GitLab announced major updates to its agentic AI and enterprise security tools, including the scalable GitLab Duo Agent Platform. The release introduces Secrets Manager to centralize and protect credentials across software projects, and new automated vulnerability triage solutions aimed at streamlining security issue prioritization for regulated and data-sensitive enterprises. GitLab, a US software company with a market value of about $7.2 billion, sells tools that help organizations manage the entire software development lifecycle across the US, Europe and Asia Pacific. The updates push agentic AI, security and credentials management deeper into customers' existing workflows, potentially making the platform more attractive to larger organizations that need control, compliance and scale. The clearest proof point to watch is how much Duo Agent Platform and related AI and security add-ons contribute to annual recurring revenue from larger customers paying over $100,000 each year in upcoming earnings.
Unauthorized Access Surges, Cyber Defense Inquiries Flood In as Hitachi, Fujitsu, and NEC Strengthen Systems
As unauthorized access to companies surges, electronics giants offering cyber defense services are receiving a flood of consultations and inquiries. In September, Hitachi launched a service that uses advanced AI models from U.S. firms such as Anthropic and OpenAI to provide end-to-end support spanning risk assessment, monitoring, and recovery. Fujitsu announced its cyber defense strategy in late August, and inquiries from client companies have poured in since then, increasing further in recent days, prompting it to establish a specialized organization of about 100 people effective October 1. NEC began offering a service in late September for financial institutions, manufacturers, and distributors that uses AI to automatically analyze risks and formulate response policies. Each company is strengthening its systems in anticipation of sophisticated AI-driven cyberattacks, and demand appears set to keep expanding.
Cybersecurity & Digital Trust › Network Security & SASE ▲Demand
6501.JP · Demand · Positive Hitachi launched an AI-based cyber defense service and is receiving a flood of consultations as unauthorized access surges.
6701.JP · Demand · Positive NEC began offering an AI cyber-risk service in late September to financial, manufacturing, and distribution clients amid surging attacks.
6702.JP · Demand · Positive Fujitsu's cyber defense inquiries have poured in since its late-August strategy announcement, prompting a new ~100-person specialized organization.
JR East: Over 2 Million Members' Data Possibly Leaked at Eki-net and Other Services
East Japan Railway Company announced on the 9th that more than 2 million members' information from its ticket reservation and travel support services "Eki-net" and "Otona no Kyujitsu Club" may have been leaked due to unauthorized access to a cloud service operated by a SoftBank subsidiary. Approximately 1.67 million email addresses of Eki-net members may have been compromised, while about 390,000 records from Otona no Kyujitsu Club, including membership numbers and credit card expiration dates, may have been leaked. Names, addresses, phone numbers, and credit card numbers were not included. In addition, email distribution to members of both services has been partially disrupted. IDC Frontier, the SoftBank subsidiary, suffered a ransomware attack on part of the systems of its cloud service "IDCF Cloud," affecting a wide range of contracted companies and local governments.
9020.JP · Regulation · Negative Over 2 million members' data from JR East's Eki-net and Otona no Kyujitsu Club services may have leaked via unauthorized access to a SoftBank subsidiary's cloud, and member email distribution was disrupted.
9434.JP · Regulation · Negative SoftBank Corp.'s subsidiary IDC Frontier was hit by a ransomware attack on its IDCF Cloud, affecting a wide range of contracted companies and local governments.
9984.JP · Regulation · Negative SoftBank subsidiary IDC Frontier suffered a ransomware attack on its IDCF Cloud, exposing data of contracted companies and local governments including JR East.
Japan's Financial Services Agency on the 9th, following a spate of customer data leaks caused by unauthorized access, called on financial institutions to review their cybersecurity measures and issued a warning. It is asking them to thoroughly check images of driver's licenses and other ID documents for anything unusual, even when verifying identity without meeting customers face to face. The FSA stressed that it wants institutions to prevent the fraudulent use of financial services and act so as not to undermine trust, urging them to review their response plans for cyberattacks and to promptly take any necessary measures where shortcomings are found. Financial Services Minister Satsuki Katayama said at a post-cabinet press conference on the 9th that identity verification should be carried out appropriately, including by reading IC chip information, which is extremely effective as a countermeasure against fraud. The Ministry of Economy, Trade and Industry announced it will issue warnings to roughly 1,000 industry associations under its jurisdiction, including those in the automotive and retail sectors, calling on management to take the lead in checking communications equipment and systems for vulnerabilities.
METI Issues Alert to About 1,000 Industry Groups After Spate of Unauthorized Access Incidents
Economy, Trade and Industry Minister Ryosei Akazawa said at a post-cabinet meeting press conference on the 9th that, in response to a series of incidents involving information leaks and other damage from unauthorized access in Japan, the ministry issued a broad alert the same day through roughly 1,000 industry groups under its jurisdiction. Akazawa called on companies to act on the understanding that they must manage security not only within their own operations but across the entire supply chain, and urged top management to take responsibility in securing the necessary resources and directing the response. He also encouraged them to quickly identify and address vulnerability information, monitor all activity on internal systems, and promptly provide information when damage occurs.
Rubrik Expands Project Hourglass With Code Guardian, Adds AHEAD, Trace3 and WWT
Rubrik announced the expansion of Project Hourglass, broadening its partner alliance to deliver Rubrik Code Guardian alongside Rubrik Agent Cloud. AHEAD, Trace3, and WWT joined the program, which already includes Cognizant, Deloitte, LTM, HCLTech, NTT DATA, and Wipro. Rubrik Code Guardian harnesses Anthropic's Claude Mythos 5 through a specialized security harness to evaluate code repositories against sophisticated, multi-step threat scenarios, testing a cloned, air-gapped copy of customer repositories rather than live production environments. According to Rubrik Zero Labs, 86% of cybersecurity and IT leaders anticipate that the proliferation of AI agents will outpace their organization's security guardrails within the next year. Rubrik Code Guardian is currently in private preview and accepting select design partners, and the company said it is not currently generally available and may change or be discontinued.
RBRK · Technology · Positive Rubrik expanded Project Hourglass and launched Rubrik Code Guardian, a new AI-agent security product now in private preview with new partners AHEAD, Trace3, and WWT.
Core6 Partners with Armis from ServiceNow to Extend Exposure Management to Storage and Backup
Core6 announced a partnership with Armis from ServiceNow that integrates its StorageGuard storage security posture management platform with Armis' continuous asset intelligence, extending cyber exposure management to storage and backup systems. The integration correlates Armis' real-time asset intelligence with StorageGuard's authenticated vulnerability and misconfiguration findings for storage and backup systems, closing a gap that has left storage arrays and backup platforms outside exposure management programs. Core6 founder and CEO Gil Hecht said several banks the FSB classifies as globally systemically important harden their storage and backup with StorageGuard. Nadir Izrael, GVP of Cybersecurity and Risk at ServiceNow, said the partnership enables security teams to shift from reactive threat response to autonomous, AI-driven security. The integration is available immediately for existing Armis from ServiceNow and Core6 customers.
Core6 · Demand · Positive Core6's StorageGuard is integrated with Armis from ServiceNow, extending its storage security posture management to more customers.
Armis Security · Demand · Positive Armis' continuous asset intelligence is integrated with Core6's StorageGuard, expanding its cybersecurity platform's reach into storage and backup exposure management.
NOW · Demand · Positive Armis from ServiceNow partnership integrates Core6's StorageGuard, extending ServiceNow's exposure management offering to storage and backup systems.