Category: News

Current, event-driven reporting, announcements and industry developments.

  • LastPass Adds Mobile Smart Scanner and Expanded SaaS Monitoring to Business Security Suite

    LastPass Adds Mobile Smart Scanner and Expanded SaaS Monitoring to Business Security Suite

    LastPass rolled out a series of product updates on August 31, 2026 aimed at credential and access management, including what the company describes as the industry’s first Mobile Smart Scanner and expanded SaaS Monitoring capabilities for its Business Max customers, according to the company’s announcement carried by Security Info Watch.

    What’s New

    The Mobile Smart Scanner lets users scan passwords from printed lists, screenshots and handwritten notes through the LastPass Mobile app and convert them into encrypted, autofill-ready credentials. Persistent Monitoring, now fully released across all browser extensions, keeps SaaS visibility active through a permanent browser-extension connection even when a user is signed out of LastPass, and administrators can now set more granular SaaS Protect usage rules for specific users or groups. LastPass also completed its move from a Legacy Admin Console to a single Unified Admin Console, introduced a company-wide sign-up link for Teams, Business and Business Max customers, and is shifting Dark Web Monitoring for consumer accounts to automatic enrollment. The company said it passed independent SOC 2 and ISO 27001/27701 audits with zero findings for a second consecutive year.

    Why It Matters

    LastPass tied the updates to IBM’s 2026 Cost of a Data Breach Report, which found AI-driven attacks rose 56% year over year and added roughly $1 million to average breach costs, with 92% of organizations hit by AI-related breaches lacking adequate AI access controls. The emphasis on visibility and credential hygiene mirrors a broader push across the industry to close the kind of access gaps that groups exploit in AI-assisted phishing and credential-theft campaigns.

  • Pentagon Suspends CMMC Phase II Rollout as Reform Task Force Reviews Program

    Pentagon Suspends CMMC Phase II Rollout as Reform Task Force Reviews Program

    The Department of Defense has suspended Cybersecurity Maturity Model Certification (CMMC) Phase II requirements that were scheduled to take effect November 10, 2026, while a reform task force reviews the program, according to an August 31, 2026 report from Security Info Watch. Phase I self-assessments and current NIST SP 800-171 Revision 2 obligations remain in effect for defense contractors.

    What’s Paused, What Isn’t

    Level 1 self-assessments covering 15 safeguarding requirements from FAR clause 52.204-21 continue on their annual cycle, and Level 2 self-assessments against the 110 security requirements in NIST SP 800-171 Rev. 2 continue every three years with annual affirmation, with results still required in the Supplier Performance Risk System (SPRS). For contracts under DFARS clause 252.204-7012, contracting officers must still verify a current SPRS assessment score before certain awards, extensions or option exercises. Only the timing of third-party CMMC Phase II assessments has changed, not the underlying obligation to safeguard Controlled Unclassified Information, Bill Osborne, vice president of Defense Sector Services at Magna5, told the publication.

    Why It Matters

    The pause gives contractors more time to fix gaps in scope, documentation and System Security Plans before a Third-Party Assessment Organization is engaged, rather than a reason to slow readiness work altogether. Compliance requirements of this kind sit alongside physical protections for critical infrastructure and defense-linked targets that state-linked threat actors continue to probe.

  • Keenfinity Splits Intrusion and Access Control Units Into Radionix and MiCOS

    Keenfinity Splits Intrusion and Access Control Units Into Radionix and MiCOS

    Keenfinity Group is separating its former Intrusion & Access portfolio into two dedicated subsidiaries effective September 1, 2026, with Radionix taking over intrusion alarm systems and MiCOS concentrating exclusively on access control, the company confirmed to Security Info Watch on August 31, 2026.

    New Leadership Structure

    Phil Dutoy, who joined Keenfinity in 2025 and previously worked on the company’s transformation strategy following its carve-out from Bosch, becomes CEO of Radionix. Gregor Schlechtriem, who had led the combined Intrusion & Access business through the Radionix brand launch, moves to lead MiCOS exclusively. Both companies remain wholly owned Keenfinity subsidiaries pursuing separate go-to-market strategies, and Keenfinity said the change will not alter existing product lines: Radionix continues to build on Bosch intrusion technology, while Bosch-branded access control products continue under the same development and support teams.

    Two Legacy Brands, Two Focused Businesses

    Radionix, formally launched at GSX 2025, builds on nearly six decades of intrusion-system heritage and includes the G Series platform that integrates intrusion detection, access control and fire alarm functions. MiCOS revives a brand with more than four decades of access control history and will operate out of Eindhoven, Netherlands, with a development center in Aachen, Germany. Keenfinity became an independent company on July 1, 2025, after Triton completed its acquisition of Bosch’s security and communications technology business.

    Why It Matters

    The split gives each business room to compete more directly in increasingly specialized markets, following a broader industry pattern of vendors separating access control strategy from intrusion detection as buyers demand deeper feature depth in each category rather than a single generalist product line.

  • CISA Ends Six Free Cybersecurity Assessments for Critical Infrastructure Operators

    CISA Ends Six Free Cybersecurity Assessments for Critical Infrastructure Operators

    The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed it is ending six free assessment programs long used by critical infrastructure operators to evaluate their cybersecurity posture, Cybersecurity Dive reported.

    What’s New

    CISA’s regional field staff will no longer conduct Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys. All six relied on CISA’s Cyber Security Evaluation Tool (CSET). Acting Cybersecurity Division head Chris Butera said eliminating the “legacy assessments” would “reduce redundancy for CISA and organizations requesting an assessment,” adding that operators can instead reference CISA’s Cybersecurity Performance Goals.

    Why It Matters

    Experts told Cybersecurity Dive that the Cybersecurity Performance Goals are not a substitute for the hands-on, in-person guidance the discontinued assessments provided. Tatyana Bolton, executive director of the OT Cyber Coalition, said “severe budget cuts have forced CISA into a corner where they can no longer provide the level of hands-on, operational support to critical infrastructure that they once did.” The change follows a reported loss of roughly a third of CISA’s workforce and comes as small utilities and rural operators — among the heaviest users of the free assessments — face rising cyber and physical threats with fewer federal resources to call on.

  • Ring Rolls Out TAKE Encryption to Limit Who Can Access Home Security Camera Footage

    Ring Rolls Out TAKE Encryption to Limit Who Can Access Home Security Camera Footage

    Amazon’s Ring announced a new default encryption system for its security cameras and video doorbells on August 26, 2026, called TAKE — short for Throw Away the Key Encryption — designed to limit ongoing access to customer video, including by Ring itself and by law enforcement without a user’s consent, according to the company’s announcement and reporting from The Verge and CEPRO.

    How TAKE Works

    Under the new system, each camera encrypts its video using unique keys that rotate roughly every five minutes. A temporary copy of each key is held in what Ring calls a secure enclave in the cloud, long enough to power features such as smart alerts, video search and AI-generated video descriptions, after which the company says it permanently deletes its copy of that key. Ring has framed the approach as a middle ground between full end-to-end encryption, which would block many of its AI-driven features outright, and its previous architecture, which gave Ring’s cloud infrastructure more persistent access to footage.

    Rollout Timeline

    TAKE is scheduled to become the default encryption setting for all Ring customers worldwide in phases starting in September 2026, according to the company’s announcement.

    Why the Framing Matters

    The change follows years of scrutiny over Ring’s video-sharing practices, including a 2023 FTC settlement over unauthorized employee and law-enforcement access to customer footage, and comes as its former data-sharing partner Flock Safety faces its own wave of municipal contract cancellations over surveillance and privacy concerns. Privacy researchers note that because Ring — not an independent, published standard — designed the key-deletion process itself, customers still have to trust Amazon’s implementation rather than verify it independently, a caveat also raised by outlets covering the announcement.

  • Researchers Find All 21 Tested Open-Weight AI Models Can Be Stripped of Safety Guardrails

    Researchers Find All 21 Tested Open-Weight AI Models Can Be Stripped of Safety Guardrails

    An international research team led by the University of Waterloo and the nonprofit AI-security group FAR.AI found that all 21 of the most widely used open-weight large language models they tested could have their built-in safety protections removed with relatively little technical effort, according to the university’s own announcement, corroborated by EurekAlert and independent technology outlet HyperAI.

    What the Researchers Tested

    The team built an open-source testing tool called TamperBench to standardize how they simulated tampering attacks across the 21 models. Every model examined could be modified to bypass its safety guardrails despite the protections built in by their developers, and the seven defensive techniques the researchers evaluated did not reliably stop the tampering methods they tried, according to the University of Waterloo’s release.

    The Stakes of Open Weights

    “When the safety guardrails are stripped out of a capable model, it can be used at scale for harm in ways a single person could never manage manually,” said Dr. Sirisha Rambhatla, a University of Waterloo professor of management science and engineering and director of its Critical Machine Learning Lab, who led the study. The researchers warned that models stripped of their protections could be used to run large-scale disinformation campaigns, automate convincing scam emails, or produce instructions for creating hazardous materials.

    Open Models Remain Valuable, But Riskier to Control

    The study’s authors were careful to note that open-weight models remain important for research transparency and independent scrutiny, since outside researchers can inspect and test them in ways closed, proprietary systems don’t allow. But once a model’s weights are published, its creator loses most practical ability to prevent later tampering — the opposite trade-off from closed models, where the vendor retains centralized control but outside researchers have far less visibility. The team’s findings, presented at the ACM Conference on Knowledge Discovery and Data Mining, add to a growing body of evidence that AI safety standards are lagging the pace at which open-weight models are approaching the capability of proprietary frontier systems.

  • PSG and Mercury Security Partner to Extend Zero Trust to Physical Security’s Far Edge

    PSG and Mercury Security Partner to Extend Zero Trust to Physical Security’s Far Edge

    Prometheus Security Group Global (PSG) announced a technology partnership with Mercury Security on August 27, 2026, aimed at extending Zero Trust principles down to the field-device level of physical security systems, according to the companies’ announcement and independent reporting from Security Systems News.

    Combining Access Hardware With Edge Authentication

    The partnership pairs Mercury’s open-architecture access-control hardware platform with PSG’s patented technology for embedding cryptographic identity, authentication and verification directly into far-edge field devices, including door readers, sensors and cameras. PSG describes the goal as moving physical security systems away from assumed, unverified inputs toward authenticated and cryptographically verified data starting at the point where it is generated, rather than only securing the network layer above it.

    Why Now

    The move extends a Zero Trust architecture approach that IT security teams have used for years, in which every device and request is continuously authenticated rather than implicitly trusted once inside a network perimeter, into physical and operational technology environments. PSG has previously supplied Zero Trust physical security technology to U.S. Air Force, Navy and Department of Energy programs, and has positioned far-edge authentication as a way to close a gap security researchers have flagged in converging IT and physical access control systems, where edge hardware has often remained a weaker link than the software managing it.

    What It Means for Integrators

    For organizations running Mercury-based access control, the partnership is intended to let them add cryptographic device-level verification without replacing existing access-control investments, addressing a common friction point in critical-infrastructure and high-security environments where wholesale hardware replacement is often impractical.

  • NextNav and Tiami Networks Partner to Test 5G-Powered Counter-Drone Sensing

    NextNav and Tiami Networks Partner to Test 5G-Powered Counter-Drone Sensing

    Positioning company NextNav has named Tiami Networks as a sensing ecosystem partner to jointly develop and evaluate counter-UAS detection capabilities built on 5G infrastructure, the companies announced on August 25, 2026, according to NextNav’s own release and independent reporting from UASweekly and Unmanned Airspace.

    The Technology

    The partnership will use NextNav’s existing 5G Positioning, Navigation and Timing (PNT) network, deployed on the licensed lower 900 MHz band, as a testbed in Santa Clara County, California. Tiami is contributing its radio-frequency sensing technology to the effort, with the two companies evaluating whether the same 5G infrastructure that provides positioning services can simultaneously support wide-area sensing for drone detection without adding load to the network. The approach falls under what the companies describe as integrated sensing and communications, or ISAC.

    Why Range Matters

    “The need for longer range situational awareness has never been more urgent as drones continue to threaten large-scale events, critical infrastructure, and government and military facilities including airports,” said David Gell, NextNav’s vice president of business development, in the companies’ announcement. That framing echoes a wider push across the counter-UAS sector this year toward detection systems that can spot drones farther out and earlier, giving operators more time to assess and respond before an unmanned aircraft reaches a protected site.

    Early-Stage Evaluation

    NextNav and Tiami characterized the work as an evaluation of performance and applicability rather than a finished product, with the companies planning to assess whether the low-band 5G approach can support counter-UAS, critical-infrastructure and national-security use cases alongside its existing positioning role.

  • Ambient.ai Adds Agentic Video Monitoring and Case Management Tools Ahead of GSX 2026

    Ambient.ai Adds Agentic Video Monitoring and Case Management Tools Ahead of GSX 2026

    Ambient.ai, a physical security AI vendor, announced new agentic capabilities across its platform on August 26, 2026, adding AI agents that continuously monitor camera feeds and automated case-management tools that assemble scattered video clips into a single incident timeline, according to the company’s announcement carried via PR Newswire and confirmed by Security Systems News.

    What’s New

    The centerpiece of the release is an AI agent Ambient.ai describes as continuously monitoring every connected camera and surfacing the events operators are most likely to need to see, rather than requiring security teams to actively watch banks of live video feeds. Alongside it, the company introduced a new case-management workflow intended to turn clips from multiple cameras and time windows into a single connected incident narrative, cutting down the manual work of stitching together footage during investigations. Ambient.ai also said it made infrastructure upgrades to support the new features at scale.

    Timed to GSX 2026

    The company plans to demonstrate the new Agentic Video Wall and case-management tools live at its booth (#3923) during GSX 2026 in Atlanta, positioning the release as part of a broader wave of “agentic” AI marketing across the physical security industry this year, as vendors compete to move video analytics from passive alerting toward autonomous monitoring and response.

    Why It Matters

    The announcement reflects a broader industry shift already visible in the growing adoption of AI-assisted video management platforms, where vendors are racing to differentiate on how much investigative and monitoring work their software can take on autonomously rather than leaving it to human operators watching screens.

  • Two Unitree G1 EDU Humanoid Robot Flaws Enable Root-Level Takeover

    Two Unitree G1 EDU Humanoid Robot Flaws Enable Root-Level Takeover

    Security researchers have disclosed two vulnerability chains affecting the Unitree G1 EDU humanoid robot that can grant an attacker root-level control over the machine’s onboard computer, tracked as CVE-2026-76639 and CVE-2026-76640, according to The Hacker News and Security Affairs.

    Two Distinct Paths to Root

    The first chain is network-adjacent, reaching root through the robot’s chat_go and bashrunner components. The second begins over Bluetooth Low Energy proximity, exploiting the robot’s Wi-Fi provisioning process to reach a buffer overflow that grants root execution on the Locomotion PC — meaning an attacker within wireless range, without any network access, can potentially take full control of the robot. Researcher Kevin Finisterre, writing on the disclosure, noted the financial and operational stakes bluntly: “They also cost a lot! I’d be pissed off if someone hacked into my G1, took control of it, and walked it off my factory/campus.”

    No Confirmed Fix Yet

    As of the disclosure, no fixed firmware release could be independently verified in Unitree’s public guidance, leaving G1 EDU owners without a confirmed remediation timeline for either vulnerability. The Hacker News reported it had reached out to Unitree to confirm affected product scope and fix status but had not received a response as of publication. Unitree’s product page lists the G1 and G1 EDU as separate models, and researchers have not yet confirmed whether the flaws extend to other robots in Unitree’s lineup.

    Part of a Pattern With Consumer-Facing Robotics

    The disclosure follows earlier security research into Unitree hardware, including a September 2025 finding that a Bluetooth Low Energy exploit dubbed UniPwn could achieve wormable root-level compromise across multiple Unitree platforms, including its Go2 and B2 quadrupeds and G1 and H1 humanoids, using a single hardcoded key shared across the entire device fleet. Robotics cybersecurity researchers have separately raised concerns about undisclosed telemetry from Unitree devices. For organizations deploying humanoid or quadruped robots in factories, campuses or public-facing roles, the G1 EDU findings underscore that physical robotics platforms now carry the same remote-exploitation risk profile as any other networked, wireless-enabled endpoint.