Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence.
According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products.
Vulnerabilities have been patched in products such as Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite.
Security fixes are also available for Enterprise Manager, Financial Services Applications, Food and Beverage Applications, Fusion Middleware, Analytics, HealthCare Applications, Hospitality Applications, Java SE, JD Edwards, MySQL, PeopleSoft, Retail Applications, Siebel CRM, Supply Chain, Systems, Utilities Applications, and Virtualization.
Roughly 600 of the patches are for vulnerabilities that can be exploited remotely without authentication. Hundreds of security holes have been assigned a critical severity rating.
The highest numbers of vulnerabilities were patched in E-Business Suite (410), Fusion Middleware (355), Communications (168), and PeopleSoft (84).
Advertisement. Scroll to continue reading.
Considering that external researchers have only been credited for discovering a few dozen vulnerabilities, a vast majority of the newly patched flaws were found internally, likely with the aid of AI.
The company said it’s applying this AI-driven vulnerability work across its own software and services, Oracle Health, and the open source components it develops and relies on.
Organizations must install the latest patches as soon as possible, as threat actors often exploit Oracle product vulnerabilities in their attacks. Examples include the exploitation of a PeopleSoft zero-day and a recently patched EBS vulnerability.
Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
The Anubis ransomware group has taken credit for the disruptive attack on Coca-Cola subsidiary Fairlife and is threatening to leak stolen data unless a ransom is paid.
Coca-Cola revealed last week that production at dairy company Fairlife had been suspended due to a ransomware attack. The full impact of the incident was still being assessed at the time of disclosure.
The Anubis group listed Coca-Cola and Fairlife on its leak website on July 20. The cybercriminals claimed to have “locked” servers – this likely means they have encrypted files – and exfiltrated 1 TB of “confidential data”.
Anubis hacks Coca-Cola subsidiary Fairlife
The hackers said they can help the company restore its systems within hours if it agrees to pay a ransom. Coca-Cola has been given a week to pay up, or the stolen data will be leaked.
SecurityWeek has reached out to Coca-Cola for comment.
Active since December 2024, the Anubis ransomware group has listed roughly 100 targeted organizations on its website.
Advertisement. Scroll to continue reading.
Like many groups, Anubis uses a double-extortion model that involves encrypting files on compromised systems and exfiltrating valuable data to increase its chances of obtaining a ransom from victims.
However, the cybercrime gang caught the attention of the cybersecurity industry for a ‘wiper mode’ feature enabling the attackers to permanently delete victims’ files and prevent their recovery.
CTEM: dalla rincorsa delle vulnerabilità al governo continuo dell’esposizione
CTEM, acronimo di continuous threat exposure management, nasce da una constatazione scomoda per chi difende le organizzazioni: si applicano patch sempre più in fretta, si automatizzano controlli, si chiudono falle a ritmo crescente, eppure l’esposizione reale al rischio non diminuisce in proporzione. La ragione è che la sicurezza viene ancora gestita come una sequenza di episodi, una vulnerabilità dopo l’altra, anziché come una condizione continua da misurare e ridurre. È esattamente lo spostamento di prospettiva che Gartner ha riassunto nella formula “gestire le minacce, non gli episodi”, e attorno al quale ha costruito un processo a cinque fasi pensato per portare ordine in un’attività che troppo spesso resta reattiva.
Il punto non è tecnologico ma metodologico. Gli strumenti per scoprire vulnerabilità esistono da vent’anni e funzionano. Quello che manca, nella maggior parte dei programmi di sicurezza, è un criterio stabile per decidere cosa conta davvero, in quale ordine intervenire e come verificare che l’intervento abbia ridotto il rischio anziché solo accorciato una lista. Il CTEM prova a colmare proprio questo vuoto.
Perché la gestione delle vulnerabilità non riduce l’esposizione
La gestione delle vulnerabilità tradizionale produce volume: scansioni periodiche, migliaia di CVE ordinati per punteggio CVSS, ticket che si accumulano più velocemente di quanto i team riescano a chiuderli. Il problema è che il numero di falle individuate non dice nulla sul rischio effettivo. Una vulnerabilità con punteggio alto su un sistema isolato e privo di dati critici può attendere; una falla apparentemente minore su un asset esposto e collegato a informazioni sensibili può essere la porta d’ingresso di un attacco.
Ridurre l’esposizione richiede un cambio di unità di misura: non quante vulnerabilità sono state corrette, ma quanto è diminuita la probabilità concreta che un attaccante raggiunga ciò che ha valore per l’azienda. Qui la differenza con la semplice riduzione della superficie d’attacco è sottile ma sostanziale: ridurre la superficie è un obiettivo, mentre il CTEM è il processo che decide quale porzione di quella superficie vada affrontata per prima, con quali risorse e con quale prova di efficacia.
Le cinque fasi del CTEM
Gartner articola il CTEM in un ciclo di cinque fasi, da percorrere in modo iterativo e non una sola volta. La forza del modello sta proprio nella ripetizione: ogni giro affina le priorità alla luce di come sono cambiati l’infrastruttura, le minacce e i controlli.
Scoping
La prima fase definisce il perimetro: quali asset, sistemi e superfici meritano attenzione continua. Gartner invita a guardare oltre i confini tipici della gestione delle vulnerabilità, includendo elementi meno tangibili come gli account social aziendali, i repository di codice online e i sistemi integrati con la catena di fornitura. Due aree fanno da terreno ideale per un primo pilota: la superficie d’attacco esterna, dal perimetro relativamente delimitato, e la postura di sicurezza delle applicazioni SaaS, diventata critica man mano che il lavoro distribuito ha spostato i dati aziendali fuori dal data center.
Discovery
La seconda fase scopre asset, vulnerabilità, configurazioni errate e altri rischi all’interno del perimetro definito. Qui si annida il primo errore ricorrente, secondo Gartner: confondere lo scoping con la discovery. Il volume di asset e falle individuati non è un successo in sé. Trovare di più non serve se non si è prima scelto bene cosa cercare in base al rischio di business e all’impatto potenziale.
Prioritizzazione
L’obiettivo della terza fase non è correggere ogni singolo problema, traguardo irraggiungibile e per giunta inutile. La prioritizzazione pesa urgenza, presenza di controlli compensativi, tolleranza per la superficie d’attacco residua e livello di rischio per l’organizzazione. Si tratta di identificare gli asset ad alto valore e concentrare il trattamento su quelli, accettando in modo consapevole che una parte del rischio resti aperta.
Validazione
La quarta fase è quella che distingue il CTEM da un esercizio teorico: verificare sul campo che le ipotesi reggano. Significa confermare che un attaccante possa davvero sfruttare una vulnerabilità, mappare i percorsi d’attacco che conducono all’asset critico e accertare che il piano di risposta sia abbastanza rapido e robusto da proteggere il business. È il terreno delle tecnologie di validazione, dalla breach and attack simulation al red teaming, spesso ancorate a una tassonomia condivisa delle tecniche avversarie come la matrice MITRE ATT&CK. La validazione trasforma una lista di rischi presunti in una mappa di rischi dimostrati.
Mobilitazione
L’ultima fase riguarda persone e processi, non strumenti. Gartner avverte che non ci si può affidare interamente alla promessa della remediation automatica: per la maggior parte delle situazioni serve che i team facciano proprie le conclusioni del programma e le traducano in azione. L’obiettivo della mobilitazione è ridurre gli attriti nelle approvazioni e nei processi di mitigazione, documentando i flussi di approvazione tra i diversi team. È la fase dove molti programmi si arenano, perché tocca le abitudini organizzative più della tecnologia.
Un programma, non un prodotto
La diffusione del CTEM ha generato un equivoco prevedibile: presentarlo come una categoria di prodotto da acquistare. Sul mercato si moltiplicano piattaforme che si autodefiniscono soluzioni CTEM, ma il CTEM non è un software. È un processo che orchestra strumenti diversi, dalla scoperta della superficie d’attacco esterna alla postura SaaS, dalla prioritizzazione basata sul rischio fino alla breach and attack simulation. Chiamare CTEM un singolo prodotto significa svuotarlo del suo contenuto, che è proprio la capacità di tenere insieme tecnologie e team attorno a un criterio unico di priorità.
La distinzione ha conseguenze pratiche. Un’organizzazione può dotarsi degli strumenti più avanzati e restare priva di un programma CTEM, se manca la fase di prioritizzazione condivisa e la mobilitazione che traduce le evidenze in interventi. Vale anche il contrario: si può avviare un CTEM credibile su un perimetro ristretto con strumenti già in casa, purché il ciclo delle cinque fasi venga percorso davvero e non solo nominato.
Cosa cambia per chi governa il rischio
Quando Gartner ha formulato il modello, ha accompagnato il CTEM con una previsione netta: entro il 2026 le organizzazioni che orientano gli investimenti di sicurezza su un programma di gestione continua dell’esposizione avrebbero avuto una probabilità tre volte minore di subire una violazione. Vale la pena leggerla per ciò che è, una proiezione e non una misura: oggi che il 2026 è arrivato, non esiste uno studio indipendente che certifichi quel rapporto specifico tra adottanti e non adottanti, e la stima va trattata come indicazione di tendenza. La logica operativa, però, resta solida: concentrare le risorse su ciò che è davvero esposto e sfruttabile riduce il rischio in modo più efficace che inseguire ogni falla.
Per chi governa la sicurezza in Italia e in Europa, il modello intercetta una pressione normativa concreta. La logica di NIS2 e di DORA, con il loro impianto di gestione del rischio continua e proporzionata, chiede esattamente ciò che il CTEM prova a sistematizzare: non un adempimento una tantum, ma un processo ricorrente di identificazione, prioritizzazione e verifica. Il legame con DORA è particolarmente stretto sulla fase di validazione: il threat-led penetration testing richiesto agli operatori finanziari mappa quasi uno a uno sulla logica di verifica avversaria del ciclo. Il CTEM non è una risposta di conformità, e non va presentato come tale, ma offre un’ossatura operativa coerente con quella direzione regolatoria.
È la stessa tensione che Jeremy D’Hoinne, VP Analyst di Gartner, pone al centro del modello. Il CTEM, osserva, è un approccio sistemico pragmatico ed efficace per raffinare di continuo le priorità e camminare sul filo tra due realtà inconciliabili della sicurezza moderna: un’organizzazione non può correggere tutto, né può essere certa di quali interventi di remediation possa rinviare senza correre un rischio. È in questa frase che il CTEM rivela la propria natura, non un metodo per eliminare il rischio ma per amministrarlo con cognizione.
Il vero ostacolo, alla fine, non è la disponibilità degli strumenti né la comprensione del metodo. È la mobilitazione, cioè la capacità di un’organizzazione di trasformare evidenze tecniche in decisioni condivise e interventi tempestivi. Per questo il CTEM va letto meno come una tecnologia e più come una disciplina di governo del rischio: sposta la domanda da quante vulnerabilità abbiamo chiuso a quanto siamo davvero meno esposti rispetto al giro precedente. È un cambio di paradigma che premia chi smette di rincorrere gli episodi e inizia a governare l’esposizione come una condizione permanente.
Per anni l’idea di un attacco informatico condotto interamente da un agente di Intelligenza Artificiale è rimasta confinata ai laboratori di ricerca e alle presentazioni dei vendor. Oggi non è più così. La piattaforma Hugging Face, punto di riferimento mondiale per lo sviluppo e la distribuzione di modelli AI open source, ha confermato di essere stata colpita da quello che descrive come un attacco condotto dall’inizio alla fine da un sistema autonomo di agenti AI. L’episodio rappresenta molto più di una violazione informatica: è probabilmente il primo caso documentato in cui un’infrastruttura di produzione di una realtà di una certa rilevanza viene compromessa da un sistema capace di pianificare ed eseguire autonomamente una campagna offensiva complessa, senza che un operatore umano debba guidarne ogni fase.
L’attacco è partito dalla supply chain dei dati
Secondo quanto comunicato da Hugging Face, gli aggressori hanno sfruttato una superficie d’attacco peculiare delle piattaforme AI: la pipeline che elabora dataset caricati dagli utenti. Un dataset malevolo ha abusato di due percorsi di esecuzione del codice, un loader che consentiva l’esecuzione di codice remoto e una vulnerabilità di template injection nella configurazione del dataset, ottenendo l’esecuzione di codice su un nodo di elaborazione. Da quel momento il comportamento dell’attaccante è stato quello tipico di un’Advanced Persistent Threat: escalation dei privilegi, raccolta di credenziali cloud e di cluster, movimento laterale tra diversi sistemi e accesso non autorizzato a dataset interni e credenziali di servizio. Hugging Face precisa di non aver trovato evidenze di manomissioni ai modelli pubblici, ai dataset disponibili agli utenti, agli Spaces o alla propria software supply chain, ma l’incidente dimostra quanto le piattaforme AI introducano superfici di attacco nuove rispetto alle applicazioni tradizionali.
La novità non è la vulnerabilità, ma chi ha guidato l’attacco
La vulnerabilità sfruttata non rappresenta l’aspetto più innovativo dell’incidente. Ciò che cambia realmente è il modo in cui è stata sfruttata. Secondo la ricostruzione dell’azienda, l’operazione è stata eseguita da un framework agentico capace di svolgere decine di migliaia di azioni distribuite su una moltitudine di ambienti temporanei, con infrastrutture di comando e controllo che migravano automaticamente tra servizi pubblici per ridurre la probabilità di essere individuate.
In pratica, l’AI non si è limitata a generare codice o suggerire una sequenza di exploit: ha eseguito autonomamente una campagna offensiva articolata, adattandosi durante le diverse fasi dell’intrusione. È lo scenario dell’agentic attacker di cui il settore della cybersecurity discute da tempo e che oggi sembra essersi concretizzato.
L’AI ha difeso Hugging Face da un’altra AI
L’altro elemento interessante dell’incidente è che anche la risposta è stata in larga parte automatizzata. Hugging Face spiega di aver utilizzato sistemi basati su LLM per analizzare la telemetria di sicurezza, correlare gli eventi e ricostruire rapidamente la cronologia dell’attacco. Gli agenti di analisi hanno elaborato oltre 17.000 eventi, permettendo ai team di incident response di individuare gli indicatori di compromissione e distinguere le attività realmente dannose da quelle create per depistare gli analisti. Secondo l’azienda, un’attività che normalmente richiederebbe diversi giorni è stata completata in poche ore grazie all’automazione. Il risultato è un assaggio di quello che potrebbe diventare il nuovo paradigma della cybersecurity: AI contro AI, con attaccanti e difensori che operano entrambi a velocità macchina.
Il problema tanto temuto dei guardrail ciechi
Tra gli aspetti più curiosi emersi dal post mortem c’è un problema che fino a poco tempo fa sarebbe sembrato marginale. Durante l’analisi forense, Hugging Face ha inizialmente provato a utilizzare modelli commerciali accessibili tramite API. Tuttavia, le richieste contenevano exploit, payload, comandi di attacco e indicatori di compromissione reali: elementi che i sistemi di sicurezza dei modelli hanno interpretato come contenuti pericolosi, bloccandone l’elaborazione.
Per completare l’analisi, l’azienda ha quindi utilizzato un modello open-weight eseguito sulla propria infrastruttura, evitando sia le limitazioni imposte dai guardrail sia il trasferimento all’esterno di dati sensibili e credenziali compromesse. Questo ci riporta a un tema che è stato affrontato più volte dall’arrivo degli LLM al grande pubblico: è giusto limitarne le capacità quando gli unici che ne fanno davvero le spese sono gli utenti che li usano per scopi leciti? Ovviamente, la risposta è lunga e articolata, ma sembra abbastanza ovvio che qualcosa debba esser ripensato, a partire dalla disponibilità di servizi AI deputati all’analisi forense e al blue teaming.
Le piattaforme AI diventano una nuova superficie di attacco
L’attacco ad HuggingFace ci dice molte cose. Innanzitutto, la scelta del bersaglio è quantomeno curiosa e ovviamente tesa a dimostrare che con l’IA non si scherza. Secondo il mio modesto parere, questo attacco è stato un atto dimostrativo per mettere in guardia un’industria che è ancora largamente indecisa se correre a più non posso o imparare qualcuna delle dure lezioni che il cybercrimine ha impartito negli anni passati. Inoltre, sottolinea che la diffusione degli agenti AI amplia la superficie di attacco ben oltre il già tartassato modello linguistico, ma comprende dataset, memoria dell’agente, strumenti esterni, protocolli come MCP, supply chain delle estensioni e contesto operativo. Le minacce si spostano sempre più dal codice ai dati e alle interazioni runtime, rendendo necessari approcci di sicurezza che trattino ogni elemento esterno come potenzialmente non affidabile. Questo significa che la protezione delle piattaforme AI deve (sì, già oggi) estendersi ben oltre i tradizionali controlli su endpoint e reti, includendo controlli specifici sulla provenienza dei dati, sull’esecuzione degli strumenti e sulle informazioni che alimentano gli agenti.
Una nuova fase per la cybersecurity che potremmo non esser pronti ad affrontare
Il caso Hugging Face non dimostra che gli attaccanti abbiano improvvisamente acquisito capacità “sovrumane”. Dimostra però che l’automazione sta riducendo drasticamente il costo operativo degli attacchi e che fare automazione complessa oggi diventa sempre più semplice. Un sistema autonomo può eseguire migliaia di tentativi, adattare continuamente la propria strategia, sfruttare nuove opportunità e operare ventiquattro ore su ventiquattro senza la supervisione costante di un essere umano. Per le organizzazioni significa che i tempi di reazione disponibili continueranno a ridursi. Se gli attacchi si muovono a velocità macchina, anche il rilevamento, la correlazione degli eventi e la risposta dovranno essere sempre più automatizzati. Nik Zur (CTO di Palo Alto) lo dice da tempo (ed era il suo slogan nel lancio di una serie di prodotti di qualche tempo fa), ma la massima continua a restare valida. Solo a marzo ho parlato con il capo dei laboratori di Mandiant che mi diceva che “ancora non accade, ma accadrà in futuro”. Il futuro è arrivato dopo neanche 4 mesi… Il problema più grande della sicurezza (e di tutta la società umana) è riuscire a tenere il passo dell’evoluzione… e non sarà facile.
Apps targeted at US troops contain Chinese and Russian code
The new study takes a first look at one piece of that exposure: what actually sits inside the apps built and marketed specifically for the military.
“We are grateful for the opportunity to bring greater attention to these issues,” says Joshua Shinkle, a Purdue University PhD researcher and the study’s lead author. “We hope the research helps military-affiliated personnel, developers, and platforms make more informed privacy decisions and encourages continued discussion with developers, platforms, and policymakers about how to address these gaps.”
The researchers examined more than 220 such apps—from uniform guides and promotion-exam prep to banking and dating apps—pulled from the Google Play store and military subreddits. Nearly two-thirds—or 64 percent—contained third-party code, known as SDKs: prebuilt software components, typically used for analytics and advertising, that can also track user behavior, including their locations, and share that information with outside companies.
Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings, the researchers found.
The most common SDKs came from Google and Facebook, the two companies that dominate US digital advertising. But 76 turned up in all, including code traced back to China, Russia, Israel, India, Germany, and others. Roughly 7 percent of the apps carried third-party code from a nation considered adversarial by the Pentagon.
Twelve of the apps contained HMS Core, a Huawei software kit that advertises the ability to map user locations, deliver ads, and store images and video. Several were built for state National Guard organizations.
The researchers observed no data actually going to Huawei servers. But an SDK can be updated remotely at any time. Code that is dormant today can still be spyware tomorrow. In at least one case, noted by the study, the Huawei code arrived without the app’s developer’s knowledge, smuggled in as a dependency in a commercial notification tool.
79% of Ransomware Attacks Start with Compromised Identities
A new report from Sophos found the most common method malicious actors use to enact ransomware is the abuse of compromised credentials. 79% of incidents exploited legitimate user logins and identities in order to gain initial access.
The research also found that malicious actors are leveraging identities in several ways, such as intruding on systems or applications (38%), remote device logins (30%), firewalls (21%), VPNs (8%) and IoT devices (3%) for initial access.
Key findings from the report include:
Malicious emails were the entry point for ransomware in 26% of incidents, showing an increase from 19% of incidents in 2025.
Phishing attacks caused 24% of incidents, often to steal login credentials. This is an increase from the last year, in which phishing attacks represented 18% of incidents.
Brute force attacks remained relatively even from the previous year (22% of incidents in 2025), accounting for 23% of incidents this year.
The exploitation of known security vulnerabilities decreased from from 32% last year to 18% in 2026.
62% of cybersecurity leaders cite network security gaps as the reason cyberattacks go undetected. 58% reported their organization was inhibited by lack of resources or employee expertise, and 57% believe the organization had not implemented sufficient cybersecurity solutions.
Below, security leaders weigh in on these findings.
Security Leaders Weigh In
Chandra Gnanasambandam, Chief Technology Officer at SailPoint:
This data confirms what we’ve been saying: 79% of ransomware attacks start with identity — nearly double malicious email and phishing combined. That’s exactly why those like us in the industry have been ringing the identity bell for years. This is the new normal. Attacks that once took a year to succeed now take about an hour, cybercrime has industrialized, and with 95% of access still standing rather than granted just in time, identity is the obvious weak point. It’s why security is undergoing one of its biggest shifts, moving from 25 years of human-centered defense to a human-plus-AI world that demands adaptive identity and zero standing privilege as baseline.
Shane Barney, Chief Information Security Officer at Keeper Security:
Stolen credentials are now the dominant ransomware entry point, and the trend is accelerating. Once attackers obtain a legitimate identity, they can move through an environment undetected, escalating privileges and staging ransomware before most teams know something is wrong.
Organizations need to recognize that identity is now the primary security perimeter. Strong password policies, Multi-Factor Authentication (MFA) and continuous monitoring remain foundational, but they’re no longer sufficient on their own. Security teams need visibility into who is accessing critical systems, whether that access is appropriate and how privileged accounts are being used. Applying least-privilege principles, eliminating standing administrative access and continuously validating identities significantly reduces the opportunities attackers have to abuse stolen credentials.
The goal isn’t just stopping the initial breach. It’s limiting the blast radius when credentials are compromised. Organizations that can’t see who has access to what, and can’t revoke it fast, will keep finding out after the fact. That’s what zero trust and strong identity governance are designed to prevent.
James Maude, Field CTO at BeyondTrust:
In order to effectively deal with ransomware and other threats, we need to invest more in shifting left. We must think more about securing identities and access to reduce our attack surface and blast radius in the event of compromise, rather than just thinking post breach. Ransomware and other threats are only as effective as the privileges and access they manage to acquire. Therefore, if we can implement better hygiene, and focus on least privilege, then threat actors are far less likely to ransomware us in the first place.
Trey Ford, Chief Strategy and Trust Officer at Bugcrowd:
Criminals have established a scalable business model, and we expect to see ransomware attack volume continue to grow. We also need to bear in mind that there will be a gap in reported incidents versus overall ransomware incidents. Larger targets, with bigger payout potential, will have seen the most aggressive corporate investment (process and technology) mitigating exposure to this attack pattern – it is still an unsolved space.
Mika Aalto, Co-Founder and CEO at Hoxhunt:
Phishing is rarely the end goal. It’s typically the front door to something much bigger, including data theft, cloud compromise, or ransomware. Here’s an analogy: If ransomware is the explosion, phishing is often the spark.
Recent research found a step change at the turn of 2025 to 2026, when AI-generated phishing surged 14-fold almost overnight. The big shift isn’t brand-new tactics and zero-day messaging, it’s the modernization of old attacks. Traditional phishing kits are being upgraded with cleaner formatting, better writing, and more personalized messaging that can be generated at scale. Phishing never really went away, it simply got an upgrade. With that being said, people are trained to obey authority, and phishing attacks are designed to push people into bypassing normal checks. Organizations need to normalize ‘see something, say something’ behavior and make verification frictionless.
Phishing has evolved beyond static text and awareness must do the same. The entire concept of ‘security awareness training’ is outdated if it stops at awareness. The next generation of defense is behavioral, not informational. We’re moving from telling people what to do to shaping what they actually do, in real time. We are building an essential set of security reflexes and instincts.
Empirical Security Raises $25 Million in Series A Funding
Cybersecurity startup Empirical has raised $25 million in a Series A funding round that brings the total raised by the company to $37 million.
The new investment round was led by Brightmind Partners, with additional support from Costanoa Ventures, Hyde Park Angels (HPA), and other investors.
Founded in 2024, Chicago-based Empirical will use the fresh funding to accelerate the development of its two flagship products that help organizations predict and identify threats in the agentic AI era.
Empirical provides organizations with Foundation, a global cybersecurity model that monitors over 18,000 exploited CVEs for threat prediction, and Radiant, a predictive engine that can identify threats relevant to each organization’s environment.
The predictive models, Empirical says, deliver the intelligence that organizations need to discover risks within background noise.
According to Empirical, its solutions provide security teams, particularly in technology, healthcare, and financial services, with transparent, data-driven insights that enable them to measure and manage cyber risks.
Advertisement. Scroll to continue reading.
Enhanced by AI and tailored to each organization’s unique environment, the predictive models help prioritize remediation through deeper forecasting, evidence-based risk analysis, and actionable intelligence.
Empirical was co-founded by CEO Ed Bellis, who co-founded Kenna Security, CTO Michael Roytman, who served as Chief Data Scientist at Kenna, and Chief Data Scientist Jay Jacobs, who co-created the Exploit Prediction Scoring System (EPSS).
“[At Kenna] we helped pioneer the category of risk-based vulnerability management, but it became clear that defending against AI-driven threats and the growing volume of potential exploits would require a fundamentally new approach. Today, we finally have the technology to give security teams predictive capabilities that weren’t possible before, and we came together to build that future,” Bellis said.
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
SecurityWeek today announced the launch of the Critical Impact Awards, a new recognition program honoring the individuals, organizations, and technologies delivering measurable impact and contributions in industrial cybersecurity. Winners will be announced live at the 2026 ICS Cybersecurity Conference, taking place October 6–8, 2026, at the W Nashville, as the event celebrates its 25-year anniversary.
Unlike pay-to-play awards programs that have eroded trust across the technology industry, Critical Impact Awards are earned, not bought. Every nomination is reviewed by an independent judging panel against published criteria. Sponsorship has no influence on outcomes, and the panel publishes its rationale for each honoree, making the Critical Impact Awards the most credible recognition program in the cybersecurity industry.
“The people defending industrial and critical infrastructure rarely seek the spotlight, and too many awards programs reward marketing budgets rather than merit,” said Mike Lennon, Managing Director at SecurityWeek and Director of the ICS Cybersecurity Conference. “The Critical Impact Awards were designed to fix that, with recognition based on outcomes and evidence, and judged by practitioners, with nothing for sale.”
Open to All. Based on Merit
Nominations are completely free and open to everyone: peers, leaders, vendors, partners, customers, and journalists. Self-nominations are welcome. Judging is based on the evidence presented, not on who submitted it.
Independent Judging Panel
Advertisement. Scroll to continue reading.
The Critical Impact Awards are judged by an independent panel of industrial cybersecurity insiders, including CISOs, OT security practitioners, and critical-infrastructure operators. The panel sets the criteria, reviews every nomination against them, and publishes its rationale for each honoree.
Award Categories
The inaugural Critical Impact Awards will honor achievement across two groups of categories:
Technical Excellence & Research
Best OT Vulnerability Research
Best OT Detection & Threat Research
Most Innovative OT Defense
Best OT Security Innovation
Best ICS Incident Response
Community & Leadership
ICS/OT Defender of the Year
Community Champion / Mentor of the Year
Lifetime Achievement in Industrial Security
Emerging Leader in ICS Security
OT/ICS Collaboration Excellence Award
Nominations and Timeline
Nominations close on August 31, 2026. Finalists will be notified in advance, and winners will be announced live on stage at the 2026 ICS Cybersecurity Conference in Nashville. To submit a nomination or review the judging criteria, visit https://www.criticalimpactawards.com/.
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
A recently discovered piece of malware abuses the Microsoft 365 calendar for command-and-control (C&C) communication, Group-IB reports.
Dubbed HollowGraph, the malware is believed to be part of a larger toolkit and is likely linked to Cavern Manticore, an Iran-nexus threat actor that Check Point detailed earlier this month.
The malware’s communication mechanism relies on the Microsoft Graph API and a compromised 365 account in Israel to hide its C&C communication within legitimate traffic.
“Using the Microsoft Graph API, it treats the compromised mailbox’s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached,” Group-IB explains.
The payloads are attached to events as files, and the events are dated far in the future (13 May 2050) to avoid alerting the mailbox owner. The malware uses hybrid RSA + AES encryption to secure the payloads.
Additionally, HollowGraph retains a secondary communication channel, performing DNS tunneling to refresh its configuration and Microsoft Entra ID (Azure AD) credentials it uses for authentication.
Advertisement. Scroll to continue reading.
Group-IB identified 12 HollowGraph victims, including three that were actively communicating with the attackers’ infrastructure. The earliest observed communication occurred on June 3, suggesting that the malware has been deployed in attacks since at least last month.
“The recovered indicators — an Israeli mailbox used for exfiltration and malware samples uploaded from Israel — suggest a focused interest in Israeli entities rather than broad, opportunistic compromise,” the company notes.
HollowGraph never reaches out to an attacker-controlled server for payload delivery. Instead, it relies on two supported commands: ‘send’ to generate calendar appointments with attached files, and ‘get’ to search for appointments planted by the operator and download new instructions.
The malware’s hardcoded configuration, which contains the Microsoft Entra ID tenant ID, client ID and secret, target mailbox address, C&C domain, and two RSA keys, is written to disk as logAzure.txt upon execution.
Based on command format and structure, Group-IB believes that HollowGraph is part of a variant of the Cavern framework, but attributes it to the Iran MOIS-linked OilRig subgroup Lyceum (also known as Hexane and SiameseKitten) with low confidence.
“Based on the evidence currently available, we cannot confidently attribute this activity to any previously identified threat actor. However, our analysis identified several technical similarities with the Iranian-nexus threat actor Lyceum. While these overlaps are noteworthy, they are not sufficiently unique to support a high-confidence attribution,” Group-IB notes.
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
Korber AG is the holding company of a diverse German technology and manufacturing organization with around 13,000 employees in 100 locations around the world.
“Take Pharma,” comments Andreas Gaetje. “Probably every vaccine you ever received has been through our machines.” Korber services companies that supply consumers. So, despite its size and importance, it is rarely known to or recognized by the eventual consumer.
Gaetje is the CISO at Korber AG.
The route to CISO
“I never planned to make a career in cybersecurity,” he said. “When I started my career, I was more focused on economics and business politics, and more likely and expectant of finding a job in public services.”
But the reality of life often reshapes expectations. He was young and needed money now, rather than from future expectations. It was the mid-1990s, when the internet had newly transitioned from an elite playground to a fundamental tool for business and people. Email became the de facto method of communication.
“I said to myself, Okay, let’s maybe do something in the computer business,” he continued. This entry route is unlike many of today’s leading CISOs, who started by being gifted an early PC and teaching themselves how to use it and the internet and get free online gaming time. But that didn’t matter too much to Gaetje. “I’m not the deepest bit-crawler – that’s just not who I am,” he said.
Advertisement. Scroll to continue reading.
He looked for a profession where he could combine his initial interest in economics and the politics of business with information technology. So, he joined a consulting firm.
But by the early 2000s, he decided that if he really wanted to focus on business inside of IT, he would need to focus on just one industry sector. “The best industry at this point in time, where IT was really crucial,” he recalled, “was the finance industry. I joined an insurance company.”
He started as an auditor, learned about the business and figured out how business and IT can work together. At that time, cybersecurity hadn’t become the major occupation it is today. “ITsec and audit had a natural affinity. ITsec was primarily about compliance – it wasn’t yet the business threat it has since become. My knowledge of business, information technology and audit put me in a good place when cybersecurity began to kick off. At that point, I was asked if I wanted to manage the growing information security area.”
Andreas Gaetje, CISO, Körber AG
It was in the 2010s that, in his own words, “The fun started.” This was the era of new large-scale cyberattacks, including WannaCry and NotPetya. “It was very clear: we weren’t talking about a simple compliance issue anymore. This was a serious business threat. Cybersecurity had become a hot topic. It was complex, innovative, and really interesting to work in.”
By 2018, Gaetje had become CISO at Korber IT Solutions. In 2019, he became CISO at Korber AG. The inexorable rise of someone starting with an interest in economics and business politics to the chief of cybersecurity in a major international group proves one thing: you can be a security leader without ever being ‘a deep bit-crawler’ provided you have a deep understanding of business and the function of IT and security.
What good career advice did Andreas Gaetje receive on his career path?
“Much,” he said, “but the most recent was what brought me to Korber. It was this: if you really want to understand security, don’t stay too long in a single company or a single industry sector.”
It was good advice, he continued. Different companies and different sectors have different risk profiles – and if you stay too long in one place, your mind may get stuck in a rut. Without wider experience, you may not be able to change how you think as fast as the attackers change how they attack.
“It’s what made me move from the insurance industry into manufacturing and machine building. I wanted to learn something else, to experience something new, and do something different.”
Becoming a leader
Working in a profession is different than leading in that profession. Leadership skills go beyond pure subject knowledge – and considering what makes a leader is a lesson in how to be a leader. Are leaders born, tutored, or self-taught?
“I’m not a born leader. I would never consider that,” said Gaetje. “But I have a clear understanding about leadership and what it is. My view is that a leader is someone who provides direction to others, or a vision of what and how something can be achieved.”
That’s an interesting idea. It suggests that a leader is fundamentally the person with the dominant personality. Whenever a group of more than one person is involved, one person emerges as the de facto leader. As the group expands, pure dominance must be enhanced with additional characteristics to justify that dominance.
“It’s something you can learn. It’s not something that comes out of the blue. I learned and enhanced that learning with training courses. But of course, your personality is also important. You need to be reliable – you need to be a person that people trust, otherwise it just doesn’t work.”
It’s basically a strong personality that engenders trust from others. “The rest,” he said, “is something you can learn – and I had to learn it.”
Becoming a leader is something most people can achieve, provided they have the intent and personality and training to do so. But achieving leadership needn’t be a formal management position. The function is not in the title. “You’re a leader, even if it’s a thought leader driving and directing other people in a specific direction.”
The leader’s team
Leaders typically emerge from within a team as their careers progress. That relationship changes when you reach C-level leadership – now you largely get to choose and shape your own team. But building that team is not necessarily simple: the ‘skills gap’ in cybersecurity in 2025 was estimated to be between 2.8 million and 4.8 million.
“In recruiting your team, you have a wish list, and then you have reality – and unfortunately, they don’t always fit together,” he explained. “But there is one requirement that is constant across all candidates of whatever experience: I need people who want to learn.”
The cybersecurity world, he said, is evolving rapidly in both attacks and attack paths. “It’s incredible how fast things change. So, what I always need are people who are engaged, can think out of the box, and want to go the extra mile to understand what’s going on.”
This is not a nine-to-five job with predefined procedures. “Cybersecurity is something where you must learn something new every day, and I need people with a desire to learn.” Training and career advice he can and does provide; but that initial personality spark of curiosity and enthusiasm he cannot. “So, whether I’m looking for an engineer, an analyst or some junior position, experience is good, but enthusiasm to learn is necessary.”
Would he employ a hacker?
“That depends,” he answered. “The hacker mentality comes with that built-in curiosity coupled with an ability to worry at a problem until it is solved. But there are two flavors of hacker – what we might call black and white.”
He simply isn’t comfortable employing someone with a history of malicious activity in Korber. “So, white hackers I would employ; blackhats, no.”
What career advice would Andreas Gaetje give ambitious members of his team?
“Be curious. Things are really changing. If you think you know everything about anything, you’re wrong. That’s never true. There’s always something new coming for you to learn and experience.”
Biggest concerns today
His primary concern today is simply the speed of new technology development.
“Just think about the many things you’ve learned in the last few weeks, about new developments, new products and new techniques that have been deployed to the public. AI is an example – we learn new things about the potential of generative AI and agentic AI every week. What used to occur over a period of two years or more now happens in a couple of weeks.”
AI is particularly challenging, because it is used by both attackers and defenders. Attackers are using AI to increase the speed, scale and sophistication of attacks. Defenders are using their own AI to defend against adversarial AI, while those very defenses can be manipulated by attackers in different attacks. Shadow AI (AI systems installed but unknown to the IT and security departments) is proliferating.
“The pace of new technology is truly hard to manage. For each new technology you must find time to learn and understand it – but that’s on top of everything else you’re already doing. And it’s not just you – everyone on your team must find time to understand the new technology, and you must personally motivate them to do so when they are already fully occupied.”
AI is expected to reduce staff requirements. Will it have any effect on the role of the CISO?
“I think not. I think the role of cybersecurity, and even my own role will be much more important in the future than it is today. But it may change. AI is growing throughout the business and creating problems too widespread for the security team to handle alone. So, we will have to bring other parts of the business into play. Our product development team, our software developers, they all need to be in play with security to protect our own innovations going forward.”
Is increased use of AI affecting skill levels generally?
“It’s not a new question – it’s common with all new technologies. I remember we worried the arrival of Excel would cause people to lose the ability to do math for themselves.” That never really happened. “But this may be a bit different with AI,” he continued. “Consider our coders. AI coding assistants require prompt engineers and architects above programmers – and that can be a problem. How do you bring people from this level to the next level if they are not able to program on their own?” (There are separate problems about the security of code generated by AI assistants.)
Gaetje doesn’t believe this problem is limited to programmers – there will be a similar issue for analysts in the SOC. The standard belief is that AI will collapse the SOC tier hierarchy. There will be no need for traditional tier 1 analysts to perform triaging because that will now be done by AI systems.
“If the security analyst job can be done via an agentic AI tool, then how will analysts learn how to analyze an event? Maybe in the future, if we just rely on AI, we will lose the ability to see the tricky things in the incident, like what could happen here, and what does it mean? This may happen.”
He has thought about the consequences of AI on security people, but he is not concerned for the future of security itself. “I’m pretty sure we will find different ways to handle the changes. And honestly, there’s so much out there that I’m not really concerned that we will lose anything.”
It’s the security team that must adapt to new processes rather than security itself failing. Guiding this process will be another requirement on the CISO.
“The job of the security team will change dramatically in the future. That’s my strong belief. The CISO challenge is to help team members along this road to a new level, where they are able to think out of the box to see what else they can bring to the job.”