Cybersecurity has just accepted a painful truth: no matter how well you defend, one day you'll get hit. So the question shifts from 'how do we keep the thief out?' to 'once they're in, will our data survive — and how fast can we get it back?' This is the story of protecting the data itself, plus the art of getting back on your feet after ransomware — the arena that pushed companies like Rubrik to IPO and turned the once-boring job of 'data backup' into a boardroom issue.
Japan and South Korea data-leak wave drives tougher rules and resilience spending
▼
Japan's data-leak wave exposes weak data handling A wave of breaches hit Japan: Osaka Metropolitan University (130,000 records, ransomware), MrMax (1.7 million), GMO Research (948,500), Monogatari (10 million), Daiwa Securities (110,000) and JR East (2 million) via a SoftBank cloud unit. These failures keep legal, recovery and liability costs high and show weak links persist.
The period's dominant new event is a broad Japanese breach wave that raises costs and demand for protection.
Governments tighten data-transfer and cyber rules Japan plans to require hundreds of banks and hospitals to notify the government before sharing sensitive data, and its FSA told financial firms to review cyber defenses and ID checks. South Korea's president ordered a probe into bank leaks. New rules force spending on monitoring, access controls and compliance tools.
Regulatory tightening is a direct, durable demand driver for data-security and resilience products.
▼
Denmark and UK breaches show identity-data gaps Denmark's CPR civil registry was breached, exposing 8.8 million people's names, addresses and ID numbers via a private company's misused access. ASOS shares fell about 9% after hackers claimed a Snowflake data compromise. Both show identity and cloud data remain weak points, keeping liability and recovery costs high.
These new breaches outside Asia reinforce that data-protection failures persist globally.
Resilience vendors add AI-agent and code protection Rubrik expanded Project Hourglass with Code Guardian, testing cloned code against AI-driven threats, and added AHEAD, Trace3 and WWT as partners. It cited research that 86% of security leaders expect AI agents to outpace their guardrails within a year, deepening the paid market for resilience and data-governance tools.
Vendor product expansion shows the resilience market widening to cover AI agents and code.
Unauthorized Access Surges, Cyber Defense Inquiries Flood In as Hitachi, Fujitsu, and NEC Strengthen Systems
As unauthorized access to companies surges, electronics giants offering cyber defense services are receiving a flood of consultations and inquiries. In September, Hitachi launched a service that uses advanced AI models from U.S. firms such as Anthropic and OpenAI to provide end-to-end support spanning risk assessment, monitoring, and recovery. Fujitsu announced its cyber defense strategy in late August, and inquiries from client companies have poured in since then, increasing further in recent days, prompting it to establish a specialized organization of about 100 people effective October 1. NEC began offering a service in late September for financial institutions, manufacturers, and distributors that uses AI to automatically analyze risks and formulate response policies. Each company is strengthening its systems in anticipation of sophisticated AI-driven cyberattacks, and demand appears set to keep expanding.
Cybersecurity & Digital Trust › Network Security & SASE ▲Demand
6501.JP · Demand · Positive Hitachi launched an AI-based cyber defense service and is receiving a flood of consultations as unauthorized access surges.
6701.JP · Demand · Positive NEC began offering an AI cyber-risk service in late September to financial, manufacturing, and distribution clients amid surging attacks.
6702.JP · Demand · Positive Fujitsu's cyber defense inquiries have poured in since its late-August strategy announcement, prompting a new ~100-person specialized organization.
JR East: Over 2 Million Members' Data Possibly Leaked at Eki-net and Other Services
East Japan Railway Company announced on the 9th that more than 2 million members' information from its ticket reservation and travel support services "Eki-net" and "Otona no Kyujitsu Club" may have been leaked due to unauthorized access to a cloud service operated by a SoftBank subsidiary. Approximately 1.67 million email addresses of Eki-net members may have been compromised, while about 390,000 records from Otona no Kyujitsu Club, including membership numbers and credit card expiration dates, may have been leaked. Names, addresses, phone numbers, and credit card numbers were not included. In addition, email distribution to members of both services has been partially disrupted. IDC Frontier, the SoftBank subsidiary, suffered a ransomware attack on part of the systems of its cloud service "IDCF Cloud," affecting a wide range of contracted companies and local governments.
9020.JP · Regulation · Negative Over 2 million members' data from JR East's Eki-net and Otona no Kyujitsu Club services may have leaked via unauthorized access to a SoftBank subsidiary's cloud, and member email distribution was disrupted.
9434.JP · Regulation · Negative SoftBank Corp.'s subsidiary IDC Frontier was hit by a ransomware attack on its IDCF Cloud, affecting a wide range of contracted companies and local governments.
9984.JP · Regulation · Negative SoftBank subsidiary IDC Frontier suffered a ransomware attack on its IDCF Cloud, exposing data of contracted companies and local governments including JR East.
Japan's Financial Services Agency on the 9th, following a spate of customer data leaks caused by unauthorized access, called on financial institutions to review their cybersecurity measures and issued a warning. It is asking them to thoroughly check images of driver's licenses and other ID documents for anything unusual, even when verifying identity without meeting customers face to face. The FSA stressed that it wants institutions to prevent the fraudulent use of financial services and act so as not to undermine trust, urging them to review their response plans for cyberattacks and to promptly take any necessary measures where shortcomings are found. Financial Services Minister Satsuki Katayama said at a post-cabinet press conference on the 9th that identity verification should be carried out appropriately, including by reading IC chip information, which is extremely effective as a countermeasure against fraud. The Ministry of Economy, Trade and Industry announced it will issue warnings to roughly 1,000 industry associations under its jurisdiction, including those in the automotive and retail sectors, calling on management to take the lead in checking communications equipment and systems for vulnerabilities.
METI Issues Alert to About 1,000 Industry Groups After Spate of Unauthorized Access Incidents
Economy, Trade and Industry Minister Ryosei Akazawa said at a post-cabinet meeting press conference on the 9th that, in response to a series of incidents involving information leaks and other damage from unauthorized access in Japan, the ministry issued a broad alert the same day through roughly 1,000 industry groups under its jurisdiction. Akazawa called on companies to act on the understanding that they must manage security not only within their own operations but across the entire supply chain, and urged top management to take responsibility in securing the necessary resources and directing the response. He also encouraged them to quickly identify and address vulnerability information, monitor all activity on internal systems, and promptly provide information when damage occurs.
Rubrik Expands Project Hourglass With Code Guardian, Adds AHEAD, Trace3 and WWT
Rubrik announced the expansion of Project Hourglass, broadening its partner alliance to deliver Rubrik Code Guardian alongside Rubrik Agent Cloud. AHEAD, Trace3, and WWT joined the program, which already includes Cognizant, Deloitte, LTM, HCLTech, NTT DATA, and Wipro. Rubrik Code Guardian harnesses Anthropic's Claude Mythos 5 through a specialized security harness to evaluate code repositories against sophisticated, multi-step threat scenarios, testing a cloned, air-gapped copy of customer repositories rather than live production environments. According to Rubrik Zero Labs, 86% of cybersecurity and IT leaders anticipate that the proliferation of AI agents will outpace their organization's security guardrails within the next year. Rubrik Code Guardian is currently in private preview and accepting select design partners, and the company said it is not currently generally available and may change or be discontinued.
RBRK · Technology · Positive Rubrik expanded Project Hourglass and launched Rubrik Code Guardian, a new AI-agent security product now in private preview with new partners AHEAD, Trace3, and WWT.
Core6 Partners with Armis from ServiceNow to Extend Exposure Management to Storage and Backup
Core6 announced a partnership with Armis from ServiceNow that integrates its StorageGuard storage security posture management platform with Armis' continuous asset intelligence, extending cyber exposure management to storage and backup systems. The integration correlates Armis' real-time asset intelligence with StorageGuard's authenticated vulnerability and misconfiguration findings for storage and backup systems, closing a gap that has left storage arrays and backup platforms outside exposure management programs. Core6 founder and CEO Gil Hecht said several banks the FSB classifies as globally systemically important harden their storage and backup with StorageGuard. Nadir Izrael, GVP of Cybersecurity and Risk at ServiceNow, said the partnership enables security teams to shift from reactive threat response to autonomous, AI-driven security. The integration is available immediately for existing Armis from ServiceNow and Core6 customers.
Core6 · Demand · Positive Core6's StorageGuard is integrated with Armis from ServiceNow, extending its storage security posture management to more customers.
Armis Security · Demand · Positive Armis' continuous asset intelligence is integrated with Core6's StorageGuard, expanding its cybersecurity platform's reach into storage and backup exposure management.
NOW · Demand · Positive Armis from ServiceNow partnership integrates Core6's StorageGuard, extending ServiceNow's exposure management offering to storage and backup systems.
Synology survey finds 86% of Thai businesses prioritise AI-ready infrastructure, but only 9.5% are confident about cyber threats
Synology Inc. has released the findings of The Synology 2026 Southeast Asia Business AI Transformation Survey, which found that 86% of respondents in Thailand consider AI-ready infrastructure important for business operations and efficiency gains, though only 31.3% view it as very important. Meanwhile, 64.4% cited data security and privacy as the top obstacle to AI adoption, followed by data quality and availability at 47.3% and system deployment costs at 33.7%. On cyber risk, only 9.5% of respondents were highly confident their organisations are ready to handle AI-driven threats, while 38.5% said they are not ready. Although 92% of organisations already use data protection tools, only 21.4% are highly confident they could quickly recover systems from a ransomware attack and keep backup data secure, while 32.5% remain unsure they could restore data after an incident. Anthony Yang, Synology's head of Southeast Asia, said having a backup system alone is not enough and that data must actually be recoverable, and that organisations should separate backup systems from primary operating systems, along with safeguards to prevent backup data from being altered. The survey also found that 34% of Thai organisations still have no controls over employee use of AI, only 26.1% enforce controls through technical means, and 47.1% cannot see how external AI tools handle the data sent to them. At the Synology Press Event 2026, the company also presented the PAS7700, a high-speed storage system for mission-critical enterprise workloads, alongside ActiveProtect for backup and recovery management and the Synology Office Suite, as well as DSM Agent. It also disclosed a case study of Ethos Media Production, which adopted the PAS7700 as its central file storage hub with 70 terabytes of capacity, supporting 15 concurrent users and cutting the upload time for a 100-gigabyte video from about 40 minutes to just 2 minutes.
Synology Inc. · Demand · Positive Synology's survey and press event showcase its AI-ready storage, backup, and Office Suite products, positioning it to capture demand from Thai businesses prioritizing AI infrastructure and data security.
Ogaki Kyoritsu Bank Adopts Box Enterprise Advanced as Bank-Wide AI Content Platform
The Ogaki Kyoritsu Bank, Ltd. has selected Box Enterprise Advanced as an AI-ready content platform for the entire bank and has begun rolling out the platform, Box, Inc. announced. The bank, headquartered in Ogaki City, Gifu Prefecture, with President Takaharu Hayashi, will use Box as a content lake for unstructured data such as procedural guides, rules and regulations, manuals, and Office documents that had been dispersed across departments and systems, centralizing content bank-wide so AI can use it securely. Box was chosen for its security and governance capabilities, including granular access controls, content protection, ransomware protection, and audit support through log and audit-trail management. Key objectives include shortening information search and discovery time with Box Hubs and Box AI, reducing inquiry response time through AI-generated answers, improving review process efficiency with Box custom agents, and supporting operations through cross-functional use of structured and unstructured data via an AI agent platform. Tomohiro Kozakai, General Manager of the Digital Management Division at Ogaki Kyoritsu Bank, said the bank will centrally manage previously dispersed unstructured data under appropriate access controls, and will look toward an AI agent platform spanning structured and unstructured data. Noriyuki Sato, President of Box Japan, said Box provides centralized management of unstructured data, security and governance, and AI-powered content utilization on a single platform.
Artificial Intelligence › AI Applications & Copilots ▲Demand
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Demand
Artificial Intelligence › Agentic AI & Autonomous Workflows ▲Demand
BOX · Demand · Positive Ogaki Kyoritsu Bank selected Box Enterprise Advanced and began bank-wide rollout, a concrete customer win for Box's platform.
8361.JP · Technology · Neutral The bank is adopting Box as its AI-ready content platform to centralize unstructured data and improve search and review efficiency.
SAMTEL says subsidiary SCI wins IEAT cyber center contract worth 146.20 million baht
Samart Telcoms Public Company Limited, or SAMTEL, disclosed that Secure Info Company Limited, or SCI, a subsidiary in which the company holds a 99.99% indirect stake through Samart Comtech Company Limited, signed a purchase and sale contract for the procurement of machinery and equipment for the project to establish a cyber operations center and a data backup center, or Digital Resilience Center, at the SMART PARK Industrial Estate office with the Industrial Estate Authority of Thailand on September 29, 2026. The total project value is 146.20 million baht, including value-added tax, with delivery scheduled for completion by April 27, 2027. Payment terms are divided into five installments based on completed work progress.
SAMTEL.BK · Demand · Positive SAMTEL's 99.99%-owned subsidiary SCI won a 146.20 million baht IEAT contract for a cyber operations and data backup center.
Samart Comtech Co., Ltd. · Demand · Positive Samart Comtech's subsidiary SCI signed the 146.20 million baht IEAT Digital Resilience Center procurement contract.
Unauthorized Access Hits SoftBank Subsidiary IDC Frontier, Municipal and Corporate Websites Unreachable
IDC Frontier, a SoftBank subsidiary that provides cloud services, announced on the 7th that it suffered unauthorized access by a third party, causing an outage in its IDCF Cloud service for municipalities and businesses. The outage occurred around 3:40 a.m. that day, leaving some services unavailable. The company said it received an external ransomware attack, and the cloud management platform automatically executed a shutdown. The company has not disclosed details of its service customers, but numerous websites, including those of Ibaraki Prefecture, the city of Kodaira in Tokyo, Jiji Press, and Tobu Zoo, became impossible to view or update. To prevent secondary damage and data leaks, the company has cut off its network and is working to identify the detailed intrusion route while rushing to set up an alternative environment.
IDC Frontier Inc. · Regulation · Negative IDC Frontier itself suffered the unauthorized access and ransomware attack, forcing a network shutdown and service outage.
9434.JP · Regulation · Negative Its subsidiary IDC Frontier was hit by unauthorized access and ransomware, creating regulatory/legal exposure for SoftBank Corp.
9984.JP · Regulation · Negative Subsidiary IDC Frontier suffered a ransomware/unauthorized-access breach, exposing SoftBank Group to legal and regulatory fallout.
Major South Korean churches investigate cyberattack, risking leak of 850,000 members' data
Two large Christian churches in South Korea are rushing to investigate a cyberattack after personal data of many members was found on overseas servers. Oasis Security disclosed that it found member data, account information, and attack logs linked to Yoido Full Gospel Church and Sarang Church in Seoul. Yoido Full Gospel Church said today that a preliminary review found data of as many as 850,000 members may have leaked, mostly names and dates of birth, while a smaller portion included records of changes to resident registration numbers, addresses, and phone numbers. The church has notified potentially affected members, suspended external access to its servers, and changed passwords to prevent further leaks. Sarang Church said it has set up a task force to investigate the attack and has notified the relevant authorities. Oasis Security said some evidence points to the use of AI tools, including references to sub-agents, as well as numerous attack reports that appear to have been generated by automated systems. The attack comes as South Korea faces a wave of cyberattacks; previously, several commercial banks were hacked, causing customer personal data to leak. President Lee Jae-myung said on Tuesday that he believes AI may have been used in the attacks on those banks.
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Oasis Security · · Neutral Oasis Security disclosed it found the leaked member data and attack logs, but the article does not state any business impact on the firm.
Times Car kept ID documents for 7 years, widening breach damage
At the car-sharing service Times Car, roughly 6.6 million members' records from the past seven years, including those of former members, were leaked, and of these, about 1.6 million involved identity verification documents. According to parent company Park24, which operates the service, former members' information such as addresses and names was retained for seven years in line with the Corporate Tax Act, while identity verification documents were kept for seven years on the company's own judgment in order to handle inquiries and similar matters. Professor Ichiro Sato of the National Institute of Informatics pointed out that the documents should have been deleted at the time identity verification was performed, and criticized the handling as sloppy, saying they should have been stored so that they could not be accessed from outside. Yuji Kakeya, principal of the Security Research Center at Macnica, which works on cybersecurity measures, expressed concern that highly accurate personal information, such as that backed by official documents, may sell for a higher price. Experts stress that management should issue a directive and review their companies' data management.
Cybersecurity & Digital Trust › Data Security Posture & DLP ▼Regulation
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Regulation
4666.JP · Regulation · Negative Parent of Times Car; 6.6 million members' records leaked, including 1.6 million ID documents kept seven years, drawing expert criticism of sloppy data handling.
ASOS Shares Fall 9% After Hackers Claim Customer Data Breach
ASOS shares fell as much as 13.2% before paring losses to trade around 9% lower on Tuesday, after customers received a notification through the online fashion retailer's app claiming that hackers had compromised its data. The message, addressed to ASOS' data protection officer and IT staff, said, "We have fully compromised the Snowflake instance. Engage with us, or we will leak it." ASOS has not commented on the notification, leaving it unclear whether any customer data was accessed or compromised. The message included a link to a Telegram channel called the Xuanye group gateway, and cybersecurity firm Sophos said it had not previously encountered the group and that it did not appear on the Telegram channels or forums it monitors. Snowflake is a cloud platform used to store and analyse data, hosting Simon AI, which combines customers' behavioural, transactional and demographic information into individual profiles. Nearly 500 customers reported problems with the ASOS website shortly before 10 am, according to Downdetector, though the website and app appeared to be functioning normally until 9:41 am and it was unclear whether the reported issues were related to the notification.
Cybersecurity & Digital Trust › Data Security & Cyber Resilience Capital
SNOW · Regulation · Neutral Hackers claim to have compromised an ASOS Snowflake instance, but it is unclear whether any data was accessed and no Snowflake-specific breach is confirmed.
GMO Subsidiary Leaks Data of 940,000 Members, 2.86 Million Yen in Points Stolen
A wave of unauthorized access targeting companies has led to a series of personal data leaks, and at a subsidiary of GMO Internet Group, secondary damage was also confirmed in which members' points were fraudulently exchanged. GMO Research & AI announced that its survey site infoQ suffered unauthorized access, leaking the names, phone numbers and other data of 948,498 registered members, and it was found that points totaling 2.86 million yen belonging to some members had been exchanged for Amazon gift codes; the company will compensate the full amount. Mr. Max Holdings, which operates discount stores, also disclosed on the 6th that the phone numbers, email addresses and other data of up to 1,735,154 members of its store-operating company's app and online store had leaked. In addition, Daiwa Securities said data on about 110,000 customers may have been compromised, and Citizen Watch said data on about 100,000 customers may have leaked, among other incidents, with cyberattacks showing no sign of letting up. It has also been pointed out that the spread of artificial intelligence is casting a shadow as a background factor behind the surge.
South Korean Leader Says AI Signals Found in Major Bank Hacks, Orders Swift Probe
South Korean President Lee Jae-myung revealed on Tuesday, October 6, 2026, that there are signs artificial intelligence, or AI, may have been used in cyberattacks on several banks in the country, and called on South Korea to speed up development of cybersecurity systems suited to the AI era. Speaking during a cabinet meeting, he said that in some hacking cases traces of AI use have begun to emerge, which has caused considerable public concern, and ordered relevant agencies to swiftly establish the facts clearly, while mobilizing personnel and resources to minimize damage. South Korean police have launched a full-scale investigation after several commercial banks were hit by cyberattacks that led to the leakage of customers' personal data. The Financial Services Commission, or FSC, disclosed that Shinhan Bank and KB Kookmin Bank, as well as other financial institutions, reported being hit by cyberattacks, while Hana Bank and Woori Bank also faced data leakage incidents. The Financial Supervisory Service, or FSS, and the Financial Security Institute passed on information about 28 suspicious IP addresses, as well as some country data linked to the latest cyberattack attempts, to the financial sector for further checks and prevention. However, South Korean authorities have not yet disclosed what type of AI tools the attackers used, and there are still no details about the full scope of damage from the incidents.
105560.KO · Regulation · Negative KB Kookmin Bank was among the South Korean banks hit by AI-linked cyberattacks that leaked customer personal data, triggering a police and FSC investigation.
Japan hit by wave of cyberattacks as data on millions leaks
Several companies in Japan, along with one university, have faced data leaks or cyberattacks since Monday, October 5, potentially affecting millions of customers, members, students and faculty combined. Osaka Metropolitan University disclosed that data on at least 130,000 students and faculty members may have leaked after about 500 servers were hit by suspected ransomware on Friday, October 2, leaving the student network system and faculty web portal still unusable and forcing classes to be cancelled. Meanwhile, MrMax Holdings disclosed that personal data on as many as 1.7 million customers may have leaked after a breach of the servers for its online trading system. GMO Research & AI said that as many as 948,500 member records were stolen, and that some member points worth about 2.9 million yen, or roughly 18,000 US dollars, were improperly exchanged for Amazon gift card codes. Monogatari, which operates more than 350 branches of the yakiniku restaurant chain King across Japan, reported that more than 10 million customer records, or nearly its entire registered user base, leaked from the system for its restaurant booking and loyalty points app. Daiwa Securities Group disclosed that data on about 110,000 customers of an affiliated brokerage may have leaked from servers managed by a contractor. All of the incidents were reported separately, and there is no indication so far that they are connected.
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Technology
8203.JP · Regulation · Negative MrMax Holdings disclosed personal data on as many as 1.7 million customers may have leaked after a breach of its online trading system servers.
8601.JP · Regulation · Negative Daiwa Securities disclosed data on about 110,000 customers of an affiliated brokerage may have leaked from contractor-managed servers.
LeapXpert Brings Governed WhatsApp Client Messaging to Webex by Cisco
LeapXpert and Webex by Cisco announced a collaboration that extends Webex beyond internal collaboration into governed client messaging, starting with WhatsApp. The integration, available now on the Webex App Hub, lets Webex users message clients on WhatsApp without leaving the platform, signing in with their existing Webex credentials on desktop or mobile. It is the first of several channels LeapXpert plans to bring into Webex, and additional messaging channels will be rolled out. Every message is checked by data loss prevention in both directions, and the full conversation is captured by LeapXpert for archiving. With Webex used by 95% of the Fortune 500 and roughly 300,000 organizations worldwide, the partnership brings governed consumer messaging within reach of tens of millions of business users. A Leap Work account and a Webex license are required, and LeapXpert will showcase at WebexOne 2026, October 5 to 8, 2026, at booth B24.
Cloud & Digital Infrastructure › API & Integration (iPaaS) ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
LeapXpert · Demand · Positive LeapXpert's governed WhatsApp messaging is now available on the Webex App Hub, reaching tens of millions of business users.
CSCO · Demand · Positive Webex by Cisco integration with LeapXpert extends Webex into governed WhatsApp client messaging, adding a new capability for its 300,000 organizations.
Diskover Data Partners With NetApp to Bring Metadata Discovery to File-Intensive Workloads
Diskover Data announced a new collaboration with NetApp that extends the Diskover Platform's governed visibility and control to ONTAP and StorageGRID environments in media and entertainment, semiconductor design, and other file-intensive sectors. Under the collaboration, customers will be able to purchase Diskover Platform through NetApp beginning in November 2026, with the platform available now for NetApp ONTAP and StorageGRID environments. Diskover's DataDiscovery uses specialized scanners to index metadata in place across ONTAP and StorageGRID, capturing ownership, permissions, age, cost, and project context in a searchable, governed catalog. Diskover says customers typically reclaim 10 to 30 percent of their footprint, exceeding three million dollars in larger environments, with return on investment inside 30 to 60 days. Will Hall, Chief Executive Officer of Diskover Data, said the collaboration gives NetApp customers a governed, searchable view of the data behind their projects, while Sandeep Singh, Senior Vice President and General Manager, Platform at NetApp, said Diskover extends the NetApp ecosystem with specialized discovery for customers with file-intensive workloads.
Cloud & Digital Infrastructure › Enterprise Data Storage Systems ▲Technology
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
NTAP · Demand · Positive NetApp will sell the Diskover Platform through its channel starting November 2026, extending its ecosystem for file-intensive workloads.
Diskover Data · Demand · Positive Diskover's platform gains distribution through NetApp's ONTAP and StorageGRID customer base.
Denmark uncovers major data breach affecting 8.8 million people in CPR system
Denmark is facing a major personal data breach after unauthorised individuals accessed the records of approximately 8.8 million people in the country's central civil registration database, covering names, addresses and national identity numbers. The Danish government said on Monday that the perpetrator, who has not yet been identified, misused the legitimate system access of a private Danish company to look up information in the Central Person Register, or CPR. The company's access to the system has now been suspended and police are investigating the incident. Authorities said it is too early to conclude who was behind it. Christina Egelund, Denmark's Minister for Digital Affairs, described the incident as extremely serious, ordered a comprehensive review of the CPR's security, and urged the public to be wary of suspicious phone calls or emails that could use the leaked data for fraud. The agency that manages the system first detected unusual activity on 2 October, before finding that unauthorised lookups had taken place during September. People registered for name and address protection in the system were not affected by the incident.
Japan to Amend Economic Security Law, Requiring Organizations to Notify Government Before Sharing Sensitive Data
Japanese authorities plan to amend the economic security law to require companies and organizations holding big data to notify the government before transferring or disclosing sensitive personal information to third parties. Kyodo News reported that the government aims to submit the amendment bill to the ordinary session of the Diet next year, amid concerns that malicious actors abroad may misuse the data as artificial intelligence technology advances, potentially posing a threat to national security. Sensitive personal information covers medical treatment histories, location data, biometric data such as fingerprints and facial recognition data, genetic information, as well as financial transaction histories. Sources said the reporting requirement will be based on the volume of data an organization holds, and is expected to cover several hundred organizations, including banks and hospitals. The government also plans to enforce the requirement when organizations store data with external cloud services or data centers. In addition, the government is considering establishing a system to assess whether data transfers should be permitted, based primarily on national security factors. A panel of experts is expected to begin discussions late this month on the proposed system, including penalties for those who evade reporting, before submitting the bill to the Diet next year. There is a tendency to discuss regulation of data center and cloud service providers, while trying to avoid unnecessarily affecting these companies' business activities. The spread of generative AI has made personal information a strategic resource with implications for both the economy and national security, since large datasets may contain information used to surveil or blackmail individuals, including those involved in important decision-making. The economic security promotion law, which took effect in 2022, covers measures to support the development of critical technologies, strengthen supply chains, and conduct advance screening of equipment used by companies operating critical infrastructure.
Revyz Launches Bitbucket Cloud Data Protection, Names Justin Leader Head of Partnerships
Revyz, a Spin.ai company, announced Revyz Command Center for Bitbucket, extending its enterprise data protection platform from Jira and Confluence to source code and pipelines in Bitbucket Cloud, alongside the appointment of Justin Leader as Head of Partnerships, Atlassian Ecosystem. The launch, announced ahead of Atlassian Team '26 Europe in Amsterdam on October 6-8, adds granular recovery of specific repositories, branches, pipelines, or issues, run-to-run diff visibility, and AI code protection. Revyz, acquired by Spin.ai in April 2026, is a Platinum Atlassian Marketplace Partner whose platform is SOC 2 Type II compliant. Justin Leader founded HyperVelocity Consulting in 2014, growing it to $24M in revenue before its acquisition by Isos Technology in 2023, where he served as VP of Product, and brings 15 years of SaaS experience to overseeing global Atlassian ecosystem partner strategy. Revyz Command Center for Bitbucket is available today, with solution partners able to access the app and co-selling support through the updated Revyz Partner Program.
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Cloud & Digital Infrastructure › Observability & DevOps ▲Technology
Revyz · Technology · Positive Revyz launched Command Center for Bitbucket, extending its data protection platform to source code and pipelines with granular recovery and AI code protection.
Revyz · Capital · Positive Revyz named Justin Leader as Head of Partnerships, Atlassian Ecosystem, to oversee global partner strategy.
TEAM · Demand · Positive Revyz extends its Atlassian data protection platform to Bitbucket Cloud, deepening the Atlassian ecosystem product offering and partner co-selling around Atlassian Team '26.
Spin.ai · Technology · Positive As Revyz's parent, Spin.ai gains from the launch of Revyz Command Center for Bitbucket extending its enterprise data protection platform.
Thales Launches CipherTrust Data Security Posture Management Platform
Thales announced CipherTrust Data Security Posture Management, which the company describes as the first purpose-built DSPM offering that lets organizations protect sensitive data directly through encryption, masking or tokenization natively within the platform. The unified as-a-service platform combines sensitive-data discovery and classification with posture, access, activity and behavioral context to prioritize material risks, and it provides discovery and risk visibility for both structured and unstructured data across cloud, on-premises and hybrid sources. Todd Moore, Vice President of Data Security Products at Thales, said organizations need to understand which sensitive data is truly at risk and take direct action to reduce it, adding that CipherTrust DSPM connects risks to protections such as encryption and tokenization rather than relying on permissions alone. The approach builds on more than 30 years of Thales expertise in data discovery, protection, key management, access control and activity analysis. Hiroji Sugito, Principal Data Security Engineer at Tokyo Electron Device, said the platform's ease of deployment and the accuracy of its data classification enable customers to quickly understand where their sensitive data is, who or what can access it, and how to protect it without slowing AI adoption.
Everpure Adds MCP Integration and AI-Optimized FlashBlade to Data Platform
Everpure announced new platform capabilities extending its Data Primacy vision, including native MCP integration, AI-optimized FlashBlade acceleration, and privacy-first data intelligence tools aimed at simplifying and securing enterprise data management for AI workloads. The company said the upgrades bring high-performance AI execution directly to data at the source while classifying sensitivity and access in real time, positioning its platform as a central control layer for both AI cost management and cyber resilience. Everpure said the near-term catalysts remain execution on its FY2027-2028 revenue guidance and uptake of newer software-led offerings. Eight Simply Wall St Community valuations for Everpure span roughly US$84 to over US$370 per share. The company faces a rich sales multiple, recent insider selling, a volatile share price, and index reshuffling.
Nvidia's Jensen Huang Caps Q3 With Record $150 Billion Buyback
Nvidia CEO Jensen Huang closed out a blockbuster third quarter in which Nvidia's stock rose about 19% and the company announced the largest stock buyback in history at $150 billion, bringing its total buyback program to $235 billion. Huang also joined other tech executives at a White House AI safety gathering, where his signature drew attention on social media, and appeared at a state dinner with the president. On the company's August earnings call, Huang said growth could exceed 100% next year. Separately, Rubrik CEO Bipul Sinha told Yahoo Finance that AI carries 1000 times more opportunities and 1000 times more risk, and warned that much of the Fortune 500 still runs on legacy technology as AI-powered attacks expand the threat surface. Micron and SanDisk were also in focus on Micron's earnings day, with both trading at single-digit forward earnings multiples despite triple-digit revenue growth.
NVDA · Capital · Positive Nvidia announced the largest stock buyback in history at $150 billion, bringing its total program to $235 billion.
RBRK · Technology · Neutral Rubrik CEO commented that AI carries 1000x more opportunities and risk, with Fortune 500 still on legacy tech as AI-powered attacks expand.
NetApp Unveils Zero-Copy Data Activation for Agentic AI, Expands Commvault Integration
NetApp announced new capabilities that let enterprises activate data in place with zero-copy access to accelerate agentic AI adoption. The heterogeneous metadata capability of NetApp AI Data Engine now extends metadata discovery across the full enterprise data estate, including NetApp ONTAP, StorageGRID, and non-NetApp storage, spanning NFS, SMB, and S3 repositories. NetApp is also previewing upcoming AIDE innovations, including expanded AI-powered data understanding, deeper governance intelligence, open analytics integrations with engines such as Starburst and Onehouse.AI, and new agentic services. An expanded integration with Commvault connects the NetApp Platform to Commvault recovery orchestration, delivering near-real-time threat detection, cleanroom validation, and advanced clean recovery from the Commvault console, enabling joint customers to recover in minutes rather than days or weeks. Asad Khan, Senior Vice President and General Manager of AI at NetApp, said the agentic enterprise will be defined by how quickly and safely organizations turn data into intelligence, while Commvault Chief Technology and AI Officer Pranay Ahlawat said the integration helps customers reduce mean time to clean recover.
Artificial Intelligence › AI Applications & Copilots ▲Technology
NTAP · Technology · Positive NetApp unveiled zero-copy data activation for agentic AI and previewed new AIDE innovations extending metadata discovery across its and non-NetApp storage.
CVLT · Technology · Positive Expanded integration connects NetApp Platform to Commvault recovery orchestration, adding near-real-time threat detection and clean recovery for joint customers.
Onehouse · Technology · Positive Named as an open analytics integration engine for NetApp's upcoming AIDE innovations.
Starburst Data · Technology · Positive Named as an open analytics integration engine for NetApp's upcoming AIDE innovations.
NetApp Launches Keystone Sovereign Data Sovereignty Controls for Europe
NetApp announced NetApp Keystone Sovereign, a new Storage-as-a-Service offering that will enable qualified European customers to use data sovereignty controls in support of their compliance and data residency journeys. The offering is designed to keep data and support within specified geographic boundaries through European-based data residency for relevant customer data, logs, backups, and telemetry, European-based support and escalation paths, European-controlled access and management processes, clear documentation of telemetry, monitoring, and data flows, and contractual and legal structures that reinforce sovereignty expectations. Ivan Iannaccone, Vice President and General Manager, Keystone at NetApp, said data sovereignty has become a strategic requirement as organizations demand greater control over the technical and operational conditions that govern their data. Initial pilots for Keystone Sovereign will be available for Germany and France, with additional countries planned to be added. Simon Robinson, Chief Analyst, Storage & Data Infrastructure at Omdia, said the market opportunity for offerings like NetApp Keystone Sovereign is emerging as customers move beyond generic data residency requirements toward broader assurances around technical oversight, operational access, and support boundaries.
Cybersecurity & Digital Trust › Data Security & Cyber Resilience Technology
NTAP · Technology · Positive NetApp launches Keystone Sovereign, a new Storage-as-a-Service offering with European data sovereignty controls, expanding its product portfolio.
Secoma reports possible leak of 570,000 members' data after unauthorized access
Secoma, which operates the Hokkaido-based convenience store chain Seicomart, announced on the 29th that it may have suffered a leak of roughly 570,000 members' information following unauthorized external access. The information potentially leaked includes members' names, dates of birth, addresses, phone numbers and email addresses. No damage, such as fraudulent use of the company's electronic money service Pekoma Money, has been confirmed at this point. According to the company, on the 24th it discovered one account that had been improperly processed for withdrawal, revealing the possibility that its member server had been accessed without authorization, and it therefore shut down connections to the server.
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Demand
Cybersecurity & Digital Trust › Identity & Access Management ▼Demand
Secoma Co., Ltd. · Regulation · Negative Secoma disclosed a possible leak of ~570,000 members' data after unauthorized server access, exposing it to data-protection/legal fallout.
Rank One Computing wins eight-year, $64.3 million Department of Justice contract
Rank One Computing Corp shares rose 7% in Monday trading after the company secured an eight-year, $64.3 million contract with the U.S. Department of Justice. The award supports the Justice Department's Digital Evidence Review Platform program, with ROC managing the ingestion, review, analysis, and processing of e-discovery assets such as mobile device extractions and social media data for federal prosecutions. The contract comprises an initial one-year base period valued at approximately $7 million, followed by seven single-year option periods exercisable at the government's discretion. The win follows a federal Automated Biometric Identification System contract award and validates ROC's recent strategic acquisition of digital forensics firm ZTC. Management said federal law enforcement agencies are increasingly prioritizing domestic, sovereign AI solutions to modernize siloed analytical workflows and manage expanding digital evidence volumes.
Bedrock Data Extends Agent DLP to NVIDIA OpenShell for Data-Aware Agent Policy Enforcement
Bedrock Data announced it has extended Agent DLP, its runtime data loss prevention for AI agents, to NVIDIA OpenShell, the open source agent runtime that is part of the NVIDIA Open Safety Platform. The integration adds a policy evaluation layer in which Bedrock Data evaluates a request payload once OpenShell authorizes the request, checking it against an enterprise's data policies and returning the decision OpenShell enforces at runtime. Bedrock Data supplies the data context and the decision through OpenShell's Supervisor Middleware, drawing on its Metadata Lake enterprise knowledge graph, which classifies data in place across cloud, SaaS, AI and on-premises environments at petabyte scale. The company said the integration lets restrictions travel with data across tables, tools and handoffs between agents, so actions that permissions allow can still be stopped when the data involved may not go where it is headed. Bedrock Data Agent DLP for NVIDIA OpenShell is available today to Bedrock Data customers as an OpenShell supervisor middleware service, and teams can run it first in observe-only mode before turning on enforcement.
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Artificial Intelligence › Agentic AI & Autonomous Workflows Technology
Bedrock Data · Technology · Positive Bedrock Data announced its Agent DLP now integrates with NVIDIA OpenShell, available today to its customers as an OpenShell supervisor middleware service.
NVDA · Technology · Positive Bedrock Data extended its Agent DLP to NVIDIA OpenShell, part of the NVIDIA Open Safety Platform, adding a security integration for NVIDIA's agent runtime.
TrendAI Extends NVIDIA Agent Safety Platform With Threat Intelligence
TrendAI, the AI security business unit of Trend Micro Incorporated, announced support for the NVIDIA Agent Safety Platform, NVIDIA's full-stack infrastructure for running autonomous AI agents safely at enterprise scale. TrendAI Vision One extends NVIDIA's agent safeguards across the whole AI factory, covering agents, models, containers, storage and networks on one platform, pairing hardware-level detection on NVIDIA BlueField DPUs and network security with Zero Day Initiative threat intelligence. The platform's model protection uses inline inspection of prompts and responses to block prompt injection and jailbreaks and to redact sensitive data before it leaks, while harness and tool governance lets security teams control which tools and MCP servers agents can reach and inspect every tool call. Data and identity controls find and classify sensitive data feeding AI, stop agents from reaching data they shouldn't, extend file security and data loss prevention to files agents read and write, and strip excess privilege from agents and other non-human identities. Using NVIDIA BlueField DPU and DOCA telemetry, TrendAI Vision One detection stays trustworthy even if the host OS is compromised and correlates AI signals with endpoint, network and identity telemetry so a hijacked agent cannot move laterally unseen. Rachel Jin, Chief Platform and Business Officer and Head of TrendAI, said security cannot sit in one place and must cover the model, the harness, and every tool and data source an agent touches.
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Artificial Intelligence › Agentic AI & Autonomous Workflows Technology
Cybersecurity & Digital Trust › Identity & Access Management ▲Technology
4704.JP · Technology · Positive TrendAI, Trend Micro's AI security unit, announced support for NVIDIA's Agent Safety Platform, extending Vision One across the AI factory.
NVDA · Technology · Positive TrendAI extends NVIDIA's Agent Safety Platform, deepening adoption of NVIDIA's full-stack AI agent infrastructure and BlueField DPU/DOCA telemetry.
Up to 6.6 Million Times Car Member Records Leaked, Park24 Announces Unauthorized Access
Park24 announced on the 28th that unauthorized external access resulted in the leak of personal information of up to approximately 6.6 million members of its car-sharing service Times Car. The leaked data includes members' names, addresses, phone numbers, and email addresses, and no fraudulent use has been confirmed at this point. Driver's license information including images, as well as service membership numbers linked to JR West group companies through point rewards, were also leaked, and the data includes information on members who canceled their subscriptions over the past seven years. Credit card information was not leaked. Park24 detected the unauthorized access on the 25th and blocked communications from the attack source, and says there is no impact on car-sharing use.
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Demand
Cybersecurity & Digital Trust › Identity & Access Management ▼Demand
4666.JP · Regulation · Negative Park24 disclosed unauthorized external access leaking personal data of up to ~6.6 million Times Car members, a data-security/legal breach.
ShinyHunters Renews Attack on Oracle PeopleSoft, Bypassing Defenses, Google Says
Mandiant, the cybersecurity firm owned by Google, said on the 25th that the hacker group ShinyHunters has resumed a large-scale attack exploiting a vulnerability in Oracle's enterprise software PeopleSoft. The group reportedly circumvented defenses put in place after a summer attack. According to Mandiant's report, ShinyHunters exploited the PeopleSoft flaw between May 27 and June 9, with universities mainly among the victims. The hackers changed their methods in response to defense guidance published after the May-June attacks, and although some defenses were put in place by introducing web application firewall rules, they targeted organizations that had not applied the update Oracle provided to fix the vulnerability. The latest attack spanned a wide range of sectors, including higher education, technology, healthcare, agriculture, transportation, and government, affecting dozens of systems worldwide, though the names of the affected organizations were not disclosed. ShinyHunters has claimed involvement in multiple large-scale data leaks, and days before the report was published, it stated that it had stolen data belonging to U.S. Federal Bureau of Investigation employees.
Meta Loses New Mexico Jury Verdict Over Facebook Data Practices
A Santa Fe jury found on September 25 that Meta Platforms misled New Mexico residents about how Facebook handled their personal information, handing the state's attorney general a verdict in a case filed in 2021 and five years in the making. The state argued not that data leaked but that Meta described its privacy practices one way to users while permitting something else behind the interface, and the jury agreed after a two-week trial. Meta shares fell 3.33% to close at $751.66, a modest move against a business that turned over about $228 billion in the past year at a profit margin close to 30%. The verdict differs from Meta's earlier $17 billion settlement over claims involving teenage users in the one respect that matters to other states: a jury, not a company signature, made the finding. Damages have not been set, and the case traces back to Cambridge Analytica, whose data-harvesting revelations preceded the suit by three years.
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Regulation
META · Regulation · Negative New Mexico jury found Meta misled residents about Facebook's handling of personal data, a legal/regulatory verdict against the company
Bitget Raises Crypto Theft Estimate to $387.5M as Stolen XRP Moves
Bitget said about $387.5 million in cryptocurrency was transferred to attacker-controlled addresses during a Sept. 24 security breach, raising its estimate from an initial $351.6 million as the exchange works to trace and recover the assets. The higher figure reflects a more complete accounting that includes assets on the Zcash and TRON networks omitted from the original estimate, and does not represent additional unauthorized transfers. XRP accounted for one of the largest portions of the theft, with public blockchain records showing nearly 103 million XRP transferred from Bitget-linked wallets, and about 54 million XRP had left the five original holding wallets by 12:41 UTC Saturday, leaving roughly 49 million XRP across those accounts, down from about 70 million about eight hours earlier. Bitget CEO Gracy Chen said preliminary IP and blockchain analysis pointed to possible involvement by North Korean hackers, though the attribution has not been independently confirmed, and Mandiant and blockchain security firm SlowMist are assisting with the investigation. Bitget has launched a bounty program offering 5% of affected funds that participants directly help freeze and 5% of funds they help recover, and said its User Protection Fund will cover the financial impact of the breach while customer account balances remain unaffected.
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Technology
Bitget · Regulation · Negative Bitget suffered a $387.5M security breach, raising its loss estimate and tracing stolen XRP amid a hacker investigation.
XRP · Regulation · Negative Nearly 103 million XRP was stolen from Bitget-linked wallets, one of the largest portions of the $387.5M breach.
TRX · Regulation · Negative Stolen funds were traced on the TRON network, tying it to the Bitget breach and North Korean hacker attribution.
ZEC · Regulation · Negative Zcash-network assets were included in the raised $387.5M theft estimate from the Bitget breach.
VAST Data Launches DataEnclave for Secure AI Integration
VAST Data has announced the launch of VAST DataEnclave, a confidential AI capability that securely integrates leading AI models with sensitive enterprise data. Leveraging NVIDIA Confidential Computing, DataEnclave lets AI models from providers including Cohere, CrowdStrike, and Deepgram operate in secure environments, protecting both customer data and AI model intellectual property. The offering targets highly regulated industries such as financial services and healthcare, where sensitive data must interact with state-of-the-art AI models while remaining within trusted infrastructure. The initiative marks a significant step toward a more encrypted and secure AI ecosystem, with AI models managed alongside data to safeguard enterprise intellectual property.
Cloud & Digital Infrastructure › Data Platforms & Analytics ▲Technology
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Artificial Intelligence › AI Tooling, Data & MLOps ▲Technology
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
VAST Data · Technology · Positive VAST Data is the subject, launching DataEnclave, a new confidential AI capability for regulated industries.
NVDA · Technology · Positive DataEnclave leverages NVIDIA Confidential Computing, tying NVIDIA's secure-computing technology to a new confidential AI offering.
CRWD · Demand · Positive CrowdStrike's AI model is included as a provider that can operate in VAST DataEnclave's secure environment, expanding its enterprise AI deployment reach.
Deepgram, Inc. · Demand · Positive Deepgram's AI model is named as a provider usable within DataEnclave's secure environment, broadening its enterprise access.
Cloudflare Launches AI Crawler Controls With Disallow AI Training Setting
Cloudflare, Inc. launched new AI crawling controls in September 2026, including a "Disallow AI Training" setting and an Accountable designation for AI crawlers, giving website owners granular control over search, AI training, and AI agents while keeping them visible in search results. A key innovation is Cloudflare's Bot Preference Sync and accountability criteria, which standardize how websites express AI access preferences across major crawlers like Apple, Google, and Microsoft, aligning with emerging open standards work at the IETF. The company's narrative projects $5.4 billion revenue and $580.9 million earnings by 2029, requiring 28.7% yearly revenue growth and a $787.2 million earnings increase from -$206.3 million today. That forecast yields a $333.55 fair value, a 7% downside to its current price. Some of the lowest ranked analysts were already expecting revenue of about US$5,000,000,000 by 2029 but still saw margin and regulation risks as severe.
Artificial Intelligence › AI Tooling, Data & MLOps Technology
Cybersecurity & Digital Trust › Data Security & Cyber Resilience Technology
NET · Technology · Positive Cloudflare launched new AI crawling controls including a Disallow AI Training setting and Accountable designation for AI crawlers.
NET · Capital · Neutral Article cites a projected $5.4B revenue/$580.9M earnings by 2029 narrative yielding a $333.55 fair value, about 7% below the current price, with analysts flagging margin and regulation risks.
Cryptocurrency trading platform Bitget suffered a hot wallet leak of $351.6 million in a major hack. Arkham Intelligence was the first to raise the alarm after detecting massive withdrawals of AVAX, BNB, ETH and stablecoins from the wallet, which were later swapped into ETH. Bitget CEO Gracy Chen said the incident was confined to the hot wallet only, while assets in the cold wallet were unaffected. The attackers compromised critical backend systems, forged transaction records, and triggered withdrawal approvals without needing private keys. Bitget has temporarily suspended withdrawals while it conducts a security review, but deposits and trading continue as normal and user balances remain safe. The platform has flagged the receiving wallet addresses and is working with law enforcement and blockchain security firms to trace and recover the stolen funds, with a full report expected within 24 hours. Chen confirmed that Bitget will fully compensate the losses through its user protection fund, which is worth more than $464 million. The attack is the largest of 2026 in terms of funds lost, bigger than the $320 million Liquid Network attack and the $292 million KeloDAO hack, making it the year's largest single point of failure. Cybersecurity experts at Certik noted that this year attackers have shifted toward compromising infrastructure, stealing from hot wallets and gaining access to private keys, rather than exploiting smart contract vulnerabilities.
Cybersecurity & Digital Trust › Cloud & Workload Security ▼Technology
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Technology
Cybersecurity & Digital Trust › Identity & Access Management ▼Technology
Bitget · Regulation · Negative Bitget suffered a $351.6M hot wallet hack, suspended withdrawals, and must compensate losses via its user protection fund.
Jamf Unveils AI Governance and Automation Platform at JNUC 2026
Jamf announced a slate of new platform innovations at its 17th annual Jamf Nation User Conference in Kansas City, aimed at governing AI usage, making Apple management more programmable and automating routine endpoint work. The company, which supports more than 35 million devices across over 78,000 organizations, said its AI Governance capabilities are available today, letting organizations discover AI tools running across managed Macs, enforce usage policies and generate audit-ready reporting, with deeper AI activity insights, AI usage and cost insights, browser-based governance, on-device AI enablement and mobile AI governance all targeted for general availability in Q4 2026. On the programmability side, Jamf launched a new Platform API Gateway and a Terraform provider, both generally available today, while a Jamf-hosted automation engine for Routines with more than 1,500 integrations is targeted for general availability in Q1 2027. For autonomous endpoint management, Jamf introduced automated app lifecycle management through Blueprints, Apple-native endpoint data loss prevention and expanded App Insights, all targeted for Q4 2026, alongside AI-powered self-service diagnostics, device health insights and automated Ring Deployments, each targeted for public beta in Q1 2027. Jamf also said Jamf Tap and Jamf Device Checker are new frontline offerings, with Device Checker available today and Tap in public beta targeted for Q1 2027, and that JNUC 2027 will be held in Anaheim, California, from October 26 through 28, 2027, marking the company's 25th year.
Coinbase to Build Quantum-Resistant Crypto Custody System
Crypto exchange Coinbase revealed by September 22 that it is developing a crypto custody system capable of supporting any post-quantum signature scheme blockchains may adopt in the future, in preparation for the risk of quantum computers cracking encryption. Yehuda Lindell, the company's head of cryptography, explained this in a video interview with the Mara Foundation. The company is upgrading its current custody infrastructure, which uses multi-party computation, so that it can withstand attacks by quantum computers, and is also considering an alternative approach using specialized devices called hardware security modules in case a signature scheme is adopted that multi-party computation cannot handle. According to the Mara Foundation, the company protects roughly 250 billion dollars' worth of digital assets centered on this system. On July 23, Coinbase explained on its official blog that its current key management system, CoreKMS, protects about 99.9 percent of its custodied assets, and that it is also developing a quantum-resistant version, PQ-CoreKMS, with plans to build an automated infrastructure within one year that can securely sign while distributing keys across multiple locations. Over the following two to three years, it aims to develop multi-party computation that does not require generating a complete private key even for quantum-resistant signatures.
COIN · Technology · Positive Coinbase is developing a quantum-resistant custody system (PQ-CoreKMS) to protect its custodied assets against future quantum attacks.
ShinyHunters Claims It Breached FBI Systems, Leaking Staff and Job Applicant Data
The cyber extortion hacking group ShinyHunters claimed on Tuesday, September 22, that it had breached the systems of the U.S. Federal Bureau of Investigation, or FBI, and stolen a massive trove of data on both former and current personnel as well as job applicants. The FBI acknowledged it was aware of claims of an unauthorized intrusion affecting the FBIjobs.gov recruitment website and said it was investigating urgently. ShinyHunters said in an online chat with Reuters that the attack was retaliation for a public warning issued by the FBI in May 2026 that exposed the group's attack methods and urged victims not to pay ransoms. The hacking group claimed it stole data on nearly all FBI special agents along with people who had previously submitted job applications, and released a sample of records on about 5,000 personnel, including names, addresses, Social Security numbers, assigned duties, and the names of family members of some agents. A preliminary Reuters review comparing the data against credit bureau databases and leak histories recorded by dark web cyber threat intelligence firm District 4 Labs found at least 10 matching records, including data on Kash Patel, the FBI director, and sources close to the matter said the job details in the dataset matched reality in some cases.