Visualização normal

Antes de ontemStream principal
  • ✇Firewall Daily – The Cyber Express
  • ZTNA Emerges as VPN Security Risks Put Federal Networks on Alert Samiksha Jain
    Federal agencies are facing growing pressure to evaluate ZTNA as an alternative to traditional VPN architectures, as cybersecurity threats expose weaknesses in internet-facing remote access systems. While VPNs provide encrypted connections for remote users, ZTNA follows a zero-trust model that continuously verifies users, devices, and access requests rather than assuming that authenticated users should receive broad network access. The shift reflects a broader move away from the traditional "
     

ZTNA Emerges as VPN Security Risks Put Federal Networks on Alert

ZTNA

Federal agencies are facing growing pressure to evaluate ZTNA as an alternative to traditional VPN architectures, as cybersecurity threats expose weaknesses in internet-facing remote access systems. While VPNs provide encrypted connections for remote users, ZTNA follows a zero-trust model that continuously verifies users, devices, and access requests rather than assuming that authenticated users should receive broad network access. The shift reflects a broader move away from the traditional "castle-and-moat" security model, where users inside an organization's network are generally trusted while those outside must first pass through a security perimeter. As organizations adopted cloud services, mobile workforces, and geographically distributed infrastructure, this model became more difficult to maintain.

VPN Security Risks Drive ZTNA Considerations

A traditional VPN creates an encrypted connection between a remote user's device and an organization's internal network. The VPN appliance typically sits at the edge of the network and remains accessible from the public internet, where it authenticates users before granting access. This architecture creates several security concerns. VPN appliances must maintain publicly accessible listening ports, making them discoverable and scannable by attackers. If vulnerabilities remain unpatched, those weaknesses can potentially be exploited remotely. The memorandum also points to risks involving legacy code bases, key-exchange processes, and lateral movement. Attackers who obtain legitimate VPN credentials, exploit a vulnerability, or hijack an active session may gain broad access to the internal network. Unlike application-specific access, traditional VPN access operates at the network layer, potentially allowing an authenticated user to reach multiple permitted subnets. Recent incidents involving vulnerable VPN appliances have further highlighted these concerns. The memorandum cites CISA directives addressing exploitation involving Pulse Connect Secure, VMware, and Ivanti Connect Secure products.

How ZTNA Changes Remote Access

ZTNA uses a "never trust, always verify" approach. Instead of treating users inside a network as inherently trusted, the architecture evaluates access requests based on factors such as identity, device health, user role, location, behavior, and risk. The architecture is built around three core components: the Policy Engine, which makes access decisions; the Policy Administrator, which establishes or ends sessions; and the Policy Enforcement Point, which enables, monitors, and terminates connections. Modern ZTNA deployments can also use outbound-only connections, removing the need for publicly accessible inbound listening ports. Rather than placing a user directly onto a corporate network, ZTNA can create an encrypted, application-specific micro-tunnel that limits the user to an authorized resource. Continuous verification is another key difference. Access is not necessarily granted once and maintained for the entire session. Instead, policies can reassess access based on changing security and contextual signals.

ZTNA Also Brings New Security Risks

The shift to ZTNA does not eliminate cybersecurity risks. The memorandum identifies the control plane as a significant concern because it is responsible for authentication, device verification, policy enforcement, and connection management. If an attacker compromises a ZTNA provider or components such as the Policy Engine or Policy Administrator, access decisions could potentially be manipulated. This could result in unauthorized access or prevent legitimate users from reaching resources. Additional security controls, including cryptographic signing of device nodes, may help reduce the impact of a compromised ZTNA provider. The memorandum cites Tailscale Tailnet Lock as an example of this approach.

Federal Agencies Face a Complex Transition

For federal agencies, moving from VPN to ZTNA involves more than replacing one remote-access technology with another. Agencies must consider federal cybersecurity policies, budgets, legacy infrastructure, authentication requirements, and cryptographic standards. NIST Special Publication 800-207 established foundational principles for Zero Trust Architecture, while Executive Order 14028 directed federal agencies toward zero trust, multifactor authentication, and secure cloud services. OMB Memorandum M-22-09 later established a federal zero-trust strategy centered on identity, devices, networks, applications and workloads, and data. A transition could involve assessing existing VPN deployments, identifying applications and user groups, deploying ZTNA alongside VPN infrastructure, and progressively migrating applications. VPN infrastructure could then be decommissioned after applications and users are migrated and validated. However, agencies must also account for recurring ZTNA subscription costs, legacy systems that may not support modern authentication, post-quantum cryptography requirements, NIST standards, FIPS requirements, and FedRAMP approval for cloud-based services. The transition from VPN to ZTNA therefore represents a broader change in how organizations approach remote access. While ZTNA can reduce exposure associated with publicly accessible network perimeters and broad network-level access, agencies must evaluate the technology's own control-plane risks, compliance requirements, costs, and technical limitations before making the shift.
  • ✇Firewall Daily – The Cyber Express
  • Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended Samiksha Jain
    The Fairlife ransomware attack has temporarily halted production operations at Coca-Cola-owned dairy company fairlife in the United States after unauthorized access was detected in a portion of its systems, including production-related systems. According to The Coca-Cola Company, fairlife identified unauthorized access by a third party in connection with a ransomware event. Following the discovery, the company activated its incident response and business continuity protocols while launching a
     

Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

Fairlife ransomware attack

The Fairlife ransomware attack has temporarily halted production operations at Coca-Cola-owned dairy company fairlife in the United States after unauthorized access was detected in a portion of its systems, including production-related systems. According to The Coca-Cola Company, fairlife identified unauthorized access by a third party in connection with a ransomware event. Following the discovery, the company activated its incident response and business continuity protocols while launching an investigation with the support of external advisors and cybersecurity experts. Law enforcement has also been notified. The company said the investigation is ongoing and that the full scope, nature, and impact of the incident are not yet known.

Fairlife Ransomware Attack Suspends U.S. Production

The Fairlife ransomware attack has resulted in the temporary suspension of production operations at fairlife facilities across the United States. However, the company stated that product quality and safety have not been affected by the incident. According to the company's statement, fairlife's production operations in Canada remain operational and have not been impacted by the ransomware event. The Coca-Cola Company also confirmed in a Form 8-K filing dated July 16, 2026, that fairlife detected the unauthorized access on Thursday. The filing reiterated that the company immediately activated its incident response procedures and business continuity protocols after identifying the intrusion. While the company continues to assess the incident, it said it has not yet determined whether the ransomware attack is reasonably likely to materially affect its business because the full impact remains unknown. The company added that it is working to complete its investigation and restore affected systems and production operations as quickly as possible.

Investigation Into Unauthorized Access Continues

The ongoing investigation is being conducted with assistance from outside cybersecurity experts. According to the company, the incident involved unauthorized access to a portion of fairlife's systems, including systems related to production. At this stage, The Coca-Cola Company has not disclosed how the attackers gained access, whether any data was compromised, or if a ransomware group has claimed responsibility for the attack. The company emphasized that its assessment is still underway and that additional details will be shared as more information becomes available.

Food and Beverage Sector Faces Growing Cybersecurity Risks

The food and beverage cyberattack trend has continued to affect manufacturers and logistics providers worldwide in recent months. On July 16, a cyberattack targeting Nichirei disrupted food deliveries across Japan after the frozen food and logistics provider confirmed unauthorized access to its servers. The incident affected logistics operations supporting KFC Japan, leading to temporary service disruptions while systems were being restored. Earlier this year, in February 2026, Australian poultry processor Hazeldenes also experienced a cybersecurity incident that disrupted production across its network. The Victoria-based company later announced it had begun a phased return to production to restore operations safely and securely while investigations continued. The latest incident involving fairlife adds another major food producer to the list of companies dealing with operational disruptions linked to cyber incidents. While production has been paused at fairlife's U.S. facilities, the company has maintained that product quality and safety remain unaffected and that its Canadian production continues without disruption. As the investigation progresses, The Coca-Cola Company said it remains focused on restoring impacted systems and resuming normal production operations. The company also noted that the complete scope and potential business impact of the incident have not yet been determined.
  • ✇Firewall Daily – The Cyber Express
  • NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands Samiksha Jain
    The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases,
     

NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

Agentic AI Deployment

The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases, limiting system privileges, and maintaining strong human oversight throughout deployment. The advisory comes as organizations increasingly experiment with AI systems capable of making decisions, accessing tools, and carrying out actions with limited human involvement.

What Is Agentic AI?

Unlike traditional generative AI systems that primarily create text, images, or predictions, agentic AI systems are designed to independently pursue goals. These systems can access data sources, remember context, make decisions, interact with software tools, and even create sub-agents to complete tasks. According to the NCSC, this added autonomy is what makes agentic AI useful for areas such as cyber defense, workflow automation, and operational efficiency. However, it also introduces a wider attack surface and increases the difficulty of monitoring system behavior. The agency noted that many security risks linked to AI are not entirely new. Concerns around access control, supply chain security, monitoring, and incident response already exist in traditional IT systems. Agentic AI systems also inherit existing large language model risks, including prompt injection and jailbreaking attacks. However, the NCSC warned that the autonomy of agentic AI systems could amplify these issues, especially if organizations deploy them without proper safeguards.

Why Agentic AI Raises Security Risks

The guidance outlines several risks tied to agentic AI deployments. One of the main concerns is broader access to systems and sensitive data. AI agents may interact with external tools, APIs, or databases in ways that traditional AI applications do not. The NCSC also highlighted the possibility of unpredictable behavior. Since AI agents interpret goals autonomously, they may take actions that differ from human expectations or exceed their intended scope. Another challenge involves visibility and oversight. Autonomous systems can operate at speeds that make meaningful human review difficult, particularly in enterprise environments where multiple systems and workflows are interconnected. The guidance further noted that explaining the behavior of agentic AI systems can be more difficult than understanding conventional AI models. The combination of decision-making, tool usage, and autonomous actions creates additional complexity during incident investigations or compliance reviews.

NCSC Calls for Incremental Agentic AI Deployment

To reduce risks, the NCSC urged organizations to adopt agentic AI gradually instead of deploying it across critical systems from the outset. The guidance recommends tightly controlled pilot deployments focused on clearly defined, low-risk tasks. Organizations are also encouraged to assess whether AI is genuinely necessary before integrating autonomous agents into existing workflows. “If you cannot understand, monitor or contain an agent’s actions, it is not ready for deployment,” the guidance stated. The agency stressed that organizations should never grant unrestricted access to sensitive data or critical infrastructure. Maintaining visibility into AI system behavior and preserving meaningful human control were identified as key requirements for safe deployment.

Human Accountability Remains Essential

Despite the growing capabilities of autonomous AI systems, the NCSC emphasized that humans remain fully accountable for how these technologies are used. The guidance states that organizations should clearly define who is responsible for approving AI access, monitoring system behavior, reviewing incidents, and shutting systems down when necessary. Security teams were also advised to integrate agentic AI risk management into existing cybersecurity and governance frameworks instead of treating AI security as a separate process. Recommended practices include applying least-privilege access controls, limiting system scope, avoiding long-lived credentials, monitoring unusual behavior, and planning for incidents involving AI misuse or loss of control.

Path Forward

While warning about the risks, the NCSC acknowledged that agentic AI could deliver significant operational benefits, particularly for repetitive and low-risk tasks. The agency said organizations should focus on responsible and scalable adoption strategies built around existing cybersecurity practices and strong governance controls. The guidance ultimately encourages businesses to move carefully, test systems incrementally, and prepare for potential failures before expanding the role of autonomous AI systems across enterprise environments.
  • ✇Security Boulevard
  • Unauthorized Users Reportedly Gain Access to Anthropic’s Mythos AI Model Jeffrey Burt
    A group of unauthorized users reportedly has gained access to Anthropic’s controversial Claude Mythos Preview AI frontier model despite the AI vendor’s efforts to keep it out of public hands by limiting the organizations that can use it. Bloomberg reported that the unnamed group had tried multiple ways to gain access to the AI model.. The post Unauthorized Users Reportedly Gain Access to Anthropic’s Mythos AI Model appeared first on Security Boulevard.
     
  • ✇Security Boulevard
  • NIST, Overrun by Massive Numbers of Submitted CVEs, Limits Analysis Work Jeffrey Burt
    NIST said it overwhelmed by the surge in the number of CVEs submissions in recent years, so it is paring back the analysis work it does on the dangerous security flaws. Security experts say the number of new vulnerabilities detected will only grow during the AI era and that the private sector will need to pick up the slack left by NIST's decision. The post NIST, Overrun by Massive Numbers of Submitted CVEs, Limits Analysis Work appeared first on Security Boulevard.
     

NIST, Overrun by Massive Numbers of Submitted CVEs, Limits Analysis Work

17 de Abril de 2026, 14:59
NIST CSF vulnerabilities ransomware backlog

NIST said it overwhelmed by the surge in the number of CVEs submissions in recent years, so it is paring back the analysis work it does on the dangerous security flaws. Security experts say the number of new vulnerabilities detected will only grow during the AI era and that the private sector will need to pick up the slack left by NIST's decision.

The post NIST, Overrun by Massive Numbers of Submitted CVEs, Limits Analysis Work appeared first on Security Boulevard.

  • ✇Firewall Daily – The Cyber Express
  • Two U.S. Nationals Sentenced in $5M North Korea IT Worker Scheme Samiksha Jain
    A major North Korea IT worker scheme has led to the sentencing of two U.S. nationals who helped facilitate fraudulent remote employment operations that generated millions of dollars for the Democratic People’s Republic of Korea (DPRK), according to the U.S. Department of Justice. The case highlights how foreign actors exploited remote work systems, stolen identities, and U.S.-based infrastructure to infiltrate companies and access sensitive data. Sentencing in North Korea IT Worker Scheme K
     

Two U.S. Nationals Sentenced in $5M North Korea IT Worker Scheme

North Korea IT Worker Scheme

A major North Korea IT worker scheme has led to the sentencing of two U.S. nationals who helped facilitate fraudulent remote employment operations that generated millions of dollars for the Democratic People’s Republic of Korea (DPRK), according to the U.S. Department of Justice. The case highlights how foreign actors exploited remote work systems, stolen identities, and U.S.-based infrastructure to infiltrate companies and access sensitive data.

Sentencing in North Korea IT Worker Scheme

Kejia Wang, 42, and Zhenxing Wang, 39, were sentenced for their roles in supporting the North Korea IT worker scheme, which placed overseas operatives into jobs at more than 100 U.S. companies. Kejia Wang received a sentence of 108 months in prison, while Zhenxing Wang was sentenced to 92 months. Both had pleaded guilty to multiple charges, including conspiracy to commit wire fraud and money laundering. The court also ordered three years of supervised release and financial penalties, including forfeiture of $600,000. Officials confirmed that the scheme generated more than $5 million in revenue for the DPRK, with at least $400,000 already recovered by authorities.

How the Laptop Farm Scheme Worked

At the center of the North Korea IT worker scheme were so-called “laptop farms” operated by the defendants in the United States. These setups were designed to make it appear that remote IT workers were physically located in the U.S. Using stolen identities of more than 80 Americans, the group secured remote IT roles across multiple organizations, including several Fortune 500 companies. The defendants and their associates hosted company-issued laptops at U.S. locations, enabling overseas workers to access them remotely. To facilitate this, they used hardware tools such as keyboard-video-mouse switches, allowing remote control of the devices from abroad. This setup helped bypass location checks and security controls commonly used by employers.

Use of Shell Companies and Financial Networks

The defendants also created shell companies, including Hopana Tech LLC and Independent Lab LLC, to support the North Korea IT worker scheme. These entities had no real operations but were used to present the overseas workers as legitimate U.S.-based employees. Payments from victim companies were routed through financial accounts linked to these shell companies. Authorities said millions of dollars were funneled through these accounts, with a significant portion transferred to overseas co-conspirators. In return, the facilitators in the U.S. received nearly $700,000 for their involvement.

Access to Sensitive Data and Security Risks

The North Korea IT worker scheme raised serious concerns about data security and national security. Investigators found that some of the fraudulently hired workers gained access to sensitive corporate information, including source code and restricted technical data. In one instance, an overseas co-conspirator accessed data controlled under International Traffic in Arms Regulations from a U.S.-based defense contractor. The data included sensitive information related to advanced technologies. Officials warned that such access could expose critical systems and intellectual property to foreign adversaries.

Ongoing Investigation and Wanted Suspects

Authorities continue to investigate the broader North Korea IT worker scheme, with several individuals still at large. The Federal Bureau of Investigation has identified multiple suspects believed to be involved in the operation. The U.S. Department of State has announced a reward of up to $5 million for information that helps disrupt financial networks supporting such activities. Law enforcement agencies have already taken action to dismantle parts of the operation. This includes the seizure of web domains and financial accounts linked to the scheme, along with the recovery of more than 70 laptops and remote access devices during coordinated searches. The North Korea IT worker scheme is part of a broader effort by DPRK-linked actors to generate revenue through cyber-enabled operations. Authorities say these schemes often rely on stolen identities, fake online profiles, and third-party facilitators to gain access to company systems. Public advisories from U.S. agencies have previously warned that such workers can earn significant sums, sometimes up to $300,000 annually, contributing to large-scale funding operations tied to North Korea’s strategic programs.

Exposed Ollama Servers: Security Risks of Publicly Accessible LLM Infrastructure

18 de Março de 2026, 04:00

Learn how exposed Ollama servers can allow unauthorized model access, prompt abuse, and GPU resource consumption when LLM inference APIs are publicly accessible.

The post Exposed Ollama Servers: Security Risks of Publicly Accessible LLM Infrastructure appeared first on Indusface.

The post Exposed Ollama Servers: Security Risks of Publicly Accessible LLM Infrastructure appeared first on Security Boulevard.

  • ✇Security Boulevard
  • The Attack Chain Your AI System is Already Missing  Mayank Kumar
    As AI adoption accelerates, organizations must evolve their security strategies from prompt filtering to comprehensive behavioral monitoring. This shift is critical to safeguarding against adaptive threats and ensuring safe AI deployment in production environments. The post The Attack Chain Your AI System is Already Missing  appeared first on Security Boulevard.
     
❌
❌