Geordie Raises $30 Million for AI Security and Governance Platform

AI security and governance startup Geordie today announced raising $30 million in a Series A funding round that brings the total raised by the company to $36.5 million.

Founded in early 2025, London-based Geordie has built a platform that helps organizations secure and govern AI agents deployed across their environments, at scale.

As organizations are increasingly relying on AI agents to automate operations at scale, they also require visibility, governance, and operational control to deploy them safely.

According to the startup, its solution provides organizations with a real-time understanding of every agent, its access and behavior, and the risk it may pose to the enterprise environment.

Geordie also offers a runtime remediation suite called Beam, which leverages context engineering and works together with the purpose-built security and governance platform to enable organizations to deploy AI agents at scale and constantly shape and constrain their behavior.

Learn More at the AI Risk Summit | Ritz-Carlton, Half Moon Bay

Advertisement. Scroll to continue reading.

The new investment round was led by Balderton Capital, with additional support from Crosspoint Capital and previous investors General Catalyst and Ten Eleven Ventures.

The startup will use the fresh investment to enhance its platform’s capabilities and to hire new talent across its engineering and go-to-market teams. It also plans to expand its operations to the US.

Related: RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries

Related: Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform

Related: Ocean Emerges From Stealth With $28M for Agentic Email Security Platform

Related: Socket Raises $60 Million at $1 Billion Valuation

https://www.securityweek.com/geordie-raises-30-million-for-ai-security-and-governance-platform/




As Summer Closes In, the Travel Sector Is Unprepared

New research from ­SecureTrust, a VikingCloud company, reveals that the three greatest threats to travel agency success are recession/reduced customer spending (54%), inflation (60%), and at the top, the risk of ransomware, data breaches, and cyberattacks (68%). The report found the concern over cybersecurity was caused by past precedent — in the last 12 months, 92% of agencies experienced some form of cyber threat. Furthermore, a majority of travel agencies (66%) reported a compromise of sensitive customer data within the last 12 months. 

Cyber incidents targeting travel agencies include: 

  • Phishing emails/texts (48%)
  • Fraudulent credit card activity (32%)
  • Fake website domains or social media accounts (22%)
  • Ransomware (22%)
  • False booking links (18%)

The report found the issue is deeper than cyberattacks targeting the sector — it’s a structural industry concern. 44% of agency owners report managing cybersecurity alone, while 26% admit the person in charge of cybersecurity (whether themselves or another individual) are not qualified for the task. 

This gap results in a breakdown of fundamental cyber hygiene and protection. 40% report their credentials may have been misused or exposed, with 28% saying employees share passwords across several systems. 36% admit to having outdated cybersecurity technology, and 12% cannot keep up with software updates and patches. 

Yet, only 20% plan to establish an incident response plan within the next 12 months. 

As summer draws closer and agencies anticipate an increase in travel, cybercriminals will likely try to exploit the heightened activity. For an industry that is already vulnerable to cyber threats, this busy season could present even greater concerns. 

The customer data that could be at stake, based on data typically compromised in travel agency breaches, includes: 

  • Phone numbers/emails (46%) 
  • Full names, birth dates and home addresses (40%) 
  • Credit card numbers (32%)
  • Passport information (28%)
  • Travel itineraries (22%)

https://www.securitymagazine.com/articles/102329-as-summer-closes-in-the-travel-sector-is-unprepared




AI Agent Conducted a Cyberattack on Its Own — It Took Less Than One Hour

Researchers discovered an intrusion conducted by a large language model (LLM) agent while it was in the post-exploitation phase. According to the researchers, this cyberattack was driven entirely by AI. 

“In this intrusion, the attacker exploited a vulnerable marimo notebook to gain code execution,” Michael Clark, Senior Director of Threat Research at Sysdig told Security magazine. “Then, they harvested data from the compromised workload, including AWS credentials. Using those credentials, the attackers performed reconnaissance across the AWS environment and discovered an SSH key in AWS Secrets Manager. They used the stolen key to access an SSH jump, where they found a reachable PostgreSQL database and exfiltrated its contents.”

The entire attack chain ran end-to-end in less than one hour.

“This attack is further evidence that every stage of the intrusion lifecycle is accelerating, from vulnerability discovery to lateral movement and data exfiltration. Defenders are increasingly operating against adversaries that can compress hours of manual analysis and decision-making into minutes with the help of AI,” explains Clark. “As a result, security teams need broader telemetry for offensive AI tools, faster detection pipelines, and lower friction in their response mechanisms. Preventing every intrusion through patching alone is becoming less realistic. Resilience will increasingly depend on how quickly teams can detect, investigate, and contain attacks once they begin.” 

Evidence of AI Driving the Execution

“The question is not whether the attack was automated,” the research states. “It most certainly was.” 

Instead, the research asserts the real question is this: was the script written prior to the session starting, or was it developed in real time? The research argues four properties of the transcript indicate real-time creation from an LLM: 

  1. The dump was improvised against an unidentified target
  2. A planning comment was leaked into the command stream, across six IPs and at at sub-second tempo 
  3. Each command was shaped for consumption by a machine 
  4. At easy handoffs, the chain consumes its own output

What Does This Mean for the Future of Cyberattacks?

The research asserts this incident showcases how malicious actors are raising the complexity and speed of their operations through AI, complicating the cyber threat landscape. 

“This attack demonstrates how LLMs are enabling threat actors to conduct increasingly complex operations, not just simple or opportunistic attacks at the edge. Sophisticated intrusion workflows that once required highly skilled operators can now be accelerated and even driven by AI, significantly lowering the barrier to entry and expanding the potential adversary pool,” states Clark. “It also changes what’s possible in terms of the speed and scale of attackers’ operations. Tasks that previously required continuous manual analysis and decision-making can now be delegated to AI systems, allowing attackers to move faster and pivot more efficiently within compromised environments.” 

This event was observed by the Sysdig Threat Research Team (TRT) on May 10, 2026. 

https://www.securitymagazine.com/articles/102325-ai-agent-conducted-a-cyberattack-on-its-own-it-took-less-than-one-hour




Carnival Data Breach Exposed 6 Million People

Cruise line operator Carnival Corporation is notifying approximately 6 million individuals that their personal information was stolen in a recent data breach.

Carnival said the incident was identified on April 14, after hackers gained access to an employee’s account via social engineering.

Using the compromised account, the attackers accessed certain company systems and exfiltrated files containing personal information.

“The company has been conducting a thorough and time-consuming analysis of the impacted files to determine what personal information they contained and to whom that information belongs,” an incident notice on Carnival’s website reads.

According to the company, the potentially impacted information varies by individual, but generally includes names, addresses, dates of birth, email addresses, phone numbers, and government-issued ID numbers.

On Wednesday, Carnival informed the Maine Attorney General’s Office that 5,995,277 people were affected and that it was providing them with 24 months of free credit monitoring services.

Advertisement. Scroll to continue reading.

While the company has not shared further details on the attack, the incident was claimed last month by the infamous extortion group ShinyHunters.

On its leak site, the hacking gang claimed the theft of 8.7 million records from Carnival’s systems, and made the data publicly available in late April.

According to data breach notification website HaveIBeenPwned, which analyzed the leaked dataset, roughly 7.5 million accounts related to the Mariner Society loyalty program run by Carnival cruise line brand Holland America were likely affected.

The leaked information included names, email addresses, dates of birth, gender, geographic locations, and loyalty program details.

SecurityWeek has emailed Carnival for additional information on the matter and will update this article if the company responds.

“From a defensive perspective, companies should treat social engineering resilience as a core cybersecurity control rather than an awareness exercise. That includes phishing-resistant MFA, stronger identity verification processes for internal requests, conditional access policies, privileged access segmentation, continuous behavioral monitoring, and regular red-team simulations focused specifically on human-centric attack paths,” SOCRadar CISO Ensar Seker points out.

Since 2020, Carnival has disclosed several data breaches. The company was hacked in 2019, fell victim to a ransomware attack in 2020, and was hacked again in March 2021.

Related: 185,000 Likely Impacted by 7-Eleven Data Breach

Related: Oncology Institute Discloses Data Breach

Related: 266,000 Affected by Data Breach at Radiology Associates of Richmond

Related: DocketWise Data Breach Impacts 143,000

https://www.securityweek.com/carnival-data-breach-exposed-6-million-people/




6M Impacted by Carnival Cruise Data Breach

Carnival Corporation has confirmed it experienced a data breach after the the ShinyHunters ransomware group claimed responsibility for an attack in April 2026. The incident was caused by a social engineering attack targeting an employee device, enabling the malicious actor to gain access to a portion of the company’s internal IT system.

“The Carnival breach is another reminder that social engineering continues to outperform many traditional security controls,” states Ensar Seker, CISO at SOCRadar. “Threat actors no longer need sophisticated zero-days when they can exploit human trust, impersonation, and operational pressure to gain legitimate access into enterprise environments. In large organizations with distributed workforces and complex third-party ecosystems, a single compromised employee account can quickly become an entry point into sensitive customer environments.”

Approximately 6 million customers have been impacted by the breach. 

“Nearly six million affected individuals means this is no longer just an operational security issue, it becomes a long-term identity and fraud risk problem,” says Seker. 

The organization has not yet confirmed impacted data, but according to an analysis by Have I Been Pwned, a data breach notification platform, compromised data includes but is not limited to: 

  • Names
  • Email addresses
  • Birth dates
  • Genders
  • Loyalty program information 
  • Geographic locations 

The analysis also stated that the compromised data involved 8.7 million records, including 7.5 million unique email addresses. 

“This is Carnival’s second major data breach of the 2020s,” points out Paul Bischoff, Consumer Privacy Advocate at Comparitech. “The company paid a $1.25 million settlement to victims of a 2020 data breach. The perpetrator in that case was never revealed. Carnival says an unauthorized user accessed employee emails and personal info. As part of that settlement, Carnival agreed to strengthen its email security and breach response practices. Clearly, the email security improvements weren’t enough. However, the company did disclose the breach in a much more timely manner this time around. It took nearly 10 months to report the 2020 breach, whereas this one appears to have been disclosed within one month.”

The organization operates nine cruise line brands: 

  • Carnival Cruise Line
  • Costa
  • P&O Australia
  • P&O Cruises
  • Princess Cruises
  • Holland American Line
  • AIDA
  • Cunard
  • Seabourn

It also operates a travel tour company known as Holland America Princess Alaska Tours. 

Currently, the organization is working with third party experts to investigate and bolster security measures. 

https://www.securitymagazine.com/articles/102327-6m-impacted-by-carnival-cruise-data-breach




New BTMOB Android Malware Enables Full Device Takeover

The BTMOB remote access trojan (RAT) is becoming a heightened threat to Android users due to its data theft and device takeover capabilities, ESET warns.

Believed to be based on the SpySolr malware, BTMOB is distributed via phishing attacks leveraging lures such as streaming, cryptocurrency mining, and other familiar services.

Its developers, however, sell it bundled with an APK builder interface, allowing threat actors to tailor lures and create new payloads based on their target geographies, without writing code.

“Once someone purchases the malicious kit, they can adapt its features, including the phishing lures so they impersonate the brand or agency most likely to lure victims in any given country,” ESET notes.

The malware is promoted via an open web page linking to a Telegram channel. Social media accounts on X and Instagram are also used to promote the Android malware.

BTMOB is offered for a lifetime license for $5,000, along with a monthly support fee. In January 2026, files related to the RAT were offered for free on a dark web forum that went offline.

Advertisement. Scroll to continue reading.

Threat actors have been observed delivering phishing messages that point victims to websites posing as legitimate services, which redirect to fake application stores mimicking legitimate repositories and serving the malicious APK.

Once executed on a device, BTMOB attempts to obtain excessive access, abusing Android Accessibility Services to elevate its privileges on the system without user interaction.

“Unlike banking trojans, which ‘only’ aim to steal people’s financial credentials or intercept their financial transactions, BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it,” ESET says.

The cybersecurity firm notes that the malware is mutating quickly, with numerous variants being observed within a short period of time, but that certain infrastructure patterns remained unmodified across iterations.

BTMOB has been mainly observed in attacks in Latin America, but the risk it poses stretches beyond the region, ESET warns.

Related: Critical Remote Code Execution Vulnerability Patched in Android

Related: Mirax RAT Targeting Android Users in Europe

Related: PromptSpy Android Malware Abuses Gemini AI at Runtime for Persistence

Related:New Keenadu Android Malware Found on Thousands of Devices

https://www.securityweek.com/new-btmob-android-malware-enables-full-device-takeover/




Il 78% delle aziende ha già subito o sospetta incidenti legati all’IA


A leggere il nuovo “2026 Cloud Security Report” realizzato da Check Point insieme a Cybersecurity Insiders, sembra proprio che l’adozione dell’intelligenza artificiale nelle aziende stia crescendo più rapidamente della capacità delle organizzazioni di proteggerla.

Il report, basato sulle risposte di 1.042 professionisti IT e cybersecurity provenienti da organizzazioni di tutto il mondo, mostra un quadro chiaro, preoccupante, ma anche atteso dal momento che ogni grande innovazione che porta “urgenza” tende a far prevalere la necessità di implementazione su quella della sicurezza “by design”. Così l’AI è già entrata nei processi produttivi, ma le architetture di sicurezza non sono state progettate per gestire traffico AI-driven, agenti autonomi e modelli generativi operativi su larga scala.

L’AI è già in produzione, ma la sicurezza è rimasta indietro

Il dato forse più importante dell’intero report riguarda la velocità dell’adozione. Il 70% delle organizzazioni dichiara infatti di avere già workload GenAI in produzione, mentre il 64% ha implementato agenti AI in ambienti pilota o direttamente in sistemi live. Ancora più significativo è il fatto che il 12% delle aziende abbia già concesso agli agenti AI accessi privilegiati a sistemi core aziendali.

Purtroppo, come dicevamo, sembra che le infrastrutture di difesa non stiano tenendo il passo. L’83% delle organizzazioni ritiene infatti che proteggere sistemi GenAI sia più difficile rispetto alle applicazioni tradizionali. La difficoltà nasce dal fatto che le architetture di sicurezza storiche erano state progettate per utenti umani, SaaS relativamente prevedibili e flussi applicativi stabili, non per agenti autonomi, API dinamiche e traffico AI machine-to-machine.

Il 78% delle aziende ha già visto incidenti AI-related o teme di averli subiti

Il 54% delle organizzazioni conferma di avere già subito almeno un incidente di sicurezza collegato all’AI, mentre un ulteriore 24% sospetta incidenti ma ammette di non avere sufficiente telemetria per verificarli. Complessivamente, il 78% delle aziende ha già registrato o teme di avere registrato impatti legati all’intelligenza artificiale.

Fra gli incidenti più frequenti emergono l’utilizzo non autorizzato di strumenti AI (“shadow AI”), segnalato dal 41% delle organizzazioni, l’impiego di contenuti generati dall’AI in attacchi phishing o deepfake, indicato dal 37%, e la perdita di dati sensibili attraverso servizi AI, fenomeno che riguarda il 32% delle aziende intervistate.

Secondo il report, uno dei problemi principali è che il traffico AI assomiglia spesso a traffico legittimo. Chiamate API verso LLM, richieste outbound e comunicazioni agent-to-agent possono facilmente mimetizzarsi nel traffico normale se i sistemi di ispezione non sono progettati specificamente per interpretare il contesto AI.

Il gap più grave: strategia e architettura non coincidono

Uno degli elementi più impressionanti dello studio è il cosiddetto “AI readiness gap”. Il 77% delle organizzazioni afferma di avere modificato la propria strategia di sicurezza in risposta all’AI, ma solo il 26% ritiene che la propria architettura sia effettivamente pronta a supportare workload AI senza importanti redesign infrastrutturali. Il risultato è un divario di 51 punti percentuali tra strategia e capacità reale di enforcement. In pratica, le aziende stanno aggiornando policy, governance e budget, ma i controlli non riescono ancora a propagarsi in modo coerente tra cloud, SaaS, data center, endpoint e workload AI.

Secondo Check Point, questo scenario sta creando policy frammentate, punti ciechi e perdita di controllo sui flussi AI distribuiti nell’ambiente ibrido enterprise.

Le aziende non vedono davvero l’AI che usano

La mancanza di visibilità è un altro tema centrale. Solo il 5% delle organizzazioni dichiara di avere piena visibilità sugli strumenti AI utilizzati dai dipendenti. Questo significa che il restante 95% prende decisioni di governance senza sapere davvero quali modelli, servizi, agenti o workflow AI siano attivi nell’organizzazione. Ancora più preoccupante è il fatto che solo il 5% affermi di riuscire a distinguere in modo affidabile attività AI legittime da utilizzi sospetti o non autorizzati. Gli strumenti tradizionali di discovery, sottolinea il report, erano stati progettati per individuare SaaS catalogati e applicazioni note, non chiamate API verso LLM, notebook AI o agenti che utilizzano account di servizio già esistenti.

Il traffico AI sta mettendo in crisi le infrastrutture di rete

L’intelligenza artificiale sta modificando rapidamente i pattern di traffico nelle reti enterprise. Il 51% delle aziende segnala un aumento del traffico API-driven, il 48% vede crescere il traffico verso servizi AI esterni, il 42% registra nuovi flussi user-to-AI e il 26% rileva un incremento del traffico east-west interno ai data center. Le architetture esistenti faticano a reggere il cambiamento. Solo il 24% dichiara di riuscire a ispezionare completamente il traffico AI senza penalizzare le performance, mentre il 76% ammette gap di ispezione o compromessi prestazionali.

Parallelamente, il 67% delle organizzazioni denuncia policy frammentate nei propri ambienti ibridi e il 64% afferma che la propria architettura necessita di redesign moderati o significativi per supportare l’AI.

I data center tornano centrali per l’AI

Un altro dato interessante riguarda il ritorno dell’on-premises. Il 29% delle organizzazioni sta già spostando workload AI verso data center privati o infrastrutture interne, mentre un ulteriore 49% sta pianificando o valutando questa possibilità. La ragione è legata a esigenze di sovranità del dato, prestazioni e controllo operativo. Il 76% delle aziende considera la sicurezza del perimetro del data center critica o mission-critical per workload AI, ma solo il 35% ritiene di essere realmente preparato a proteggerli.

Secondo il report, i data center AI stanno diventando ambienti molto diversi rispetto all’infrastruttura enterprise tradizionale, con traffico east-west elevatissimo, forte dipendenza da API e connessioni continue tra orchestrazione, storage, inferenza e servizi downstream.

La governance dell’accesso AI è completamente frammentata

Le aziende non hanno ancora trovato un modello dominante per gestire l’accesso dei dipendenti agli strumenti AI. Il 24% non applica alcun controllo specifico, il 22% si affida principalmente agli endpoint agent, il 19% utilizza regole diverse a seconda che l’utente sia on-network o off-network e un altro 19% blocca completamente gli strumenti AI esterni. Solo il 16% applica policy coerenti indipendentemente dalla posizione dell’utente.

Questo significa che lo stesso dipendente può avere livelli di protezione completamente differenti a seconda del browser, della rete o del dispositivo utilizzato.

Endpoint, SaaS e browser restano pieni di buchi e i WAF sono in crisi

Il report evidenzia forti limiti nella capacità di controllare il traffico AI SaaS. Solo il 13% delle organizzazioni riesce a ispezionare completamente e applicare policy efficaci verso servizi come ChatGPT, Gemini o Copilot. Sul fronte endpoint la situazione è persino peggiore: appena l’11% dichiara di avere piena visibilità e controllo sugli strumenti AI browser-based o installati sui dispositivi gestiti. Inoltre, il 39% afferma che i propri strumenti endpoint non coprono le applicazioni AI, mentre solo il 12% dispone di rilevamento real-time dello shadow AI sui dispositivi corporate.

Inoltre, l’intelligenza artificiale sta mettendo in crisi anche i sistemi WAF e WAAP. Solo il 22% delle aziende ritiene che i propri strumenti siano efficaci contro attacchi GenAI-specific come prompt injection o jailbreak. Il 71% segnala invece un aumento dei falsi positivi dopo l’adozione dell’AI. Secondo lo studio, i WAF tradizionali erano stati progettati per traffico web umano e pattern prevedibili, mentre i modelli generativi introducono prompt lunghi, streaming di risposte, API model-driven e interazioni service-to-service che sfuggono alle logiche storiche di inspection.

Runtime protection e testing sono ancora quasi assenti

Uno dei punti più delicati riguarda i controlli runtime sugli LLM. Solo il 17% delle organizzazioni ha distribuito in modo esteso controlli runtime come input validation, output filtering o autorizzazioni sull’utilizzo di tool da parte degli agenti AI.

Parallelamente, il 56% non possiede un processo strutturato di security testing per applicazioni GenAI oppure effettua test solo in modo occasionale. In pratica, moltissime applicazioni AI arrivano in produzione senza test sistematici contro prompt injection, adversarial input o abusi runtime.

L’AI sta creando una nuova crisi di identità e accessi, così come nella protezione dei dati

Il tema delle identità non umane emerge come uno dei principali problemi futuri. Il 48% delle organizzazioni identifica la gestione delle non-human identities come la sfida numero uno legata all’AI. Gli agenti AI utilizzano account di servizio, API key e credenziali delegate che spesso non rientrano nei tradizionali modelli IAM human-centric. Il problema è aggravato dal fatto che il 46% delle aziende non possiede alcun processo strutturato di assessment per vendor AI e solo il 7% effettua scansioni dei modelli AI prima del deployment per verificare vulnerabilità o codice malevolo.

La protezione dei dati emerge come uno dei punti più critici dell’intera ricerca. Il 25% delle aziende permette già oggi l’inserimento di codice sorgente in strumenti AI esterni, esponendo IP, configurazioni e logiche proprietarie a piattaforme con limitato controllo sull’esfiltrazione. Il 44% non riesce a tracciare il percorso dei dati sensibili una volta entrati nei workflow AI e solo il 15% dispone di sistemi DLP specificamente progettati per i flussi AI.

Secondo il report, molte aziende stanno consentendo l’ingresso di informazioni critiche nei sistemi AI senza avere lineage tracking, enforcement inline o visibilità sui movimenti downstream dei dati.

Le aziende rilevano gli attacchi AI, ma non riescono a bloccarli

Il report evidenzia una situazione particolarmente grave sul fronte prevention. Solo il 13% delle organizzazioni riesce a bloccare in tempo reale prompt malevoli o jailbreak prima che raggiungano il modello. Sul fronte della protezione dei dati, appena il 16% riesce a impedire che dati sensibili vengano inviati verso servizi AI. Ancora peggiore la situazione sugli output: soltanto il 5% è in grado di bloccare contenuti AI-generated pericolosi prima che raggiungano utenti o sistemi downstream.

Per Check Point, questo dimostra che molte organizzazioni possiedono sistemi di detection, ma non veri meccanismi di prevenzione inline capaci di operare “a velocità di inferenza”.

I dipendenti aggirano regolarmente i controlli AI

La ricerca evidenzia anche un problema organizzativo molto concreto. Il 42% delle aziende ammette che i dipendenti bypassano i controlli di sicurezza AI quando questi rallentano il lavoro.

In pratica, utenti e team trovano scorciatoie più rapide utilizzando account personali, strumenti browser-based non autorizzati o workflow esterni ai controlli aziendali. Questo fenomeno trasforma la governance AI in un problema operativo e culturale oltre che tecnologico.

Governance AI: responsabilità diffuse e poca enforcement

La governance emerge come uno degli aspetti più immaturi. Il 44% attribuisce la responsabilità AI al CISO, il 40% a comitati cross-funzionali e il 36% al CIO o all’IT leadership. Solo il 14% possiede un responsabile AI security dedicato.

Ancora più significativo è il fatto che il 45% abbia policy AI documentate, ma appena il 14% le faccia rispettare e auditare realmente.

Nel frattempo cresce la pressione normativa legata a framework come AI Act europeo e NIST AI RMF: soltanto il 7% si considera pienamente preparato.

Il mercato si sta muovendo verso piattaforme unificate

Nonostante le difficoltà, il report evidenzia una direzione molto chiara del mercato. Il 75% delle organizzazioni ha modificato la propria strategia architetturale a causa dell’AI e il 52% sta aumentando il budget dedicato alla sicurezza AI.

L’86% considera fondamentale una gestione unificata della sicurezza tra data center, cloud ed edge, mentre il 37% sta già consolidando strumenti e piattaforme verso modelli più centralizzati.

Secondo Check Point, il futuro della sicurezza AI passerà sempre più attraverso architetture “Hybrid Mesh Network Security”, capaci di distribuire policy coerenti, ispezione inline e controlli runtime attraverso ambienti cloud, endpoint, SaaS e data center.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2026/05/28/il-78-delle-aziende-ha-gia-subito-o-sospetta-incidenti-legati-allia/?utm_source=rss&utm_medium=rss&utm_campaign=il-78-delle-aziende-ha-gia-subito-o-sospetta-incidenti-legati-allia




Allied Universal Acquires Canadian Investigative Firm IRM

Allied Universal announced the acquisition of Investigative Risk Management (IRM), a provider of workplace investigations, insurance claims investigations, and risk management services based in Ontario, Canada. IRM will join Allied Universal Compliance and Investigations, the company’s global insurance claims services business unit, expanding Allied Universal’s investigative capabilities across Canada.

The acquisition establishes a dedicated Canadian investigative workforce, enabling Allied Universal Compliance and Investigations to provide insurance claims investigations, fraud detection, and risk assessments throughout the country. It also strengthens the company’s ability to support clients with cross-border investigations across North America.

“IRM has built an exceptional reputation for delivering high-quality, defensible investigative work grounded in integrity and professionalism,” said Mike Malone, president of Allied Universal Compliance and Investigations. “This acquisition expands our ability to serve global insurance clients with dedicated Canadian operations while bringing our advanced fraud detection capabilities and Third Eye technology to the Canadian market.”

“Joining Allied Universal Compliance and Investigations represents a transformative step forward for our organization and our clients,” said Brian Sartorelli, president of IRM. “We look forward to combining our investigative expertise with Allied Universal’s global scale, advanced technology platforms, and innovation-driven culture to deliver an unmatched level of capability to clients throughout Canada and beyond.”

https://www.securitymagazine.com/articles/102324-allied-universal-acquires-canadian-investigative-firm-irm




What Industry Leaders Can Do to Support Women in Security

@import url(‘https://fonts.googleapis.com/css2?family=Nunito+Sans:ital,opsz,wght@0,6..12,400;0,6..12,500;0,6..12,600;0,6..12,700;1,6..12,400;1,6..12,500;1,6..12,600;1,6..12,700&family=Nunito:ital,wght@0,400;0,500;0,600;0,700;1,400;1,500;1,600;1,700&display=swap’); h3 { font-weight: bold; font-size: 18px; color: #C72026; } figure { padding: 4px; margin: auto; } figcaption { color: #404144; Nunito Sans’, Arial, sans-serif; font-size: 14px; padding: 10px; text-align: left; }

Can the industry do more for women in security? 

That was a question I asked earlier this year, just before International Women’s Day. The insights I received from female leaders in the industry were eye-opening. While many shared that security and cybersecurity spaces have become more welcoming to women, they also acknowledged that there is still a long journey ahead for not just acceptance, but support and empowerment. 

In the most recent episode of Lock It Down with Security Magazine, I spoke with Melissa Mack, Director on the Professional Certification Board for ASIS and Managing Director at Pinkerton, about her experiences in rising to a leadership position in a traditionally male-dominated field. Mack expressed that for a majority of her career, she “was often the only woman in the room.” 

“I learned very quickly how to work and adapt in a male-dominated environment,” Mack states. 

But why is the expectation that women must the ones to adapt? Thinking back to the earlier question — can the industry do more for women in security — I think the answer is “yes.”

To learn how security leaders and organizations like can take actionable steps to support women seeking leadership roles in the industry, listen to our conversation below: 

Lock it Down Podcast logo

What Industry Leaders Can Do to Support Women in Security

Melissa Mack, Managing Director at Pinkerton, discusses the state of the security industry for women.

Or check it out on our Apple Podcasts. Don’t forget to like, follow, and rate and review our podcasts!

https://www.securitymagazine.com/articles/102314-what-industry-leaders-can-do-to-support-women-in-security




Windows Users Targeted in New Phishing Campaign

Research from FortiGuard Labs reveals a new phishing campaign leveraging emails posing as purchase orders, prompting targets to open malicious attachments.  

The research states, “This campaign demonstrates a sophisticated multi-stage attack chain that begins with a phishing email delivering a malicious JavaScript file. The JavaScript decrypts and executes a PowerShell script that uses process hollowing to inject a .NET downloader module into a trusted Windows process (MsBuild.exe). The downloader module communicates with a remote C2 server to fetch and execute additional plugin modules, allowing the attacker to adapt the malware’s post-compromise behavior.”

Windows users are the primary target of this phishing threat. 

This campaign is evasive and challenging for conventional signature-based security measures to identify, largely due to the use of: 

  • Several encryption layers
  • Fileless execution
  • Process hollowing tactics 

Below, security leaders discuss this campaign. 

Security Leaders Weigh In

Kern Smith, Senior Vice President of Global Solutions Engineering at Zimperium:

While this campaign ultimately executes on Windows, the broader lesson extends well beyond the endpoint. Attackers increasingly rely on social engineering and multi-stage attack chains that begin wherever users are most active, and increasingly, that starts on mobile devices through email, messaging platforms, and collaboration tools.

What makes these attacks effective is not just the malware itself, but the ability to move users from initial engagement to compromise while avoiding detection across devices and environments. Organizations should think beyond traditional endpoint visibility and ensure they can identify suspicious activity early, correlate signals across mobile devices, applications, and endpoints, and rapidly determine whether an alert represents a real incident. As attack paths become more distributed and AI accelerates attacker execution, security teams need AI-empowered security capabilities that reduce investigation time and provide clearer paths from signal to response.

Jason Soroko, Senior Fellow at Sectigo:

FortiGuard Labs recently discovered JavaScript-driven phishing campaign, deploying a PureLogs variant, underscores the shift toward fileless, evasive execution chains. Attackers hide the payload in an archive disguised as a purchase order, exploiting routine business workflows. The obfuscated JavaScript serves as an entry point that bypasses perimeter defenses, then decrypts and launches a PowerShell script. Threat actors continue refining methods that blend malicious activity with legitimate administrative tools.

The campaign relies on process hollowing to inject a .NET downloader into the trusted Windows MsBuild executable, masking it within a heavily used framework component and complicating detection. Once embedded, the downloader contacts a remote command server to retrieve modular plugins, giving the attacker dynamic post-compromise control. Layered encryption combined with legitimate system processes shows a sophisticated approach to data theft that demands equally adaptive, behavior-focused defenses.

Maxime Cartier, Vice President of Human Risk at Hoxhunt:

Historically, risky behavior and the human element have been linked to up to 90% of breaches, mainly via social engineering and phishing. However, when you look meticulously at recent research, many of the risks and barriers are behavioral, not technical.

Developers, admins, IT operations teams — they respond to the same drivers we think about in Human Risk Management every day: motivation, prioritization, clarity, communication, and friction. If security teams want outcomes to improve, they need to communicate risk in ways that help people act, not just escalate pressure.

This creates a significant opportunity for security awareness and Human Risk Management teams to collaborate more closely with vulnerability management teams. We spend a lot of time thinking about how to influence secure behavior at scale. Those same principles apply directly to improving remediation outcomes across the organization.

https://www.securitymagazine.com/articles/102322-windows-users-targeted-in-new-phishing-campaign