run the Business CData Software today launched CData Connect AI Gateway, the next evolution of the Connect AI platform designed to give organizations a single control point for the models, tools, data and actions…
itnerd.blog
CData Launches Connect AI Gateway, One Control Point Between AI and the Systems That Run the Business
CData Software today launched CData Connect AI Gateway, the next evolution of the Connect AI platform designed to give organizations a single control point for the models, tools, data and actions used by AI agents and the individuals who work with them. The Gateway connects agents and individuals to enterprise systems through governed tools, applies company context at every step, enforces permissions down to the record and routes each request to the most efficient model for the task, helping enterprises move AI from answering questions to taking action.
000
The IT Nerd @theitnerd.ca · 29/09/2026
IDC Analyst: Enterprises Are Finally Seeing AI Returns, But the Bill for Keeping the Lights on Hasn’t Gone Away Generative AI has crossed the line from experiment to return on investment for roughly half of enterprises, but the infrastructure that runs the rest of the business is still waiting for…
itnerd.blog
IDC Analyst: Enterprises Are Finally Seeing AI Returns, But the Bill for Keeping the Lights on Hasn’t Gone Away
Generative AI has crossed the line from experiment to return on investment for roughly half of enterprises, but the infrastructure that runs the rest of the business is still waiting for its budget. That tension is the subject of the newest episode of The Savvy CIO, the podcast from Park Place Technologies, available tomorrow wherever you get your podcasts. Host Bradd Busick sits down with Rob Brothers, an IDC analyst who has spent nearly four decades on every side of the infrastructure lifecycle market, as a value-added reseller, as a third-party maintainer and now as an analyst covering the space.
000
The IT Nerd @theitnerd.ca · 29/09/2026
Kiteworks told customers to shut down to avoid pwnage Kiteworks told customers to temporarily shut down certain systems after receiving credible threat intelligence about a potential attack, despite no confirmed compromise. ...
itnerd.blog
Kiteworks told customers to shut down to avoid pwnage
Kiteworks told customers to temporarily shut down certain systems after receiving credible threat intelligence about a potential attack, despite no confirmed compromise.  Kiteworks is advising customers to facilitate a nine-hour precautionary shutdown window this weekend, in their local time zone. Customers who self-manage their Kiteworks systems—on-premises or on AWS or Azure—should shut down those systems themselves during this window. Kiteworks will shut down the customer systems it hosts, on behalf of customers, during the same window, so Kiteworks-hosted customers are not required to take any action.
000
The IT Nerd @theitnerd.ca · 29/09/2026
OpenAI Does Not Release Its Latest Model Over “Safety Concerns” From the file marked "duh", OpenAI has announced that it has scrapped the release of its new GPT-6.1 Astra model after safety concerns that it showed “higher levels of deception”....
itnerd.blog
OpenAI Does Not Release Its Latest Model Over “Safety Concerns”
From the file marked "duh", OpenAI has announced that it has scrapped the release of its new GPT-6.1 Astra model after safety concerns that it showed “higher levels of deception”. The decision comes just days after OpenAI models were found to have accessed data on two US government websites. Luke Hinds, co-founder and CEO of nolabs has this comment: Barely a week goes by without another story like this, and each one points to the same problem for businesses.
000
The IT Nerd @theitnerd.ca · 28/09/2026
OpenAI agents went beyond instructions to access U.S. government websites – Sigh…. According to a Wall Street Journal report, OpenAI agents tasked with retrieving information from U.S. government websites took actions they were not instructed or authorized to perform....
itnerd.blog
OpenAI agents went beyond instructions to access U.S. government websites – Sigh….
According to a Wall Street Journal report, OpenAI agents tasked with retrieving information from U.S. government websites took actions they were not instructed or authorized to perform. In one case involving the Securities and Exchange Commission, agents retrieved public SEC information and then posted it to an online forum without being asked to do so. Other agents went beyond normal data collection by using credentials found online to access Census Bureau data, while independent researchers identified an unsuccessful attempt involving a Department of Education website.
000
The IT Nerd @theitnerd.ca · 28/09/2026
About 17 TRILLION Microsoft Records Accessed by 16-Year-Old Researcher  An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets in Microsoft’s Titan analytics service, were reachable through a single internal analytics service, all because it never checked the signature on…
itnerd.blog
About 17 TRILLION Microsoft Records Accessed by 16-Year-Old Researcher 
An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets in Microsoft’s Titan analytics service, were reachable through a single internal analytics service, all because it never checked the signature on a login token. The flaw, which a 16-year-old security researcher known as Faav uncovered, enabled him to claim an administrator’s identity and submit unauthorized SQL queries without any real credentials.
000
The IT Nerd @theitnerd.ca · 28/09/2026
New SOCRadar AI Identity Exposure Report Reveals 80,000+ Enterprises Had Employee AI Logins Stolen – ChatGPT is the Front Door  SOCRadar’s just-released AI Identity Exposure Report 2026 reveals that 80,000+ enterprises had employee AI logins stolen and ChatGPT is the front door....
itnerd.blog
New SOCRadar AI Identity Exposure Report Reveals 80,000+ Enterprises Had Employee AI Logins Stolen – ChatGPT is the Front Door 
SOCRadar’s just-released AI Identity Exposure Report 2026 reveals that 80,000+ enterprises had employee AI logins stolen and ChatGPT is the front door. SOCRadar mapped more than a million infostealer records against corporate domains The report looks at the growing exposure of corporate AI identities and credentials, particularly how infostealer malware is capturing access to AI platforms, sessions, credentials, and other sensitive information used by organizations.
010
The IT Nerd @theitnerd.ca · 28/09/2026
New Eclypsium data: Attackers are targeting the systems that control infrastructure Attackers are increasingly going after the systems that control enterprise infrastructure, rather than just the individual devices underneath them....
itnerd.blog
New Eclypsium data: Attackers are targeting the systems that control infrastructure
Attackers are increasingly going after the systems that control enterprise infrastructure, rather than just the individual devices underneath them. The latest InfraTrust Pulse from Eclypsium tracked 158 new security advisories covering 1,699 CVEs in less than a month including 42 Critical advisories, eight perfect 10.0s and 71 remotely exploitable without authentication. One trend stands out: serious flaws are repeatedly hitting…
010
The IT Nerd @theitnerd.ca · 28/09/2026
New CalPhishing Campaign Uses Internal Email Forwards to Reach Targets Fortra Intelligence and Research Experts (FIRE) have identified a new CalPhishing variant where attackers exploit internal referrals to conduct credential theft attacks....
itnerd.blog
New CalPhishing Campaign Uses Internal Email Forwards to Reach Targets
Fortra Intelligence and Research Experts (FIRE) have identified a new CalPhishing variant where attackers exploit internal referrals to conduct credential theft attacks. Key takeaways: Attackers pose as prospective customers and contact non-sales employees first. Employees unknowingly become "trust bridges" by forwarding meeting-booking links to sales teams. The booking page appears legitimate but ultimately prompts users to sign in with Microsoft 365 credentials.
010
The IT Nerd @theitnerd.ca · 28/09/2026
Autoheal raises $7.9M to build a self-improving software factory for enterprises AI is helping engineering teams ship more code, faster than ever. But that acceleration comes with a growing operational burden: more production incidents to respond to, more security vulnerabilities to remediate, and…
itnerd.blog
Autoheal raises $7.9M to build a self-improving software factory for enterprises
AI is helping engineering teams ship more code, faster than ever. But that acceleration comes with a growing operational burden: more production incidents to respond to, more security vulnerabilities to remediate, and spiraling token costs to contain. Autoheal is built for these challenges and already battle tested at industry leaders such as Nomura Bank and AvidXchange where off-the-shelf point agents failed to deliver. 
010
The IT Nerd @theitnerd.ca · 28/09/2026
Producing code has never been easier, but AI-generated bugs and rising debugging workloads are slowing software delivery   New research from Undo, the technology that gives developers the runtime context needed to solve the most challenging problems in the most complex codebases, finds that almost…
itnerd.blog
Producing code has never been easier, but AI-generated bugs and rising debugging workloads are slowing software delivery  
New research from Undo, the technology that gives developers the runtime context needed to solve the most challenging problems in the most complex codebases, finds that almost four in five (79%) engineering leaders say their release cycles are no faster than before, despite their teams being able to produce code more easily than at any time in their careers. …
010
The IT Nerd @theitnerd.ca · 25/09/2026
Edinburgh Napier and Approov team up on smartphone security innovation A new partnership between Edinburgh Napier University and mobile cybersecurity firm Approov Limited will aim to improve smartphone security....
itnerd.blog
Edinburgh Napier and Approov team up on smartphone security innovation
A new partnership between Edinburgh Napier University and mobile cybersecurity firm Approov Limited will aim to improve smartphone security. The Edinburgh-based company has agreed a Knowledge Transfer Partnership (KTP) with ENU, which will include the recruitment of two cyber security researchers, co-funded by Innovate UK. Over the course of 30 months, Approov and Edinburgh Napier will work together to create innovative defence mechanisms and an offensive test bed – known in cyber security as 'blue team' and 'red team'.
000
The IT Nerd @theitnerd.ca · 25/09/2026
The CISA releases election security plan 40 days before midterms The CISA released its 2026 Election Infrastructure Security Plan 40 days before the November midterm elections, outlining cyber and physical threats facing election systems and federal resources available to state and local election…
itnerd.blog
The CISA releases election security plan 40 days before midterms
The CISA released its 2026 Election Infrastructure Security Plan 40 days before the November midterm elections, outlining cyber and physical threats facing election systems and federal resources available to state and local election officials. The plan identifies potential threats including cyberattacks against voter registration databases, election networks and other systems, as well as physical threats against election facilities and personnel. It recommends measures including vulnerability scanning, risk assessments, incident response planning, information sharing and the use of auditable paper ballots.
000
The IT Nerd @theitnerd.ca · 25/09/2026
Guest Post: Why are the FBI hackers so obsessed with their reputation?  By Stefanie Schappert For most ransomware and extortion gangs, the end goal has always been pretty simple: money....
itnerd.blog
Guest Post: Why are the FBI hackers so obsessed with their reputation? 
By Stefanie Schappert For most ransomware and extortion gangs, the end goal has always been pretty simple: money. Steal enough sensitive data, threaten to leak it, and hope the victim decides paying millions of dollars is better than dealing with the fallout. But what happens when money is no longer the ransom? This week, the notorious ShinyHunters hacker group announced it had breached multiple FBI systems, claiming it made off with sensitive data belonging to "almost all" FBI agents, employees, and even job applicants.
000
The IT Nerd @theitnerd.ca · 25/09/2026
TELUS brings Toy Story 5 to life in select GTA stores Toy Story 5 is gearing up for its highly anticipated release on Disney+, and TELUS is celebrating with a special in-store activation at five locations in the greater Toronto area....
itnerd.blog
TELUS brings Toy Story 5 to life in select GTA stores
Toy Story 5 is gearing up for its highly anticipated release on Disney+, and TELUS is celebrating with a special in-store activation at five locations in the greater Toronto area. Fans of all ages can step into the world of Woody, Buzz and Jessie and experience the magic of Toy Story 5. While there, they can also discover why TELUS Stream+
000
The IT Nerd @theitnerd.ca · 25/09/2026
Guest Post: Fortune 500 not so fortunate: Employee credentials leak every 100 seconds Findings from a report from NordLayer, a toggle-ready network security platform for business, reveal that credentials of Fortune 500 employees are being leaked on the dark web at an alarming rate, with the…
itnerd.blog
Guest Post: Fortune 500 not so fortunate: Employee credentials leak every 100 seconds
Findings from a report from NordLayer, a toggle-ready network security platform for business, reveal that credentials of Fortune 500 employees are being leaked on the dark web at an alarming rate, with the overall number of leaked credentials reaching nearly 10 million. The numbers are accelerating in 2026 — dated infostealer logs from this year show a new Fortune 500 credential appearing on the dark web every 100 seconds.
000
The IT Nerd @theitnerd.ca · 25/09/2026
What Canadians Need To Know About Cellphone Searches At The US Border Everyone's cellphones contains years and years of data about you. And that is likely why US Customs And Border Protection is super interested in looking at your cellphone....
itnerd.blog
What Canadians Need To Know About Cellphone Searches At The US Border
Everyone's cellphones contains years and years of data about you. And that is likely why US Customs And Border Protection is super interested in looking at your cellphone. The fact is that this can tell them a lot about you and whether they should admit you to the US. So in the interest of getting the facts out there, here's what Canadians need to know about those cellphone searches.
100
The IT Nerd @theitnerd.ca · 24/09/2026
Databricks Acquires Row Zero Databricks today announced it has acquired Row Zero, the spreadsheet built for humans and agents to work together with data....
itnerd.blog
Databricks Acquires Row Zero
Databricks today announced it has acquired Row Zero, the spreadsheet built for humans and agents to work together with data. The acquisition will expand the capabilities of Genie, Databricks’ AI coworker, which helps business teams turn data into trusted answers and actions. Genie can analyze why margins changed or produce a document on sales pipeline opportunities. With Row Zero, Genie will add a familiar spreadsheet interface that business teams can use to explore, model, and collaborate, all on a governed foundation powered by 
020
The IT Nerd @theitnerd.ca · 24/09/2026
The CISA, FBI warn critical infrastructure operators of third-party ICS risks The CISA and the FBI warned critical infrastructure operators about cybersecurity and supply chain risks associated with third-party industrial control system (ICS) integrators, urging organizations to limit access to…
itnerd.blog
The CISA, FBI warn critical infrastructure operators of third-party ICS risks
The CISA and the FBI warned critical infrastructure operators about cybersecurity and supply chain risks associated with third-party industrial control system (ICS) integrators, urging organizations to limit access to operational environments and apply the principle of least privilege. The agencies pointed to a 2025 incident in which foreign cyber actors compromised a U.S. industrial automation solutions company serving power utilities and transportation entities.
000
The IT Nerd @theitnerd.ca · 24/09/2026
Case Study: Peel Regional Police support mission critical technology with private cellular Highly connected vehicles are creating smarter transport and more intelligent fleets. From logistics to emergency services, vehicles that communicate with each other and their environments in real-time are…
itnerd.blog
Case Study: Peel Regional Police support mission critical technology with private cellular
Highly connected vehicles are creating smarter transport and more intelligent fleets. From logistics to emergency services, vehicles that communicate with each other and their environments in real-time are creating safer roads and more reliable transportation futures. Ontario's Peel Regional Police faced the challenge of preparing its 400 frontline cruisers for a future defined by in-car technology. The solution was to create a reliable, more predictable connected fleet using private LTE and Canada's Public Safety Broadband Network.
010
The IT Nerd @theitnerd.ca · 24/09/2026
New OT zero-day can take down a database with one packet, and you may not know it’s there  Ridge researchers discovered CVE-2026-42542, a high-severity vulnerability in TDengine, a time-series database used in industrial IoT, manufacturing, energy, connected vehicles and other environments that…
itnerd.blog
New OT zero-day can take down a database with one packet, and you may not know it’s there 
Ridge researchers discovered CVE-2026-42542, a high-severity vulnerability in TDengine, a time-series database used in industrial IoT, manufacturing, energy, connected vehicles and other environments that rely on machine and sensor data. The basic problem is pretty striking: an unauthenticated attacker can crash a TDengine server with a single malformed packet. No credentials, session or user interaction are required. Ridge has not yet observed exploitation or identified any attack IOCs – however, AI-aided vulnerability discovery and chaining have substantially changed the security equation, and the pace of exploitation is only expected to increase.
010
The IT Nerd @theitnerd.ca · 24/09/2026
Darktrace Launches Signal Labs to Research Emerging Risks of Enterprise AI Agents Darktrace today announced the launch of Darktrace Signal Labs, a new initiative specialized in research on behavioral security focused on emerging risks as AI systems become more autonomous....
itnerd.blog
Darktrace Launches Signal Labs to Research Emerging Risks of Enterprise AI Agents
Darktrace today announced the launch of Darktrace Signal Labs, a new initiative specialized in research on behavioral security focused on emerging risks as AI systems become more autonomous. Researchers in Darktrace Signal Labs will investigate misaligned model and agent behavior across a range of scenarios, including task drift, jailbreaks, and other adversarial attacks inside safe, sandboxed environments to better understand scenarios that trigger rogue or anomalous behavior and demonstrate how…
020
The IT Nerd @theitnerd.ca · 24/09/2026
Cloud Range Launches AI Validation Range and AI Readiness Framework Cloud Range today announced the official launch of its AI Validation Range™ and Cloud Range AI Readiness Framework™....
itnerd.blog
Cloud Range Launches AI Validation Range and AI Readiness Framework
Cloud Range today announced the official launch of its AI Validation Range™ and Cloud Range AI Readiness Framework™. Together, they give organizations a structured way to test AI models and agents in realistic environments, validate their readiness for operational responsibility and safety, and determine which roles and tasks are best handled by AI versus human experts. Recent incidents involving rogue AI agents have exposed gaps in traditional testing, with autonomous agents moving beyond intended boundaries and accessing external systems.
000
The IT Nerd @theitnerd.ca · 24/09/2026
Datadobi Adds Data Access Governance to StorageMAP, Enabling Enterprises to Answer the Critical Question: “Who Has Access to What?” Datadobi today announced the general availability of Data Access Governance (DAG) within StorageMAP. The new capability gives organizations visibility into who has…
itnerd.blog
Datadobi Adds Data Access Governance to StorageMAP, Enabling Enterprises to Answer the Critical Question: “Who Has Access to What?”
Datadobi today announced the general availability of Data Access Governance (DAG) within StorageMAP. The new capability gives organizations visibility into who has access to their unstructured data and whether that access aligns with corporate policy. It extends Datadobi's ability to help enterprises discover, align, and operationalize data across fragmented environments as their intelligence and orchestration layer. As AI initiatives, cyber threats, and rising data complexity expose the limits of traditional approaches, DAG addresses a critical gap: organizations cannot govern, protect, or extract value from data they cannot see or control.
000