Cybersecurity has just accepted a painful truth: no matter how well you defend, one day you'll get hit. So the question shifts from 'how do we keep the thief out?' to 'once they're in, will our data survive — and how fast can we get it back?' This is the story of protecting the data itself, plus the art of getting back on your feet after ransomware — the arena that pushed companies like Rubrik to IPO and turned the once-boring job of 'data backup' into a boardroom issue.
Commvault Enables FedRAMP High Cloud for Federal Agencies
Commvault Systems has enabled its managed service provider partners to deliver FedRAMP High Authorized Commvault Cloud for Government services to U.S. federal agencies and defense contractors, broadening the company's public sector reach. The move lands on a stock with a 7 day share price return of 10.29% and a 90 day share price gain of 11.67%, though its 1 year total shareholder return is down 23.35% while the 3 year total shareholder return is up 111.68%. The most followed valuation narrative puts fair value at $161.15 against a last close of $145.21, implying roughly 10% upside, and rests on analyst expectations of about 10.6% annual revenue growth, profit margins rising toward 9.8%, and an 8.85% discount rate. That story leans on recurring SaaS economics, including 63% SaaS ARR growth, a 45% increase in multi-product customers, and 125% SaaS net dollar retention. A contrasting read notes the stock trades at a P/E of 88.1x versus 30.5x for the wider US Software group and a fair ratio of 38.7x, signaling valuation risk if sentiment cools.
Varonis Systems Launches Data Lifecycle Management Capability
Varonis Systems, Inc. launched Varonis Data Lifecycle Management, a new capability that automatically identifies and remediates redundant, obsolete, and trivial data across enterprise environments using its existing Data Security Platform. The launch ties data cleanup directly to sensitivity, access, and activity context, aiming to reduce storage waste, improve AI output quality, and help organizations address compliance exposures from scattered sensitive information. The DLM tool stacks on top of Varonis Atlas, the AI security platform that went generally available in March 2026, which targets discovery, posture management, and runtime protection for AI workloads. Together, Atlas and DLM broaden Varonis' role from guarding unstructured data to governing how that data is stored, used, cleaned up, and exposed across Snowflake, Claude, Cursor, and other cloud and AI partnerships. Varonis Systems' narrative projects $1.1 billion revenue and $120.7 million earnings by 2029, yielding a $50.68 fair value, an 8% upside to its current price, while the most pessimistic analysts were already modeling about US$1.0 billion of 2029 revenue.
Hackers threaten to leak Revolut customer data, demand $3 million ransom in Monero
Hackers have threatened Revolut with a ransom demand, seeking $3 million in Monero within 24 hours or they will expose the company's customer data. The hackers claim to be behind a cyberattack that leaked KYC and personal data of Revolut customers. The incident represents a significant security risk for the crypto company and its users, who must remain vigilant about the leakage of their personal data.
Cohesity Launches Agent Resilience to Protect and Recover AI Agent Infrastructure
Cohesity introduced Cohesity Agent Resilience, a new Cohesity Data Cloud capability that will discover, protect, and recover the infrastructure behind enterprise AI agents. The capability is available now to select customers, with general availability targeted for the end of 2026, and launches with support for Amazon Bedrock AgentCore and Amazon Bedrock Agents, while Microsoft and Google agent platforms are on the roadmap. Cohesity also outlined its vision for Autonomous Cyber Resilience, which uses agentic workflows to automate its five-step cyber resilience framework, and introduced the Cohesity AI Resilience Academy, beginning with a free, self-paced Foundations of AI Resilience with Cohesity course that Catalyst attendees will get early access to immediately after the event. The company cited new research from the fifth annual Cohesity Global Cyber Resilience Report showing that 56% of organizations said they were not well prepared to detect or contain unintended actions by AI agents and automated workflows, while 58% were not very confident in their ability to verify the integrity of AI models and related data following a cyberattack. Cohesity also said customers with Cohesity Data Cloud Enterprise Edition and Cohesity DSPM can now automate the protection of newly discovered sensitive data that is not already protected.
Palantir and Nvidia Restrict Anthropic AI Over Data Retention
Palantir and Nvidia have reportedly tightened restrictions around Anthropic's advanced AI models over data-retention concerns, with Palantir demanding irrevocable zero-data-retention guarantees before making the models available through its software and Nvidia limiting Claude to less-sensitive internal work. Palantir's September 10 sovereign-AI push with Nvidia uses Nvidia Nemotron open models and customer-controlled infrastructure, while Anthropic said on September 1 it would roll out Enterprise Frontier Safeguards later this fall, storing data in customer-controlled cloud infrastructure with zero-data-retention protections. Microsoft's Sovereign Private Cloud can run large AI models in fully disconnected, customer-controlled environments, a proposition it expanded with Mistral on July 21, though Microsoft also offers Anthropic models across Copilot and Foundry and says Anthropic models used in its online services are excluded from some in-country processing commitments and unavailable in certain sovereign-cloud environments. Palantir's second-quarter U.S. commercial revenue rose 149%, and Insider Monkey tracked 86 hedge funds long PLTR in the second quarter of 2026, down from 96 in the first quarter, while 273 hedge funds held reportable MSFT longs in the second quarter, down from 282. Short positioning is more pointed in Palantir, with 65.13 million shares sold short as of August 31, 3.00% of float, and 2.2 days to cover.
Finance Ministry and Digital Economy Ministry Set Up 4 National Central Systems to Block Fraudsters' Money in Real Time
The Ministry of Finance has joined hands with the Ministry of Digital Economy and Society to prepare four national central systems to link data on suspicious transactions between agencies, so that all sectors see the same set of risk data, and to speed up the tracing and freezing of money trails before funds are withdrawn, converted into digital assets or gold, or transferred out of the country. Dr. Ekniti Nitithanprapas, Deputy Prime Minister and Minister of Finance, in his capacity as chairman of the subcommittee on linking financial data to enhance the monitoring and investigation of suspicious financial transactions, disclosed together with Mr. Chaichanok Chidchob, Minister of Digital Economy and Society, that the subcommittee approved guidelines to upgrade the prevention and suppression of suspicious transactions in two areas: raising KYC, CDD and EDD standards to be on par with the world's leading financial centres, and drawing up a National Anti-Fraud Master Plan, whose core structure comprises four national central systems. These are the Data Sharing with Consent system, which exchanges risk data under consent; the Anonymous Financial Data Bureau, a centre for anonymous financial transaction data; the Case Management system, a national incident-reporting management system based on the principle of report once, one route; and the Financial Investigation and Account Action system for linking data and freezing money trails. The subcommittee has assigned the Permanent Secretary of the Ministry of Finance, together with relevant agencies, to design the details of the data structure, operating systems, connection guidelines, responsible parties, as well as the rules and data standards for all four systems, to be completed within 30 days before being submitted to the subcommittee for further consideration.
Palantir, Nvidia and Booz Allen Weigh Limits on Anthropic and OpenAI Models Over Data Risk
Palantir Technologies, Nvidia and Booz Allen Hamilton could restrict or stop using models from Anthropic and OpenAI unless the companies provide stronger guarantees around customer data and intellectual property, Reuters reported, citing The Information. Palantir has pushed Anthropic for irrevocable zero-data-retention guarantees before making its models available through Palantir software. Nvidia is taking a different approach, reportedly limiting Anthropic models to less sensitive work and using its own Nemotron models for some internal tasks. Booz Allen has also barred employees from using Anthropic's commercial model for proprietary cybersecurity work, as AI labs face more scrutiny over how usage logs and customer information are stored. Microsoft may have an opening, reportedly pitching isolated cloud environments and its own AI products to customers worried about data exposure.
IDrive Adds Microsoft Entra ID Backup to Its Microsoft 365 Protection Suite
IDrive announced on September 14, 2026 that it has added Microsoft Entra ID Backup to its IDrive Microsoft Office 365 Backup solution, extending protection to the identity and access management layer. The new capability automatically backs up critical Entra ID objects and settings to the IDrive cloud, covering users, groups, roles and administrators, administrative units, app registrations, enterprise applications, devices, policies, sign-in logs, audit logs, device configurations, device compliance policies, and BitLocker recovery keys. Key features include frequent automated snapshots, change tracking with historical comparison views, granular and bulk recovery that preserves relationships, point-in-time restore, centralized management of Entra ID and Office 365 backups from a single web console, and AES-256 encrypted storage in the IDrive cloud. The addition complements existing IDrive Microsoft Office 365 Backup support for OneDrive, Outlook, SharePoint, Teams and Groups. Microsoft Entra ID Backup is available for $10 per Entra ID seat per year with unlimited storage.
China warns AI poses security risks and could be used to whip up attacks on infrastructure
Chen Yixin, China's Minister of State Security, warned that the rapid advance of artificial intelligence could threaten China's political stability and critical infrastructure. In an article published on Sunday, September 13, in the magazine China Cyberspace, he said that misuse of AI by hostile forces could directly threaten China's political security, institutional security and ideological security. He also warned that AI is growing more capable of finding system vulnerabilities and of creating malware or software to exploit them. The Chinese government is also concerned that hostile forces could use AI for public opinion and perception warfare, through AI-generated text and images, social media bots and deepfakes, to create political rumours, spread harmful information and stir up social division. At the same time, AI-powered web crawlers, data mining systems and profiling systems could boost the ability of foreign intelligence services to gather sensitive data, including government information, trade secrets and personal data. Countries with an AI advantage could invoke national security grounds to impose technology controls, monopolise industry standards and build closed ecosystems. The warning comes as executives at leading US technology companies call for more cautious AI development. Dario Amodei, co-founder of Anthropic, said in a blog post on Saturday, September 12, that AI capabilities are advancing faster than risk safeguards, and proposed that companies in the United States and other democracies coordinate their efforts. Chen's article, however, did not mention calls by Anthropic or OpenAI to slow the development of cutting-edge AI models, and there is no sign that the two sides' public statements were coordinated. Chen framed AI risks in terms of political control, technological sovereignty, foreign threats and strategic competition.
Boston Scientific Warns Cyberattack Will Break 2026 Guidance
Boston Scientific Corporation disclosed that an August 25 cyberattack disrupted manufacturing and shipping, making it unlikely to meet its previously issued third-quarter and full-year 2026 guidance for net sales and adjusted earnings per share. The company said operations have since resumed, but the incident is still expected to weigh on third-quarter and full-year results. The disruption did not stem from a product-quality problem; the lost sales were orders that could not ship, and distribution is already back online. Farapulse, Boston Scientific's pulsed-field-ablation system, still commands a major share of the US atrial-fibrillation market, though the company had already projected flat global electrophysiology growth for the second half of 2026 after lowering its market-share assumptions. Hedge fund holdings in BSX slipped to 99 in the second quarter of 2026 from 106 in the prior quarter, while short interest remains low at 1.9% of the float.
Liquid Network Resumes Trading, Blockstream Says It Will Not Pay Ransom
Bitcoin sidechain Liquid Network resumed trading on September 11 after roughly four days offline, and its operator Blockstream stated on X that it will not pay any ransom. Liquid Network had suspended transactions on the network on September 7 following a security incident in which about 4,000 BTC were illicitly drained. Blockstream said it investigated the cause and verified security after the incident, and implemented the necessary security measures before restarting the network. It also noted that fake update sites and scam messages capitalizing on the incident have been identified, urging users not to trust guidance from any channel other than official ones and warning them not to disclose private keys or seed phrases to third parties. Liquid Network is a sidechain built on Bitcoin, used for fast BTC transfers and the management of issued assets.
ServiceNow Touts AI Control Tower as AI Business Grows Ninefold
ServiceNow outlined its enterprise AI "Control Tower" strategy at the Goldman Sachs Communacopia Conference, with CEO Bill McDermott describing a common platform that integrates AI agents, data, identity, security and workflows for governance, visibility and auditability. McDermott said the company's AI business has grown ninefold in nine months, its agents have generated $1 billion in value and eliminated about 2.5 million hours of employee work, and its customer relationship management business is doubling year over year and has crossed $2 billion in annual contract value. He said ServiceNow's security operations business has surpassed $1 billion, and the company is broadening its security platform through Armis, which provides visibility into IT, internet-of-things and operational-technology assets, and Veza, which contributes identity capabilities. McDermott said the average enterprise uses 47 security tools, creating a "point solution mess," and that ServiceNow manages 7 billion devices with another 40 billion expected to come into scope in the next several years. He also said ServiceNow acquired Moveworks in April 2025, with the deal closing in December, and cited customer examples including Robinhood, where agents manage 70% of cases previously handled by people, and Starbucks, which is converting at least 4,000 U.S. locations to ServiceNow Customer Service Management.
Japan records 123 ransomware cases in first half, a record high, with SMEs the main target
Japan's National Police Agency (NPA) said on September 10 that a total of 123 ransomware attacks were reported in Japan in the first half of this year, the highest half-year figure since record-keeping began in 2020. Of these, 79 targeted small and medium-sized enterprises (SMEs), 31 hit large companies, and 13 targeted other types of organizations. The NPA said more than half of all cases took over a month to recover systems, and 9 cases brought all business operations to a halt. Meanwhile, the number of detected suspicious accesses, often preparations for cyberattacks, rose by more than 4,000 per day per IP address compared with the same period a year earlier, reflecting the growing severity of cyber threats. The NPA has compiled half-year ransomware statistics since the second half of 2020. Ransomware is malware in which attackers demand a ransom in exchange for restoring access to a company's data, which has been encrypted and rendered unusable.
Commvault Unveils Active Directory Pre Recover for Rapid Identity Recovery
Commvault has introduced Active Directory Pre Recover, a solution that reduces the time to cleanly recover Active Directory from hours to minutes by creating a clean standby copy in an isolated Cleanroom environment. The solution, part of Commvault's Identity Resilience portfolio, uses existing technologies including Cleanroom and Threat Scan to ensure the standby copy is free of malicious content. Organizations can fail over to this clean copy during a cyber incident, maintaining access to critical systems without waiting for a full forest recovery. Commvault's Chief Products Officer, Rajiv Kottomtharayil, highlighted that identity is foundational to enterprise operations, and this innovation extends recovery progress toward near-real-time availability. Active Directory Pre Recover will be available for early access in the coming months, included at no extra cost for all enterprise AD customers, with a lite version of Cleanroom, and will be offered globally through Commvault's partner ecosystem.
LTM Collaborates with IBM and Red Hat on Lightwell for AI-Driven Open-Source Remediation
LTM, the Business Creativity partner to the world's largest enterprises, announced a collaboration with IBM and Red Hat on Lightwell, an AI-driven solution to help enterprises safeguard the open-source software supply chain through vulnerability remediation. Lightwell delivers validated fixes for production environments, moving beyond detection to scalable remediation. LTM, an IBM Platinum Partner, will offer services including remediation strategy, dependency analysis, risk-based prioritization, program management, DevSecOps integration, testing, and deployment support. The collaboration aims to help organizations address security challenges across complex open-source ecosystems, with LTM's expertise in application modernization, cloud, cybersecurity, and DevSecOps. Executives from LTM, IBM, and Red Hat emphasized the need for collective defense and expert ecosystems to accelerate patch delivery and prevent zero-day exploits.
Visa Unveils Singapore Security Roadmap 2026 to Combat AI-Driven Fraud
Visa has unveiled its Singapore Security Roadmap 2026 and Beyond, a comprehensive strategy to strengthen the resilience of Singapore's digital payments ecosystem against evolving fraud, scams, and cyber threats. The roadmap outlines six strategic priorities, including strengthening cybersecurity, advancing authentication, enabling safer transactions through tokenisation, transforming eCommerce checkout experiences, leveraging foundational standards and risk programs, and building a resilient payments ecosystem to combat fraud and scams in the AI era. Visa's study shows that close to seven in 10 Singapore residents trust digital payments, but 42 per cent have encountered scams, with only 8 per cent losing money. To address these threats, Visa is investing in AI-powered fraud detection, tokenisation, and authentication innovations like passkeys and biometrics, deploying over 150 AI and machine learning models globally. The roadmap emphasizes ecosystem-wide collaboration with regulators, financial institutions, merchants, and fintechs to enhance cyber resilience and intelligence sharing.
Hackers Drain 95% of Liquid Network's Bitcoin Reserves
A hacker group has withdrawn $320 million in bitcoin from Liquid Network, nearly 95% of its bitcoin reserves, according to Scott Melker on "The Daily Wolf." The exploit targeted Liquid, a Bitcoin sidechain developed by Blockstream, founded by Adam Back. The attacker exploited a bug in Elements, the software underlying Liquid, to create approximately 4,000 LBC without depositing actual BTC. These fake LBC were then sent through the withdrawal process, causing the Liquid Federation to release nearly 4,000 genuine Bitcoin. The hacker, described as a white hat, returned 3,400 of the 4,000 Bitcoin but kept 600 as a tip. Liquid has not yet announced full restoration of normal bridge operations.
Crypto platforms lose over $3.63 billion to cyberattacks despite audits
Crypto platforms have lost more than $3.63 billion to cyberattacks and stolen passkeys between January 2025 and July 2026, according to a report by CoinGecko dated Aug. 27. The report found that about 88% of the stolen funds and 60% of affected platforms had completed independent security audits, but most attacks targeted areas not typically covered by such checks. Bybit was the most affected, losing $1.4 billion in a February 2025 heist attributed to North Korea by Elliptic, followed by KelpDao with $292 million and Drift Protocol with $285 million. Bybit, KelpDao, and Drift Protocol did not immediately respond to CNBC's request for comment.
Socify.ai Hits 300 Clients, Accelerating Toward 10,000 by 2030
TAC InfoSec Limited's Socify.ai, an AI-powered SOC 2 compliance platform, has crossed 300 customers, with the latest 100 added in just two months, following six months for the first 100 and three months for the second 100. The company, listed on NSE as TAC, aims to reach 10,000 clients by 2030 as part of its broader goal of $100 million in annual recurring revenue. Founder and CEO Trishneet Arora highlighted the accelerating adoption, noting that each 100-customer milestone is being achieved faster than the previous one. The customer base spans AI, cybersecurity, enterprise software, and other sectors, including NETGEAR, Peloton Interactive, Globant, and several AI-first startups. Socify aims to make SOC 2 compliance accessible to thousands of businesses globally through automation and aggressive pricing.
Trezor Customer Data Breach Expands to About 80,000 People
Hardware wallet maker Trezor announced on September 4 the results of an additional investigation into a customer data breach at its shipping partner, revealing that approximately 67,000 more customers in the United States are affected. This brings the total number of affected individuals to about 80,000, roughly six times the initial figure of about 14,000. The company had disclosed the breach of about 14,000 individuals on August 13, but it became clear that past order data, which was thought to have been deleted, also remained. The source of the breach is the shipping partner ShipMonk, and the compromised data includes transaction information from November 2019 to August 2021. Trezor stated that its own systems were not compromised and that the security of its devices is unaffected, while warning of the risk of the information being used for fraud and notifying all affected individuals by email.
Commvault Integrates Cyber Recovery with CrowdStrike SOAR
Commvault announced on August 31 that its cyber recovery actions can now run as native steps inside CrowdStrike Holdings' Charlotte Agentic SOAR workflows, enabling security teams to trigger data recovery without leaving their incident response tools. This integration, the third leg of a broader CrowdStrike partnership, allows joint customers to restrict access, suspend backup data aging policies, and restore compromised assets into Commvault Cleanroom for forensics. The announcement follows Commvault's fiscal first quarter 2027 results reported on July 28, which showed subscription revenue of $267 million, up 16% year over year, and SaaS revenue crossing $100 million for the first time, up 39%. However, the company's GAAP operating margin was just 8.2% versus a non-GAAP figure of 22.8%, and its second-quarter guidance projects a non-GAAP EBIT margin of approximately 20%, a step down from the 22.8% delivered. Hedge fund ownership fell from 36 to 28 funds quarter over quarter, and short interest stands at 9.07% of float, while the stock trades at a forward P/E of 24.51 as of September 4.
Commvault has tripled the number of Microsoft Azure resource types its Cloud Rewind platform can protect and recover, expanding coverage to 62% of enterprise-relevant Azure resource types. The August 18 update follows fiscal first-quarter 2027 results reported on July 28, when subscription revenue rose 16% year over year to $267 million, subscription annualized recurring revenue reached $1,054 million, up 22%, and SaaS revenue crossed $100 million for the first time, up 39%. Free cash flow jumped 71% to $51 million, and the company struck a multi-year deal with Microsoft to sell its resilience tools as a native Azure service. However, GAAP operating margin was just 8.2% versus a 22.8% non-GAAP margin, and management guided second-quarter subscription revenue to $264–268 million, essentially flat, with full-year non-GAAP EBIT margin around 21%, below the 22.8% just posted. Hedge fund ownership fell from 36 to 28 funds, short interest stands at 9.07% of float, and the stock trades at a forward P/E of 24.51 as of September 4.
Unauthorized Access to Thomson Reuters Litigation Management System Affects Courts in US and Canada
A cybersecurity incident occurred in Thomson Reuters' litigation case management platform for legal departments, known as C-Track, affecting multiple courts in the United States and Canada. According to an investigation, an unauthorized third party obtained some C-Track-related files in March, potentially leading to the exposure of court records containing names and personal information. Court systems in the US states of Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, and Wyoming, as well as the US Virgin Islands, were affected, and Ontario, Canada also confirmed impact. Thomson Reuters has taken containment and remediation measures and notified affected customers, but a spokesperson stated that C-Track operations have not been disrupted, and products and services remain fully functional.
Varonis Systems shares jumped 13% Wednesday afternoon following a Bloomberg report that Proofpoint, backed by private equity firm Thoma Bravo, is in talks to acquire the cybersecurity company. People familiar with the matter said a transaction could be announced in the coming weeks, though no final decision has been made and talks could still fall apart or another bidder could emerge. Before the report surfaced, Varonis had a market value of approximately $4.7 billion. Representatives for Thoma Bravo, Proofpoint and Varonis did not immediately respond to requests for comment, according to the Bloomberg report. Varonis provides cybersecurity solutions that help companies monitor and control access to sensitive information across cloud systems.
Visa Enhances A2A Fraud Protection to Tap Real-Time Payments Growth
Visa Inc. is strengthening its position in the fast-growing account-to-account (A2A) payments market with an enhanced A2A Protect solution that combines its network intelligence with behavioral AI from Featurespace to assess fraud risk in real time. The product has delivered up to a 75% increase in scam detection and a 40% reduction in false alerts, and banks can integrate it through a single API. As A2A transactions bypass traditional card rails, Visa aims to monetize this shift by providing security infrastructure, turning fraud prevention into a recurring software service that deepens ties with banks. Competitors Mastercard and FIS are also expanding fraud-prevention capabilities, with Mastercard embedding real-time scam scoring in markets like the UK and FIS offering real-time monitoring through SecurLOCK. Visa's shares have risen 6.3% year to date, and the Zacks Consensus Estimate for fiscal 2026 earnings implies a 14.7% jump from the prior year.
Ceva Logistics sued over employee data theft in cyberattack
A former employee has filed a class action lawsuit against Ceva Logistics, alleging the freight giant failed to protect sensitive personal information stolen during a cyberattack that disrupted operations in Europe. Kevin Krupa sued Ceva in U.S. District Court for the Southern District of Texas, claiming hackers accessed systems in late July, impacting eight warehouses in the Netherlands and other European countries. The suit alleges that employee bank account details and social security numbers were stolen, and that Ceva did not adequately train staff or maintain reasonable security safeguards, despite a similar incident a year earlier. Krupa says he experienced fraudulent credit card activity and increased spam calls, and that Ceva has not formally notified employees. The complaint seeks class action status, citing at least 100 affected employees, and demands at least $5 million in damages for negligence, breach of implied contract, and unjust enrichment.
ControlMonkey Extends Cloud Configuration Disaster Recovery to Security Stack
ControlMonkey, a Cyber Resilience Platform for Cloud Configuration Disaster Recovery, announced expanded configuration backup and recovery for leading security platforms, starting with CrowdStrike, Zscaler, Fortinet, and Palo Alto Networks, with additional platforms coming soon. The new coverage makes critical security policies, rules, and configurations recoverable, addressing the gap where security tools are often missing from recovery strategies. CEO Aharon Twizer emphasized that security configuration needs to be recoverable, not manually rebuilt under pressure. This expansion builds on ControlMonkey's broader platform, which already covers cloud infrastructure, identity, networking, observability, SaaS, and third-party systems, adding a new recovery layer for the security stack.
JFrog Launches Zero-Touch Remediation with Security Partners
JFrog Ltd. (Nasdaq: FROG) has introduced JFrog Zero-Touch Remediation, a new capability that automatically finds and applies the best available fix for known vulnerabilities through a customer's pipeline without human intervention, and announced initial partners in its Self-Healing Software Supply Chain Security Ecosystem, including Broadcom, Chainguard, Echo, IBM/Red Hat, Moderne, TuxCare, and Seal Security. The system leverages JFrog Artifactory as a single source of truth to consume partner fixes natively, apply policy-compliant versions, and attest every action via JFrog AppTrust, collapsing remediation SLAs from weeks to minutes. Zero-Touch Remediation is available immediately as part of JFrog Unified Security, and JFrog plans to demonstrate it at swampUP 2026 in New York.
Zenmu hits limit-up after announcing launch of secret-sharing proxy technology business
Zenmu hit limit-up. The company announced that it will jointly launch a cybersecurity business utilizing its patented "secret-sharing proxy technology" (data communication system), developed in collaboration with the Medical AI Platform Technology Research Association (HAIP, Koto-ku, Tokyo). Following this announcement, investor interest surged, causing the stock price to soar.
Cohesity Adds Managed Clean Room to HCLTech VaultNXT
Cohesity, the AI and data security leader, has launched a new managed clean room capability within the HCLTech VaultNXT offering, integrating its Clean Room solution and AI-powered data security features to accelerate data recovery, improve regulatory compliance, and strengthen business resilience. The enhancement delivers a fully managed, isolated recovery environment with secure investigation, containment, validation, and recovery capabilities, addressing requirements such as DORA and NIS2. Kit Beall, Cohesity's chief revenue officer, said the partnership brings together market-leading managed clean room services and AI-powered data security to help customers recover trusted data faster and reduce risk. Rampal Singh, senior vice president of HCLTech's Hybrid Cloud Business Unit, noted that VaultNXT reflects the strength of the partnership in turning data protection into a strategic cyber resilience asset in the AI era.
Archive Intel Partners With Zocks to Streamline AI Compliance Reviews
Archive Intel, an AI-powered communications compliance platform for financial institutions, has announced an integration with Zocks, the privacy-first AI platform for financial services, to help firms capture, review, and retain AI notetaker data in line with SEC and FINRA regulations. The integration automatically flows Zocks data into Archive Intel, which contextually reviews AI-generated transcripts, flags non-compliant language, and archives records for audit-ready access. Archive Intel clients can activate the integration for $12 per user per month. The partnership addresses the challenge of managing compliance across growing client communication channels, as noted by executives from both companies. This marks the latest addition to Archive Intel's ecosystem of integrations for financial advisors.
Crypto Hacks Rise 67% in August, $136 Million Stolen
August 2026 saw a significant rise in security incidents in the cryptocurrency sector, despite a significant decrease in the total amount stolen when compared to July. According to data from PeckShieldAlert, there were 50 significant hacks in the industry in August, a 67% increase from 30 in July.
Marsh and Resilience have launched Cyber Protect in Asia, an offering that combines Marsh's cyber insurance expertise with Resilience's 24/7 Risk Operations Center to help clients detect and respond to cyber threats before they become losses. Available exclusively through Marsh in Asia, excluding China, the program includes proactive threat monitoring and human-validated alerts at no additional cost to clients who purchase cyber insurance brokered by Marsh. The launch comes as only 50% of Asia-based organizations are confident in their cyber risk management, compared to the global average of 72%, and nearly three in ten cyber attacks globally target Asia. Sean Letz, Cyber Leader for Marsh Asia, said prevention alone is no longer sufficient, while Resilience President Mario Vitale emphasized the value of preventing losses before they occur.
Jack Henry Says Cybersecurity Incident Hit Limited Internal Systems
Jack Henry & Associates has issued a statement on its response to a cybersecurity incident, saying the breach affected only a limited portion of its internal, non-production corporate environment and that no client-facing systems or core platforms were accessed or disrupted. The company, which serves more than 7,200 financial institutions, said fewer than 10 clients had personally identifiable information impacted, and it is offering two years of credit monitoring to those affected. The incident began with a vishing attack by a threat actor identified as ShinyHunters, and Jack Henry said it did not pay any ransom and that the incident is not financially material. The company is working with an independent cyber forensics firm and federal law enforcement.
Rubrik Beats Q2 Estimates, Raises Full-Year Outlook
Rubrik reported second-quarter fiscal 2027 results that exceeded all guided metrics, marking its tenth consecutive quarter of outperformance as a public company. Subscription ARR reached $1.66 billion, up 33% year-over-year, with net new subscription ARR of approximately $96 million, accelerating growth. Subscription revenue grew 37% to $407.2 million, and total revenue rose 38% to $427.3 million. The company also reported free cash flow of $65.7 million and raised its full-year subscription ARR guidance to $1.88 billion to $1.885 billion, reflecting about 29% growth. CEO Bipul Sinha highlighted the growing demand for agentic cyber resilience, citing the recent Hugging Face incident and the rise of AI-driven attacks, and noted that Rubrik now has over 15 paying customers for its Rubrik Agent Cloud product. CFO Kiran Choudary confirmed that the Strata Identity acquisition contributed zero ARR in the quarter and is not included in guidance.
Broadcom Launches TrueSource to Secure Open Source Software
Broadcom Inc. announced TrueSource, a portfolio of commercially supported, verifiably built open source software for the enterprise, at VMware Explore 2026 in Las Vegas. The portfolio includes Spring Enterprise, TrueSource Trusted Artifacts, and TrueSource Data Services, expanding coverage to Java, Python, and Node.js ecosystems. TrueSource Trusted Artifacts provides secure clean-room builds and a catalog of hardened container images, while TrueSource Data Services offers trusted artifacts and support for PostgreSQL, RabbitMQ, MySQL, and Valkey. Broadcom engineers verify every patch, and the company contributes fixes upstream, with research from 1Password's Off-by-1 Labs showing only 26 percent of AI-generated patches are safe without human oversight. The offerings are available with tiered site licensing options.
Flock Safety Spent $2 Million on Lobbying Amid Bipartisan Backlash
Flock Safety, the maker of automated license plate recognition cameras, has spent $2 million on lobbying efforts since 2025, according to a new report from OpenSecrets. The report, released Thursday, details that the company spent nearly $1.3 million on federal lobbying between January 2025 and July 2026, including $840,000 in 2025 and $430,000 so far in 2026, plus roughly $1 million in state lobbying. Flock has hired former government officials as lobbyists across dozens of states, and its lobbying targets include both chambers of Congress and the White House on law enforcement and crime issues. The report also highlights privacy concerns, citing an incident where a Kentucky officer accessed the Flock system 2,000 times to track his ex-girlfriend. Bipartisan backlash has grown, with Senator Bernie Sanders planning to introduce legislation to ban the technology, and Representative Greg Steube calling for warrants, while Senator Josh Hawley has launched an investigation. The city of Tempe, Arizona, has ended its contract with Flock, and Amazon has ended its partnership with the company.
Brazil's Central Bank to Launch Crypto Monitoring System
Brazil's central bank plans to implement a real-time crypto threat alert system following several major cyberattacks and thefts in the country. The new monitoring system will connect banks and domestic stock exchanges, providing around-the-clock surveillance of cryptocurrency transactions. This move comes after hackers stole an estimated $180 million U.S. in cryptocurrency from digital wallets in Brazil during 2025. The alert system, developed with blockchain security company Hypernative, is expected to go live within two weeks and will require a 24-hour preventive hold on crypto transfers above $10,000 U.S. starting in January 2027. It will cover both large cryptocurrencies like Bitcoin and smaller memecoins, helping financial institutions identify attacks, respond to suspicious activity, and track stolen funds moving from the banking system into the crypto market.
Yellow Hat warns of possible data breach affecting over 1.8 million customers
Yellow Hat announced on the 28th that customer information of 1,801,499 people may have been leaked due to unauthorized access to its systems. The unauthorized access occurred in a system used for booking oil changes and vehicle inspections, and was detected on the 18th. The potentially leaked information includes customer names, phone numbers, email addresses, and membership numbers, but credit card and vehicle information were not compromised. After confirming the unauthorized access, the company has taken measures such as blocking external connections to the system, strengthening security, and consulting with the police.
Rubrik Raises FY2027 Subscription ARR Outlook to $1.88B-$1.885B
Rubrik, Inc. (RBRK) reported strong fiscal second-quarter results and raised its full-year guidance, with subscription ARR reaching $1.66 billion and free cash flow of $65.7 million. The company now expects fiscal 2027 subscription ARR of $1.88 billion to $1.885 billion, up from a prior range of $1.854 billion to $1.862 billion, and free cash flow of $323 million to $333 million, up from $293 million to $303 million. For the third quarter, Rubrik guided revenue of $429 million to $431 million and non-GAAP EPS of $0.07 to $0.09. CEO Bipul Sinha attributed demand to AI-driven security needs, highlighting the company's push into "agentic cyber resilience," while CFO Kiran Choudary noted a $18 million headwind from material rights revenue. Analysts questioned the implied deceleration in net new ARR, but management expressed confidence, noting zero ARR contribution from the Strata acquisition and more than 15 paying customers for Rubrik Agent Cloud.