Category: Security

  • FedRAMP High Arrives for Defense Supply-Chain Compliance

    FedRAMP High Arrives for Defense Supply-Chain Compliance

    On September 1, 2026, Baltimore-based FutureFeed and CyberIllumination announced that both platforms have achieved FedRAMP High Authorized (Class D) status. FutureFeed is a compliance platform for NIST SP 800-171 and CMMC used across the Defense Industrial Base (DIB); CyberIllumination, operated by Continuous Compliance LLC and currently in beta, gives prime contractors and subcontractors a shared view of supply-chain cybersecurity posture.

    Per the release, Class D aligns with the historical FedRAMP High baseline, the standard applied to federal systems where a loss of confidentiality, integrity, or availability could have severe or catastrophic consequences. The authorizations followed independent third-party assessments of each platform’s security controls. Cloud service provider Project Hosts supported both efforts. FutureFeed reports more than 1,400 clients and 350-plus partners across the DIB.

    Executive Summary

    The announcement is narrow in substance and broad in signal. Two platforms that hold defense contractors’ most sensitive compliance artifacts — system security plans, risk assessments, audit evidence, supplier posture records — now carry the federal government’s highest authorization tier for unclassified cloud workloads. FedRAMP, the Federal Risk and Authorization Management Program, standardizes how cloud services are security-assessed for government use; its High baseline sits above the Low and Moderate tiers and applies to data whose compromise would be severe or catastrophic.

    Why it matters: the data these platforms aggregate is arguably more sensitive than any single customer’s own environment. A compliance tool serving 1,400 DIB organizations holds a consolidated map of where the defense supply chain is weakest — which controls are unimplemented, which remediation plans are open, and for how long. That concentration is exactly the profile FedRAMP High was written for, and it is the strongest argument in the release.

    What the release does not do is quantify its central marketing claim. It states that “few compliance platforms reach FedRAMP High” without a figure, names no federal agency customer, and does not disclose the authorization pathway, effective date, or cost. The security assessment is independently validated; the competitive framing around it is not.

    The Compliance Tool Becomes the Concentration Risk

    There is a structural irony in defense compliance software. To help a contractor prove it protects Controlled Unclassified Information (CUI), the platform must first collect a detailed inventory of that contractor’s security gaps. Multiply that across a customer base the size of FutureFeed’s stated 1,400 clients and 350-plus partners, and the vendor accumulates something no individual contractor holds: a cross-sectional view of where the defense industrial base is unprotected, documented in audit-ready detail.

    That is the honest case for FedRAMP High here, and it does not depend on marketing language. A system security plan describes architecture, boundaries, and control implementation. A plan of action and milestones (POA&M) is, functionally, a dated list of known weaknesses and when they will be fixed. Aggregated, these are high-value targets regardless of whether the platform itself ever touches a federal network. Holding the aggregator to the same bar as the systems it describes is a defensible design principle.

    For buyers, the practical read is that vendor due diligence in this category should now include the platform’s own authorization posture, not just its feature list. For competing vendors, the announcement raises the reference point in procurement conversations even where no regulation formally requires it.

    What FedRAMP High Buys — and What It Does Not

    Context matters for interpreting the tier. Under DFARS 252.204-7012, cloud service providers handling covered defense information for contractors are generally expected to meet requirements equivalent to the FedRAMP Moderate baseline. High sits above that. So this is a vendor electing to exceed the common contractual floor for its market segment — a legitimate differentiator, but one worth describing precisely rather than as a pass/fail gate that competitors have failed.

    It is also worth separating what an authorization certifies from what it implies. FedRAMP attests that a defined system boundary was assessed against a control baseline by an independent assessor at a point in time, and that continuous monitoring obligations apply thereafter. It does not certify product quality, data-handling ethics, uptime, or that every customer workload runs inside the authorized boundary. The release states that CyberIllumination runs in AWS GovCloud on U.S. soil; it does not state the hosting arrangement for FutureFeed, nor whether existing customers are automatically served from the authorized environment.

    The economics deserve a mention because they shape the market. FedRAMP authorization is a capital-intensive exercise in assessment, documentation, and ongoing monitoring — historically a barrier that favors larger vendors or those buying a compliant platform-as-a-service underneath them. That is precisely the gap Project Hosts describes filling with its FasTrack program, which the release says provides a path to authorization without securing an agency sponsor. Sponsorless pathways lower the barrier meaningfully; they also make “few platforms reach FedRAMP High” a claim with a shorter shelf life than the announcement implies.

    The Flow-Down Problem and the Case for Authorize-Once

    CyberIllumination’s stated premise is the more interesting product thesis in the release: compliance obligations flow down every tier of the defense supply chain, but visibility does not. A prime contractor may hold a contract requiring assurance about subcontractors it has limited insight into, while a small supplier answers substantially the same questionnaire for every prime it serves. The proposed fix — a supplier authorizes one compliance record and shares it with multiple primes, with audit logs of who accessed what — replaces N questionnaires with one record.

    This is a two-sided network, and two-sided networks are hard to start. Suppliers only benefit if enough primes accept the shared record; primes only adopt if enough suppliers are on it. The audit-log design is a sensible trust mechanism for the supplier side, since the objection to shared compliance data is usually not transparency but loss of control over who sees weaknesses. Whether primes will accept a third-party record in place of their own assurance process is an adoption question the release does not address.

    One detail is worth flagging plainly and without prejudice: the release describes CyberIllumination as currently in beta. Authorizing a pre-general-availability product at the High baseline is unusual sequencing, though not improper — building to the standard before scale is arguably better practice than retrofitting. It does mean the authorization currently applies to a platform with an undisclosed production customer base, and readers should not infer commercial traction from a security designation.

    Background

    Defense contractors have faced formal cybersecurity obligations for roughly a decade, beginning with DFARS clauses requiring implementation of NIST SP 800-171 to protect Controlled Unclassified Information. Self-attestation proved uneven, and the Department of Defense responded with the Cybersecurity Maturity Model Certification program, which introduces third-party verification and is being phased into contracts. The practical effect has been a surge in demand for software that helps contractors document, evidence, and sustain compliance rather than reconstruct it before each assessment.

    FutureFeed, based in Baltimore, built its business in that market, reporting more than 1,400 clients and 350-plus partners including managed service providers and consultants. CyberIllumination extends the same logic upward into the supply chain, addressing a persistent structural gap: obligations flow down through every contracting tier, but reliable visibility into whether lower tiers have met them does not flow back up. FedRAMP, meanwhile, has spent recent years modernizing its authorization process to reduce cost and time-to-authorization — context that makes new High-tier entrants in specialized software categories more likely, not less.

    Source: FutureFeed and CyberIllumination Achieve FedRAMP High Authorized (Class D) Status, the Federal Government’s Highest Cloud Security Bar — PR Newswire release issued from Baltimore on September 1, 2026, announcing FedRAMP High authorizations for two Defense Industrial Base compliance platforms.

  • AI Agents as Digital Actors: Governance Lags Adoption

    AI Agents as Digital Actors: Governance Lags Adoption

    Info-Tech Research Group, an IT research and advisory firm, published new research on 28 August 2026 from Arlington, Virginia, arguing that enterprise AI agents should be governed as a distinct class of digital actor rather than as ordinary IT assets or as earlier generative AI models. The blueprint, Govern Enterprise AI Agents While Preserving Innovation, sets out a three-phase framework for managing agent identity, access, autonomy limits and ongoing oversight.

    The firm names five governance gaps it says organizations hit as agent use spreads: shadow AI, capability mismatch, runtime drift, unmanaged access and ambiguous ownership. The blueprint ships with a governance playbook, a charter example, an executive dashboard template and a glossary. Info-Tech says it serves more than 30,000 IT, HR and marketing leaders and has operated for nearly 30 years.

    Executive Summary

    The core claim is narrow and worth taking seriously: an AI agent does not merely produce output, it takes action. It can call systems, trigger workflows and make decisions on its own, at machine speed. That breaks the assumption underneath most enterprise AI governance to date, which is that a human reviews and approves a model’s output before anything consequential happens. Info-Tech’s position is that one-time approval gates cannot govern something that keeps operating after the gate.

    Altaz Valani, principal advisory director at Info-Tech, frames the problem in the release as a mismatch on both sides: agents cannot be governed like IT assets because they act across systems, and they cannot be governed like employees because, in the firm’s words, they move quicker and lack emotions, conscience and consequences. The practical translation is that the controls that work on people — training, incentives, accountability, the fear of being fired — have no purchase here. What is left is identity, credentials, permissions, monitoring and a defined kill switch.

    That is not a new discipline. It is the same control discipline that regulated supply chains already run under. On the same day, Nelson Miller Group announced it had earned Cybersecurity Maturity Model Certification (CMMC) Level 2, the US Department of Defense standard that obliges defense manufacturers to demonstrate control over access to sensitive information. The difference is that defense suppliers are made to prove those controls by contract, while most enterprises are deploying agents years ahead of anything comparable.

    Approval Gates Do Not Govern Things That Keep Moving

    Most enterprise AI governance was designed for a request-and-response world. A team proposes a use case, a committee reviews it, a model is approved, and a human checks the output before it becomes a decision. That control model has a hidden dependency: the risk sits still long enough to be reviewed. An agent breaks the dependency because the approval happens once and the behaviour continues indefinitely, across systems, with credentials attached.

    Info-Tech’s five named gaps are really five ways that assumption fails. Shadow AI means agents created outside sanctioned tools that IT does not know exist — the same problem as unsanctioned SaaS, except the unsanctioned thing holds credentials and acts. Capability mismatch means an agent’s autonomy and access outrun the validation and monitoring applied to it. Runtime drift means an agent quietly expands its scope as tools, prompts and permissions change, so the thing running in month six is not the thing that was approved in month one. Unmanaged access means service accounts and permissions let an agent do more than anyone intended. Ambiguous ownership means that when something goes wrong, no one is clearly accountable.

    None of these are exotic. They are the standard failure modes of any privileged non-human identity, which is why the useful reading of this research is deflationary rather than alarming: agentic AI is largely an identity and access management problem wearing new clothes. The genuinely new part is speed and volume. As Valani notes in the release, many people will have multiple agents working for them — which means identity populations that were once measured in employees start being measured in some multiple of employees.

    The CMMC Parallel: Regulated Sectors Already Do This, Under Contract

    The comparison worth drawing is with the defense industrial base. CMMC is the US Department of Defense’s framework for verifying that contractors and subcontractors protect sensitive government information; Level 2 aligns with the NIST SP 800-171 control set for controlled unclassified information, covering access control, identification and authentication, audit and accountability, configuration management and incident response. Nelson Miller Group’s 28 August 2026 announcement that it earned Level 2 certification is, in commercial terms, a supply chain credential: it is how a manufacturer stays eligible for programs that handle protected data.

    Strip away the acronym and the CMMC control families read like a specification for governing agents: know every identity, prove who owns it, restrict what it can reach, log what it did, detect when it drifts, and be able to respond. The defense supplier does this because a contracting officer requires it and an assessment verifies it. The enterprise deploying a fleet of agents has no equivalent forcing function — no customer withholding a purchase order, no assessor arriving to check the evidence.

    That asymmetry is the real story. Control discipline in enterprise technology almost never arrives because it is a good idea; it arrives because a contract, a regulator or an insurer demands proof. Agentic AI is currently in the window between capability and requirement. Firms in regulated supply chains have an unusual advantage here: the muscle memory of proving controls to a third party transfers directly to governing non-human identities. Firms without that history are building the practice from a standing start, and doing it while the agents are already running.

    What the Release Substantiates, and What It Does Not

    This is analyst research promoting a paid deliverable, and it should be read as such — evenly, without either deference or dismissal. What is substantiated is a structured method. The three phases are specific and sequenced: Phase 1 establishes governance authority, decision rights and a small set of enforceable guardrails; Phase 2 maps the agent lifecycle, discovers agents wherever they are created, classifies them by risk and defines runtime monitoring and intervention actions by risk tier; Phase 3 assigns accountability across business owners, technical owners, AI governance and enterprise risk, then defines metrics, executive dashboard reporting and a phased rollout. The named artifacts — playbook, charter example, executive dashboard, glossary — are the ordinary output of this kind of advisory engagement and are reasonable to expect.

    What is not substantiated is the scale of the problem the framework addresses. The release describes a widening gap between adoption and governance but offers no survey data, no incidence rates for shadow agents, no measured cost of a runtime-drift failure and no baseline for how many organizations currently classify agents by risk at all. It refers to case studies without naming an organization or an outcome. The assertion that agents “lack conscience and cannot be morally incentivized” is a framing device rather than a finding; it is intuitively correct and empirically untested as stated here.

    That is not a criticism of the firm — vendor and analyst releases are marketing documents by design, and this one is unusually specific about method for the genre. It does mean a buyer should treat the framework as a hypothesis to be tested against their own environment rather than as evidence that their environment is on fire. The prudent question for a CIO is not whether the five gaps sound plausible, but which of them they can actually measure in their own estate this quarter.

    Who Gains: Identity Vendors, Platform Owners and Whoever Owns the Log

    If agent governance becomes an identity problem, the commercial gravity moves toward whoever already holds the identity layer. Identity and access management providers, privileged access management vendors and cloud platforms that issue and rotate machine credentials are positioned to extend existing products rather than sell new categories. Security operations vendors benefit from the runtime monitoring requirement, since drift detection is a telemetry problem before it is a policy problem. Governance, risk and compliance platforms gain a new object type to track.

    The harder position belongs to business units that have deployed agents quickly using departmental budgets and low-code tooling. Info-Tech’s Phase 2 — find agents wherever they are created — is the phase that generates conflict, because discovery inevitably surfaces work that was never registered with IT. Organizations that treat that discovery as an audit failure will drive the remaining agents further underground; the ones that treat it as an inventory exercise will get better data.

    For infrastructure operators specifically, there is a second-order consequence worth noting. Agents that act autonomously across systems generate authentication events, API calls and audit records continuously rather than in bursts tied to human working hours. Logging, retention and monitoring costs scale with that behaviour. Governance frameworks tend to be discussed as policy; the bill arrives as storage, egress and detection capacity.

    Background

    Info-Tech Research Group is an IT research and advisory firm that publishes structured methodologies — it calls them blueprints — covering IT strategy, security and governance, alongside affiliates McLean & Company for HR research and SoftwareReviews for software buying data. Its business model is subscription advisory, so its research releases both inform the market and market the firm; that dual purpose is standard for the analyst sector and is worth holding in mind when reading any single publication.

    The wider context is a two-year shift from generative AI, where models produce content a human then uses, to agentic AI, where software is granted credentials and permitted to act. That shift moves AI from a content-quality question into an access-control question, territory enterprise security teams have worked in for decades under frameworks such as NIST SP 800-171 and, for defense suppliers, the Department of Defense’s CMMC program. The unresolved issue is timing: regulated supply chains prove their controls because contracts require it, while most enterprises are deploying agents without an equivalent obligation.

    Source: AI Agents Must Be Governed as Persistent Digital Actors, Advises Info-Tech Research Group — the firm’s 28 August 2026 announcement of its Govern Enterprise AI Agents While Preserving Innovation blueprint, with background from Nelson Miller Group’s same-day CMMC Level 2 certification release.

  • MDR Buyer’s Remorse: What CISOs Must Fix Before Signing

    MDR Buyer’s Remorse: What CISOs Must Fix Before Signing

    Info-Tech Research Group, a global IT research and advisory firm, published a blueprint titled Streamline Security Detection & Response Outsourcing on August 27, 2026, from Arlington, Virginia. The firm argues that rising threat volume, expanding attack surfaces and thin security operations capacity are pushing more organizations toward managed detection and response (MDR) — an outsourced service where a third party watches an organization’s systems around the clock and reacts to suspected attacks — but that inconsistent vendor terminology makes providers hard to compare.

    The blueprint sets out a four-phase procurement methodology: Prepare, Set Outcomes, Procure, and Implement & Govern. Senior research analyst Seva Ioussoufovitch is quoted urging leaders not to “rush into a contract you’ll regret.” The full blueprint is available to Info-Tech clients and to media through the firm’s Media Insiders program.

    Executive Summary

    The announcement is advisory content rather than a product launch, but the problem it names is real and expensive. MDR has become a default answer for organizations that cannot staff a 24/7 security operations centre. Info-Tech’s position is that the market’s naming conventions — MDR, MSSP, SOCaaS, XDR-as-a-service and a long tail of branded packages — obscure genuine capability differences, so buyers end up comparing marketing categories instead of deliverables.

    Why it matters: detection and response is one of the few security functions where the buyer hands over not just tooling but decision-making during an incident. A contract that specifies how many alerts a provider triages, without specifying what the provider is authorized to do about them, who owns the resulting telemetry, and how the relationship unwinds, buys visibility the customer cannot act on. Info-Tech’s framing — capabilities and outcomes over acronyms — points in the right direction.

    The release also makes a secondary argument worth noting: MDR procurement is a natural moment to rationalize overlapping security tools, because modern providers often bring capabilities a buyer already licenses. That reframes an MDR deal from an added line item into a potential consolidation event, which changes the business case considerably.

    The Acronym Problem Is Really a Comparability Problem

    Info-Tech’s central observation — that providers use overlapping terms and branded descriptions for similar capabilities — sounds like a semantics complaint. It is actually a market-structure issue. When two offerings cannot be placed on the same axis, price competition weakens, because a buyer cannot credibly say a rival will do the same work for less. Differentiated naming is not necessarily deceptive; vendors genuinely build different things. But the practical effect is that the burden of constructing a comparison framework falls entirely on the buyer.

    That burden lands on exactly the teams least able to carry it. The release identifies limited security team bandwidth as one of its four named obstacles, alongside inconsistent terminology, growing vendor portfolios, and rushed decisions. The circularity is stark: organizations turn to MDR because they lack security operations capacity, then need meaningful security operations capacity to evaluate MDR properly. Structured requirements templates — the kind Info-Tech is selling — exist precisely to lower that evaluation cost. Whether a generic template is specific enough for a given environment is a fair question, and one the release does not address.

    Alert Volume Is the Wrong Unit of Account

    Info-Tech’s phase two calls for measurable KPIs and service level requirements, without prescribing which ones. That restraint is defensible in a general methodology, but it leaves the hardest question open. The metrics MDR contracts most commonly carry — alerts triaged, mean time to detect, mean time to acknowledge — measure the provider’s throughput, not the customer’s risk reduction. A provider can hit every one of them while an intrusion progresses, because acknowledging an alert is not containing an incident.

    The commercially decisive terms sit elsewhere: whether the provider may isolate a host, disable an account or block traffic without waiting for customer approval; how fast that authority applies at 3 a.m. on a holiday; and what happens when the provider acts and is wrong. Response authority is what separates managed detection from managed detection and response, and it is the clause most often softened during negotiation because it carries liability for both sides. Buyers who treat it as boilerplate discover the gap during their first serious incident. Info-Tech’s release does not name these specific terms; the emphasis on defining how responsibilities are divided between organization and provider in phase one is nonetheless the right place to force the conversation.

    Consolidation Cuts Both Ways

    The blueprint’s argument that MDR procurement can surface duplicate tooling is the most immediately monetizable idea in the release. If a provider’s platform already covers endpoint detection, log aggregation and threat intelligence, a buyer paying separately for all three has a genuine savings case — and a stronger negotiating position, because the deal is now worth more to the vendor. For infrastructure operators running their own colocation, network and cloud estates, this is often where the real economics of an MDR deal live.

    The counterweight is concentration. Folding detection tooling into a provider’s stack means the provider owns the pipeline that generates the evidence of its own performance. That raises questions the release does not take up: whether the customer retains a copy of raw telemetry in its own storage, in what format, for how long, and at what egress cost on the way out. A buyer who consolidates onto provider-owned tooling and later wants to switch may find that the practical cost of leaving is not the migration project but the loss of detection history — the baseline that makes anomaly detection work. Consolidation savings are real; they should be scored net of that exit risk, not gross.

    Governance Is the Phase Nobody Staffs

    Phase four asks organizations to actively govern provider performance rather than treat service reviews as passive status updates. This is the least glamorous part of the framework and probably the most predictive of whether a deal succeeds. An MDR relationship degrades quietly: detection rules go stale as the environment changes, integrations silently break after a cloud migration, escalation contacts leave the company. None of that shows up in a monthly alert-count report.

    The problem is that governance requires a named internal owner with time and authority — the same scarce resource whose absence justified outsourcing. Organizations that buy MDR as a headcount substitute and assign oversight as a fraction of someone’s week tend to get the relationship they resourced. The honest version of the business case treats MDR as a capacity multiplier that still requires a retained internal function, not as a full replacement. Info-Tech’s four phases imply that conclusion without stating it, and buyers would be well served to make it explicit in their own board-level justification.

    Background

    Managed detection and response emerged over the past decade as a response to a structural shortage: continuous threat monitoring requires staffing across three shifts, specialist tooling and constant tuning, which is out of reach for most organizations outside the largest enterprises. The category grew out of earlier managed security service provider (MSSP) models, which largely forwarded alerts to the customer, by adding investigation and, in principle, active response. Adjacent labels — SOC-as-a-service, extended detection and response, co-managed SIEM — overlap heavily in practice, which is the comparability problem Info-Tech’s blueprint addresses.

    Info-Tech Research Group is an IT research and advisory firm headquartered with a US presence in Arlington, Virginia, publishing prescriptive methodologies it calls blueprints alongside advisory services. Its business model is subscription research, so its published announcements function both as analysis and as marketing for the underlying deliverable. This particular release was distributed via PR Newswire’s CNW service on August 27, 2026, and follows other recent Info-Tech procurement guidance, including work on agentic AI contracting.

    Source: CISOs Risk MDR Buyer’s Remorse Without Clear Procurement Requirements, Says Info-Tech Research Group — Info-Tech Research Group’s August 27, 2026 announcement of its four-phase blueprint for procuring managed detection and response services.

  • SealingTech Wins $750M USCYBERCOM Award for Joint Cyber Hunt Kit Full-Rate Production

    SealingTech Wins $750M USCYBERCOM Award for Joint Cyber Hunt Kit Full-Rate Production

    Sealing Technologies (SealingTech), a subsidiary of Parsons Corporation (NYSE: PSN), announced on August 25, 2026 that it has received a five-year, sole-source Other Transaction Agreement from U.S. Cyber Command to begin full-rate production of the Joint Cyber Hunt Kit (JCHK), with a ceiling value of up to $750 million.

    The JCHK is a mobile, self-contained defensive cyber platform — effectively a deployable security operations center — built for the military’s Joint Cyber Protection Teams. It replaces a patchwork of service-specific kits with a single standardized system, and SealingTech is the sole prime contractor.

    Executive Summary

    The award moves the Joint Cyber Hunt Kit from prototyping into full-rate production, the acquisition milestone at which the Department of War commits to buying a system at scale rather than in test quantities. SealingTech, which had previously received a contract modification to continue the JCHK prototype, now holds the program outright as sole provider and prime contractor for up to five years.

    For Parsons, the win reinforces a strategic bet: the company says its cyber and electronic warfare business already represents more than 20% of total revenue, and SealingTech’s deployable edge hardware sits at the center of that portfolio. A $750 million ceiling on a single defensive-cyber hardware program is a substantial figure in a market segment historically dominated by services contracts rather than productized systems.

    The broader signal is infrastructural. Cyber defense at the tactical edge is being standardized, productized, and procured at industrial scale — the same trajectory that servers, storage, and networking followed in the commercial data-center world, now applied to fly-away kits that must operate on contested and disconnected networks.

    From Fragmented Kits to a Standardized Platform

    Until now, each military service largely fielded its own cyber-hunt equipment — different hardware, different software baselines, different logistics tails. According to the release, the JCHK deliberately replaces those fragmented, service-specific kits with a single joint system, improving interoperability and accelerating mission readiness for Cyber Protection Teams, the units tasked with finding and evicting adversaries from U.S. and allied networks.

    Standardization is the real story here. A common platform means common training, common spares, common software updates, and comparable telemetry across teams — the same logic that drives enterprises toward standardized server fleets. The release also notes the kit was co-developed with key allies, which matters for “hunt forward” missions, in which U.S. teams deploy to partner nations’ networks at their invitation to hunt for threats. A shared hardware baseline lowers the friction of operating on someone else’s infrastructure.

    The Deployable SOC as an Edge-Computing Product

    Functionally, the JCHK is a security operations center (SOC) compressed into transportable cases: expanded storage, high-throughput processing, and integrated analytics that let operators capture and interrogate network traffic on site, without reach-back to a distant cloud. The release emphasizes operation in “connected, disconnected, and contested environments” — meaning the kit must work when links home are degraded, jammed, or deliberately severed.

    That places this award squarely in the edge-computing trend familiar to commercial infrastructure buyers. The technical problems — dense compute in constrained power and thermal envelopes, ruggedization, rapid setup, local data gravity — mirror what telecoms and industrial operators face at their own edges. SealingTech built the JCHK on years of portable edge-compute and Cyber Fly-Away Kit engineering, and the defense market is effectively validating that deployable, modular infrastructure is now a product category, not a custom integration exercise.

    Ceiling Values, OTAs, and What $750M Actually Means

    The contract’s structure deserves scrutiny. This is an Other Transaction Agreement (OTA) — a flexible acquisition vehicle that sits outside traditional federal procurement regulations and is designed to move faster, often with non-traditional contractors. The $750 million figure is a ceiling over five years, not guaranteed revenue: actual orders will depend on annual budgets, fielding schedules, and USCYBERCOM’s demand. Investors should read it as the maximum size of the opportunity, not a booked backlog.

    The sole-source structure cuts both ways. For the government, a single prime simplifies configuration control and accountability on a standardized platform. For the market, it concentrates a significant defensive-cyber hardware franchise in one vendor, which typically strengthens pricing power and follow-on positioning — sustainment, refresh cycles, and software — while raising the familiar questions any single-supplier arrangement invites about long-term price competition and surge capacity. The release does not describe how the sole-source decision was justified, which is standard for announcements of this kind but worth noting.

    Winners, Losers, and the Parsons Portfolio Effect

    The clearest winner is Parsons, which acquired veteran-founded SealingTech (established 2012) and now sees that bet mature into a franchise program. With cyber and electronic warfare already exceeding 20% of company revenue by Parsons’ own description, JCHK full-rate production deepens a differentiated hardware-plus-software position that most services-oriented defense primes lack. The competitive implication is that vendors of the legacy service-specific kits the JCHK replaces lose their footholds as those systems retire.

    For the wider industry, the award signals that deployable cyber-hunt infrastructure is being militarized at genuine scale — procured like a weapons system, with full-rate production milestones and multi-year ceilings. That is likely to pull more edge-hardware makers, ruggedized-compute specialists, and analytics vendors toward the defense market, and it gives allied governments a reference model for their own deployable cyber programs.

    Background

    SealingTech was founded by veterans in 2012 and built its business around portable edge compute and Cyber Fly-Away Kits — transportable systems that let cyber operators bring analysis capability to networks in the field. Parsons Corporation, a defense and infrastructure technology firm traded on the NYSE, acquired the company in 2023 and folded it into a cyber and electronic warfare portfolio that Parsons says now exceeds 20% of total company revenue.

    The JCHK program itself emerged from U.S. Cyber Command’s push to unify the defensive cyber equipment used by its Cyber Protection Teams, which had historically relied on kits built separately by each military service. SealingTech carried the program through prototyping — including a publicly announced prototype-continuation contract modification — before this full-rate production award.

    Source: SealingTech, a Parsons Corporation company, receives $750 Million Joint Cyber Hunt Kit (JCHK) Full-Rate Production Award from USCYBERCOM — PR Newswire press release announcing the five-year sole-source production agreement, August 25, 2026.

  • NAPCO Fiscal 2026 Results: Record Revenue, $103M Recurring Run Rate

    NAPCO Fiscal 2026 Results: Record Revenue, $103M Recurring Run Rate

    NAPCO Security Technologies (NASDAQ: NSSC), the Amityville, New York-based maker of intrusion and fire alarm equipment, door-locking hardware and school safety solutions, reported record results for its fiscal fourth quarter and full year ended June 30, 2026. Full-year net revenue rose 11.4% to $202.3 million, and fourth-quarter revenue climbed 10.0% to a quarterly record $55.8 million.

    Recurring service revenue — the subscription-like fees tied to NAPCO’s wireless alarm communicators — grew 13.0% for the year to $97.5 million at gross margins above 90%, and now carries a prospective annual run rate of roughly $103 million. The board raised the quarterly dividend 13.3% to $0.17 per share.

    Executive Summary

    The announcement is a clean read on demand for electronic security at a moment when physical and cyber security budgets increasingly converge: both of NAPCO’s revenue streams grew. Equipment sales rebounded 10.0% for the year to $104.8 million on strong door-locking demand and a 36% fourth-quarter jump in intrusion product sales, driven primarily by StarLink fire communicators. Recurring service revenue (RSR) reached approximately 45% of total revenue in the fourth quarter — a meaningful shift for a company historically viewed as a hardware manufacturer.

    The headline profit numbers need unpacking, however. Fourth-quarter net income surged 52.7% to a record $17.8 million, but gross margin of 61.3% included roughly 600 basis points of benefit from tariff refunds — about $0.09 of the quarter’s $0.50 in diluted earnings per share. Full-year GAAP net income actually slipped 0.9% to $43.0 million because of a $16 million litigation settlement charge taken in the third quarter. Excluding that charge, non-GAAP net income rose 32.0% to $57.3 million.

    For investors and security-industry watchers, the takeaway is that NAPCO’s recurring-revenue flywheel keeps compounding at double-digit rates while the hardware business that feeds it has returned to growth — with two one-time items, one favorable and one unfavorable, muddying the year-over-year optics in opposite directions.

    Recurring Revenue Is Now the Engine

    NAPCO’s most important number is not the record top line — it is the $97.5 million of recurring service revenue earned at gross margins above 90%. In plain terms, every StarLink cellular communicator NAPCO sells to an alarm installer keeps paying the company monthly fees for the wireless connection that carries alarm signals, long after the hardware sale closes. That model converts one-time equipment purchases into an annuity, and the July 2026 run rate of approximately $103 million suggests the annuity is still building.

    At roughly 45% of fourth-quarter revenue, RSR is approaching parity with equipment sales, and it explains why company-wide gross margin has expanded from 55.6% to 59.2% year over year even before tariff refunds. This is the same economic logic that has re-rated software and connectivity businesses across the technology sector: predictable, high-margin, contracted revenue is worth more per dollar than transactional hardware revenue. The 13.0% RSR growth rate indicates that alarm dealers keep activating new communicators faster than old accounts churn off — though the release provides no subscriber or churn figures to verify the mix of the two.

    Headline Margins Come With Asterisks

    The fourth quarter’s 61.3% gross margin is the most impressive figure in the release, and also the one that deserves the most scrutiny. NAPCO discloses that tariff refunds contributed approximately 600 basis points of that margin — meaning the underlying quarterly gross margin was closer to the mid-50s. The refunds also added about $0.09 to the quarter’s $0.50 in diluted earnings per share. These are real dollars, but refunds of previously paid tariffs are by nature backward-looking; they say little about the cost structure going forward, and the release does not address ongoing tariff exposure.

    The full year carries the opposite distortion. A $16 million litigation settlement charge, taken in the third quarter and still sitting as an accrued (unpaid) liability on the June 30 balance sheet, turned what would have been strong GAAP net income growth into a 0.9% decline. The release does not describe what the litigation concerned. NAPCO’s non-GAAP presentation, which adds the charge back, shows 32.0% net income growth — a fair representation of operating momentum, but readers should note that non-GAAP measures are company-defined and, as NAPCO itself cautions, not standardized across companies. The honest picture lies between the two: core profitability improved substantially, flattered modestly by refunds and dented once by a settlement.

    The Hardware Rebound Feeds the Subscription Base

    Equipment revenue growing 10.0% to $104.8 million matters for more than its own sake, because in NAPCO’s model hardware is the on-ramp to recurring revenue. Management called out strong demand for door-locking products and a 36% fourth-quarter increase in intrusion product sales driven primarily by StarLink fire communicators — devices that replace legacy phone-line connections for fire alarm systems with cellular links. Every such device installed typically begins generating service fees, so today’s equipment growth is a leading indicator of tomorrow’s RSR.

    The demand backdrop is favorable in ways the release references but does not quantify: commercial fire-code compliance drives non-discretionary communicator upgrades, and NAPCO positions itself as a provider of school safety solutions, a segment with sustained public funding attention. What the release does not offer is any segment-level detail on how much of the growth came from fire, locking, access control or school safety specifically, or any forward guidance on whether the fourth quarter’s 36% intrusion growth is sustainable.

    A Fortress Balance Sheet and a Bigger Dividend

    Cash and equivalents grew to $126.9 million from $83.1 million a year earlier, alongside $10.6 million in marketable securities, and full-year free cash flow rose 15.2% to $59.2 million — a 29.3% free-cash-flow margin that would be enviable for a software company, let alone a manufacturer. That cash generation comfortably funds the raised dividend of $0.17 per quarter, payable October 2, 2026 to holders of record September 11, 2026.

    The 13.3% dividend increase is a signal of management confidence, but it also raises a capital-allocation question the release leaves open: with well over $135 million in cash and securities and modest capital-expenditure needs, NAPCO has firepower for acquisitions, buybacks or accelerated product investment, and the release articulates no plan for it beyond the dividend. In a consolidating security industry, that optionality cuts both ways — dry powder is valuable, but idle cash earns questions over time.

    Background

    NAPCO Security Technologies is one of the longer-standing independent manufacturers in the electronic security industry, headquartered in Amityville, New York, and operating through four divisions: NAPCO plus wholly owned subsidiaries Alarm Lock, Continental Instruments and Marks USA. Its products span intrusion and fire alarms, wireless alarm communicators, access control and architectural door locking, sold through professional security installers into commercial, industrial, institutional, residential and government settings — including a growing focus on school safety solutions.

    The company’s strategic story over recent years has been the deliberate layering of recurring service revenue on top of its hardware business: wireless communicators that replace phone-line alarm connections generate monthly service fees at gross margins above 90%. That shift places NAPCO in the multi-billion-dollar electronic security market at the intersection of physical hardware and subscription connectivity — the same hardware-plus-recurring model reshaping much of the broader security and infrastructure sector.

    Source: NAPCO Security Technologies, Inc. Reports Fiscal Q4 and Full Year 2026 Results — company press release issued via PR Newswire on August 24, 2026, announcing financial results for the quarter and fiscal year ended June 30, 2026.

  • Exostar Powers Fujitsu’s Trusted Supply Chain Service for Japan’s Defense Sector

    Exostar Powers Fujitsu’s Trusted Supply Chain Service for Japan’s Defense Sector

    Exostar, the Herndon, Virginia-based secure-collaboration provider, announced on August 20, 2026 that it is supplying its “Exostar Managed on Microsoft 365” environment-building technology for Fujitsu Limited’s new “Fujitsu Trusted Supplychain Service,” which Fujitsu is launching in Japan for the country’s defense and critical-infrastructure sectors.

    The service will run on ISMAP-registered infrastructure in Japan — ISMAP being Japan’s government cloud-security assessment program — giving customers in-country data residency while inheriting security controls Exostar has already deployed for the U.S. Defense Industrial Base. The arrangement extends a collaboration between the two companies that began in 2019.

    Executive Summary

    The announcement is a technology-provision deal: Exostar builds and manages the secure Microsoft 365 environment inside Fujitsu’s service, while Fujitsu operates and sells the offering in Japan. The environment includes a managed enclave — a walled-off cloud workspace where sensitive files stay put rather than scattering across suppliers’ own systems — plus centralized identity and access management, multi-factor authentication, partner onboarding, information-sharing controls, and audit-ready activity logging.

    Why it matters: cybersecurity requirements for defense suppliers are converging across allied nations. The U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) program, built on the NIST SP 800-171 standard, governs contractors that handle controlled unclassified information (CUI). Japan’s Ministry of Defense and its Acquisition, Technology & Logistics Agency (ATLA) have introduced closely aligned requirements, alongside Japan’s Economic Security Promotion Act of 2022. Multinational supply chains increasingly need one trust layer that satisfies both regimes.

    For Exostar, the deal exports a platform proven in U.S. defense environments — a Microsoft GCC High enclave with FedRAMP Moderate Equivalency — into a second allied market through a local operator. For Fujitsu, it adds vetted enclave technology to a domestic compliance service without building it from scratch.

    Allied Cybersecurity Mandates Are Converging on a Common Standard

    The most significant context in this release is regulatory, not technical. NIST SP 800-171 — a U.S. catalog of security controls for protecting sensitive-but-unclassified government information on contractor systems — has become a de facto international baseline. The U.S. enforces it through CMMC; Japan’s defense ministry and ATLA have adopted closely aligned supplier requirements. When two allied procurement regimes converge on the same control set, a vendor that has already operationalized those controls at scale can sell essentially the same capability into both markets.

    That is the strategic logic here. Exostar says its platform is used by more than half of the U.S. Defense Industrial Base, including 98 of the top 100 firms — a company-provided figure, but one that, if accurate, represents exactly the kind of installed-base credibility Japanese defense suppliers facing new mandates would want to borrow rather than rebuild. For smaller suppliers especially, achieving NIST 800-171-level security independently is expensive; inheriting controls from a managed enclave is the shortcut the compliance market has been moving toward.

    The Shared-Responsibility Enclave Model, and Its Limits

    The service uses what the release calls a shared responsibility model: Exostar’s managed environment provides many of the technical controls (encryption, access management, logging), while customers remain responsible for organizational requirements — policies, training, personnel vetting, and physical security. This is an honest framing worth noting, because “compliance in a box” claims in this market often gloss over it. An enclave can dramatically reduce a supplier’s technical burden; it cannot make an organization compliant by itself.

    The economics still favor the model. Concentrating sensitive information in one controlled environment, rather than distributing it across dozens of supplier systems of varying maturity, shrinks the attack surface and the audit surface simultaneously. The trade-off is concentration risk and dependency: suppliers’ most sensitive collaboration flows through a single third-party-managed environment, which raises the stakes on that environment’s own security and availability — a question the release, understandably, does not explore.

    Data Sovereignty as a Design Requirement, Not an Afterthought

    The structure of the deal is itself instructive. Exostar did not simply extend its U.S.-hosted service to Japanese customers; its technology is integrated into a Fujitsu-operated service running on ISMAP-registered infrastructure inside Japan. Data residency — keeping data physically and legally within national borders — and in-country operation are explicit features. This reflects a broader pattern in allied technology cooperation: security capabilities cross borders, but data and operations increasingly do not.

    For the infrastructure industry, that pattern has real consequences. Every allied market that mandates in-country operation for sensitive workloads creates demand for sovereign cloud capacity, local data centers, and partnerships pairing a foreign technology provider with a domestic operator. The Exostar–Fujitsu structure — U.S. platform expertise, Japanese infrastructure and go-to-market — is a template likely to recur as other allies formalize supplier-security regimes.

    Winners, Losers, and the Competitive Field

    The clearest beneficiaries, if the service performs as described, are mid-tier Japanese defense and critical-infrastructure suppliers that face rising security requirements without the IT resources of a prime contractor. Fujitsu gains a differentiated compliance offering; Microsoft benefits indirectly, since the enclave is built on Microsoft 365. The competitive pressure falls on standalone secure-collaboration and governance/risk/compliance vendors targeting Japan, who now face an incumbent domestic integrator paired with the dominant U.S. defense-collaboration platform.

    That said, the release is a technology-provision announcement, not a results announcement. It names no customers, no adoption targets, no pricing, and no launch date beyond “launching in Japan.” The 2019-era Fort# Forum collaboration shows the relationship has history, but the market impact of this new service is, at this stage, a projection rather than a demonstrated outcome.

    Background

    Exostar was built around the U.S. defense supply chain’s need to collaborate on sensitive programs without leaking controlled information. The company says more than half of the U.S. Defense Industrial Base — including 98 of the top 100 defense firms — transacts business over its platform, and that over 25 of the top global biopharmaceutical companies also use it. Its U.S. defense offering runs in a Microsoft GCC High enclave with FedRAMP Moderate Equivalency, the assurance tier used for handling controlled unclassified information.

    The Japanese market context has shifted markedly since the companies first partnered in 2019 on Fujitsu’s Fort# Forum offering. Japan’s Economic Security Promotion Act of 2022 and new Ministry of Defense and ATLA supplier requirements — closely modeled on the U.S. NIST SP 800-171 standard — have pushed Japanese defense and critical-infrastructure suppliers toward the same kind of formalized cybersecurity compliance that CMMC now enforces in the United States.

    Source: Exostar Technology Enables Fujitsu’s Trusted Supply Chainservice for Japan’s Defense and Critical Infrastructure Sectors — Exostar press release via PR Newswire, August 20, 2026, announcing its secure Microsoft 365 technology provision for Fujitsu’s new supply-chain security service in Japan.

  • Kasm and Everfox Partner on Cross-Domain Workspace Access for Defense

    Kasm and Everfox Partner on Cross-Domain Workspace Access for Defense

    Kasm Technologies and Everfox announced a strategic technology partnership on August 20, 2026, combining Kasm Workspaces — a container-based platform that streams desktops and applications to users in disposable, policy-controlled sessions — with Everfox’s Trusted Thin Client, a purpose-built zero-trust endpoint for accessing networks at different security classification levels. The joint solution, available now, targets government, defense, and intelligence agencies that today issue multiple devices or run parallel virtual-desktop stacks to keep classified networks separated.

    Executive Summary

    The announcement pairs two specialized vendors around one problem: giving cleared personnel access to applications and desktops across multiple classification levels from a single device. In classified environments, networks at different levels (for example, unclassified versus secret) are deliberately kept apart, which historically means separate computers, separate virtual desktop infrastructure (VDI) stacks, and the cost and desk clutter that come with them. Everfox contributes the cross-domain access layer — its Trusted Thin Client bridges those separated networks on validated hardware — while Kasm contributes the workspace layer, streaming containerized desktops and applications into ephemeral sessions that are centrally managed and fully wiped when they end, so no data persists on the endpoint.

    The companies emphasize that adoption does not require a rip-and-replace: Kasm Workspaces integrates with existing hypervisors, cloud environments, and identity providers, letting agencies layer modern workspace delivery onto current infrastructure and migrate at their own pace. The announcement is a technology partnership with immediate availability, but it names no customers, contract values, or accreditation milestones — it establishes a joint offering, not demonstrated adoption.

    The Economics of Endpoint Sprawl

    The clearest business case in this release is cost consolidation. In many classified settings, working across networks means a physical computer per classification level on each desk, or a separate VDI environment per network — each with its own licensing, patching, and support burden. The release frames the joint solution as a direct replacement for these “multi-endpoint, multi-VDI-stack approaches,” collapsing them into one validated device and one workspace platform. If the technology performs as described, the savings show up not just in hardware counts but in operational overhead: fewer stacks to patch, fewer images to maintain, and central policy enforcement instead of per-device configuration.

    That said, the release quantifies none of this. There are no cost-comparison figures, seat counts, or reference deployments, so the economic argument rests on the general premise that fewer endpoints and fewer parallel stacks cost less — plausible, but unproven in this document.

    Containers as a Challenger to Legacy VDI

    The more interesting technical bet is architectural. Traditional VDI runs each user a full virtual machine, which is resource-heavy and rigid. Kasm’s model instead streams desktops and applications from containers — lightweight, fast-starting software packages — into browser-delivered sessions that exist only for the duration of use and are destroyed at termination. In security terms, ephemerality is a feature: a session that is fully wiped leaves no residual data on the endpoint, which matters enormously when the endpoint touches multiple classification levels.

    Defense environments, however, are conservative adopters for good reason. Cross-domain solutions face some of the most demanding assurance expectations in government IT, and the release does not address how the combined stack is accredited or evaluated for cross-domain use — only that Everfox’s hardware is “validated” and its solutions are “purpose-built” for high-assurance environments. Whether container isolation plus a trusted thin client satisfies each agency’s specific approval processes is the question that will actually determine adoption, and it is not answered here.

    The No-Rip-and-Replace Pitch

    Both companies clearly understand their buyer. Agencies running classified missions cannot take infrastructure offline for a wholesale migration, so the release leans hard on incrementalism: Kasm integrates with existing hypervisors, clouds, and identity providers, and agencies can “transition at a pace that does not put critical missions at risk.” Kasm’s chief product officer, Daniel Ben-Chitrit, also stresses the absence of vendor lock-in and the platform’s on-premise deployment model — both sensitive points for government buyers wary of dependency on any single supplier or on commercial cloud availability.

    Strategically, the partnership is complementary rather than overlapping: Everfox gets a modern desktop-delivery story to pair with its cross-domain plumbing, and Kasm gets a credentialed route into classified networks it could not plausibly enter alone. The risk cuts the other way too — a technology partnership without disclosed go-to-market commitments, joint contract vehicles, or named integrator support can remain a datasheet exercise. The release states the joint solution is available now, which is a stronger claim than a roadmap announcement, but availability and adoption are different things.

    Background

    Kasm Technologies builds an open-core platform for streaming containerized desktops, browsers, and applications to users through the web browser — a container-based alternative to virtual desktop infrastructure (VDI), the long-standing enterprise approach of hosting each user’s desktop as a virtual machine in a data center. Everfox operates in the cross-domain solutions market, supplying trusted access and secure data transfer between networks at different classification levels for government, defense, and intelligence customers, where high-assurance requirements have historically favored purpose-built hardware and specialized vendors.

    The partnership lands amid a broader government push to modernize classified-environment IT, where the default pattern of one endpoint per network has become an acknowledged cost and usability burden. It also extends a run of alliance announcements from Kasm, which recently shipped Kubernetes support in Workspaces 1.19 and a stealth-networking integration with Dispersive, suggesting a deliberate strategy of pairing its workspace layer with specialized security partners rather than building those capabilities alone.

    Source: Kasm Technologies and Everfox Announce Strategic Partnership to Deliver Secure Cross Domain Workspace Access for Government and Defense — PR Newswire press release, August 20, 2026, announcing the joint containerized cross-domain workspace solution.

  • Corero Adds AI Cloud-Assist to SmartWall ONE as DDoS Attacks Go Automated

    Corero Adds AI Cloud-Assist to SmartWall ONE as DDoS Attacks Go Automated

    Corero Network Security (AIM: CNS; OTCQX: DDOSF), the London-headquartered DDoS protection specialist, announced AI-Augmented Cloud-Assist for its SmartWall ONE platform on August 20, 2026. The new capability layers cloud-delivered AI analysis, threat intelligence, and policy optimization on top of Corero’s existing on-premises, edge-based DDoS mitigation.

    The system analyzes attack telemetry in Corero’s cloud, recommends new protection policies that can be applied manually or automatically in seconds, and keeps Corero’s security experts in an oversight role. It targets AI data centers, NeoCloud providers, service providers, and digital enterprises.

    Executive Summary

    The announcement is Corero’s answer to a problem the whole DDoS defense industry is wrestling with: attackers are using AI to develop and evolve attack campaigns faster than human security teams can write countermeasures. Corero’s proposed remedy is a continuous intelligence loop — on-premises SmartWall ONE appliances at the network edge feed attack telemetry and forensic data to Corero’s cloud, where AI identifies emerging attack behaviors and generates recommended protection policies, which flow back to the edge devices with human experts supervising the loop.

    Why it matters: a distributed denial of service (DDoS) attack floods a network or service with junk traffic until legitimate users cannot get through, and mitigation speed is measured in seconds, not hours. If cloud-scale AI can genuinely shorten the gap between a novel attack pattern appearing and an effective policy being deployed, that is a meaningful operational improvement — particularly for AI data centers and cloud GPU providers (so-called NeoClouds) whose expensive workloads make downtime costly. The release, however, offers no benchmarks, pricing, availability dates, or named customers, so the launch is best read as a directional architecture statement rather than a proven result.

    Fighting Automation With Automation

    The premise of the launch is an arms-race argument: as attackers use AI to mutate DDoS campaigns mid-attack, defenses that depend on humans hand-tuning mitigation policies fall behind. Corero frames AI Cloud-Assist as restoring symmetry — machine-generated attacks met with machine-generated countermeasures, applied “in seconds.” That framing is consistent with where the broader security industry is heading, and the underlying logic is sound: policy generation is the slow, human-bottlenecked step in DDoS response, so it is the rational place to apply AI.

    What the release does not provide is evidence of the improvement. There are no response-time figures, detection-accuracy comparisons, or before-and-after case studies. “Reduce response times, improve protection accuracy, and strengthen operational efficiency” are the intended outcomes, not measured ones. Buyers evaluating the claim will need to ask for data the release does not contain.

    The Hybrid Architecture: Cloud Brains, Edge Muscle, Human Oversight

    The design choice worth noting is what Corero did not do: it did not move mitigation to the cloud. Traffic scrubbing stays on the on-premises SmartWall ONE appliances at the network edge — close to the applications and AI workloads being protected — which preserves low latency, while the computationally heavy analysis moves to the cloud where scale is cheap. This is a sensible division of labor, and it plays to Corero’s installed base: the AI works from SmartWall ONE’s existing telemetry and forensic data rather than requiring a new sensor footprint.

    Equally deliberate is keeping humans in the loop. Recommendations can be applied automatically or manually, with Corero’s security experts providing oversight. That addresses the real operational fear about AI-driven security — a false positive that auto-deploys a policy blocking legitimate customer traffic is itself a denial of service. The trade-off is that human oversight reintroduces some of the latency the automation was meant to eliminate; how customers tune that dial will determine how much of the promised speed they actually realize.

    Reading the Target Market: AI Data Centers and NeoClouds

    Corero names its target buyers explicitly: AI data centers, NeoCloud providers (the newer class of specialized GPU cloud operators), service providers, and digital enterprises. That ordering tells a market story. AI infrastructure operators run revenue-dense, latency-sensitive workloads and are attractive DDoS targets precisely because their downtime is expensive and visible. Positioning a DDoS product launch around them signals where Corero sees growth — and follows its recent momentum with infrastructure operators, including the deal in which its technology powers TierPoint’s Adapt DDoS protection service.

    Competitively, Corero claims the capability “is largely missing in most DDoS solutions.” That is a contestable assertion in a market where large cloud-delivered DDoS providers also advertise machine learning and automated mitigation. Corero’s genuine differentiation argument is narrower and more defensible: combining cloud AI with on-premises edge mitigation and the forensic-grade telemetry its appliances already collect. The release asserts the broader claim without a competitive comparison, so readers should treat the “largely missing elsewhere” framing as positioning rather than established fact.

    What Is Substantiated — and What Is Not

    Substantiated by the release: the product exists as an announced extension of SmartWall ONE; it uses cloud-based AI analysis of attack telemetry; recommendations can be applied manually or automatically; human experts oversee the loop; and it targets edge mitigation for AI-era infrastructure. Unsubstantiated as yet: any quantified performance gain, the nature of the AI models involved, general availability timing, pricing, and customer adoption. None of this is unusual for a product launch release, but the gap between the confident claim that “this is the future of DDoS protection” and the absence of measurable evidence is exactly the space a prospective buyer’s proof-of-concept should fill.

    Background

    Corero Network Security has spent years as a pure-play DDoS specialist, selling automatic detection and mitigation for complex edge and subscriber environments — the kind of always-on, real-time protection that internet service providers and hosting operators embed in their networks. The company is dual-listed on London’s AIM market and the US OTCQX, with operational centers in Massachusetts and Edinburgh.

    The launch continues a run of activity for the company: Corero was recently recognized as a leader and innovator in the 2026 DDoS SPARK Matrix vendor assessment, and its technology powers TierPoint’s new Adapt DDoS protection service — evidence of its strategy of reaching enterprises through infrastructure and service-provider partners. AI Cloud-Assist extends that installed edge footprint with a cloud intelligence layer rather than replacing it.

    Source: Corero Network Security Launches AI-Augmented Cloud-Assist for SmartWall ONE™ — PR Newswire release, August 20, 2026, announcing cloud-delivered AI analysis and policy optimization for Corero’s edge-based DDoS protection platform.

  • Password Spraying Surges 155x as Attackers Slip Through MFA Gaps

    Password Spraying Surges 155x as Attackers Slip Through MFA Gaps

    Security firm Huntress reported a 155x increase in password spraying attacks in the first half of 2026, driven largely by a campaign targeting Microsoft’s Azure CLI that generated more than 81 million login attempts and 78 account compromises in a single two-week window in mid-June. The traffic originated from an IPv6 range operated by hosting provider LSHIY LLC under a bring-your-own-IP arrangement.

    The striking finding: most compromised organizations had multi-factor authentication (MFA) deployed. Attackers succeeded anyway by abusing Resource Owner Password Credentials (ROPC), a legacy OAuth login flow that bypasses MFA prompts entirely.

    Executive Summary

    Password spraying — trying one common password against many accounts, slowly enough to dodge lockout rules — is one of the oldest tricks in the attacker playbook. What Huntress documented in H1 2026 is that trick industrialized: a 155-fold volume increase, with a single campaign against Azure command-line logins producing 81 million attempts in two weeks. The attackers sharpened the technique by recycling valid username-and-password pairs from old breaches that were never rotated, making each attempt far more likely to land than a blind guess.

    The deeper story is not password hygiene but policy scoping. Of 23 affected businesses Huntress analyzed, eight had no MFA at all — but the other 15 did, and were breached anyway because their Conditional Access policies (Microsoft’s rules engine for when to demand MFA) excluded the specific sign-in path the attackers used. The abused path, ROPC, is a deprecated OAuth grant that sends the username and password straight to the token endpoint with no interactive prompt where an MFA challenge could occur.

    For any organization running Microsoft Entra ID — and for the infrastructure providers hosting them — the takeaway is blunt: MFA that is deployed but incompletely scoped provides the feeling of protection without the fact of it.

    MFA You Bought Isn’t MFA You’re Getting

    The most commercially significant number in the Huntress data is not the 155x surge — it is that 15 of 23 breached organizations had MFA deployed and it simply did not apply to the attack. Their Conditional Access policies were limited to certain applications or user groups, trusted ‘safe’ network locations, or sat in report-only mode, a testing setting that logs violations without blocking them. Each of those is a reasonable-sounding operational compromise, usually made to avoid locking out legitimate users or breaking a line-of-business app.

    This reframes the identity-security market. The gap is no longer ‘do you have MFA?’ — adoption is widespread — but ‘can you prove every authentication path enforces it?’ That favors vendors and managed service providers selling policy auditing, attack-path validation, and identity posture management over those selling MFA seats. It also shifts liability conversations: an organization that attests to having MFA for cyber-insurance purposes, while ROPC sits unprotected, may find that attestation contested after a breach.

    ROPC: The Legacy Door That Skips the Guard

    Resource Owner Password Credentials is an OAuth grant designed years ago as a migration bridge: it lets an application collect a username and password directly and exchange them for an access token, with no interactive login screen. No login screen means no place to insert an MFA prompt. The grant is deprecated in OAuth 2.1, yet it remains available in many Microsoft Entra tenants — often because some old script or application still depends on it, and nobody wants to be the person who breaks it.

    That is the economics of legacy authentication in miniature. The cost of leaving ROPC enabled is invisible until an incident; the cost of disabling it is an immediate, attributable helpdesk headache. Attackers systematically arbitrage that asymmetry. As Huntress’s Andrew Brandt put it, ROPC is technically ‘an impersonation method’ — a reused password that still works becomes an active session, no second factor required.

    BYOIP and IPv6 Turn Blocking Into Whack-a-Mole

    The campaign’s infrastructure choices matter as much as its authentication trick, and they land squarely on the hosting industry. The attackers used a bring-your-own-IP (BYOIP) service — a legitimate offering that lets a hosting customer route traffic through a provider using address space the customer owns. When LSHIY terminated the activity, the spraying resurfaced from FranTech-hosted IPv6 ranges, then from 3xK Tech on IPv4. Combine provider-hopping with IPv6’s effectively unlimited address pool and IP-based blocklists become a losing game: defenders block a range, attackers announce a new one.

    For hosting and connectivity providers, this is a growing abuse-desk and reputation problem. BYOIP customers bring their own address space and, with it, their own history — providers that vet BYOIP onboarding lightly are effectively renting their network’s reputation to whoever shows up. Expect pressure, commercial if not regulatory, for stronger BYOIP due diligence and faster abuse response as these campaigns keep routing through legitimate infrastructure.

    81 Million Attempts, Zero Follow-Through — and Why That’s Ominous

    Huntress observed no post-compromise activity after the successful logins — no lateral movement, no data theft. Their assessment is that the operators were likely validating credentials for resale on dark-web markets. That points to a maturing supply chain: one group industrializes the guessing, verifies which credentials actually work, and sells confirmed access to others who specialize in monetization through business email compromise or ransomware.

    The practical consequence for defenders is counterintuitive, and Huntress states it directly: do not prioritize response by spray volume. The most heavily sprayed tenants were often the least compromised. The right triage signal is credential validity — whether any attempt actually succeeded — not how much noise the attacker made. A quiet, successful login against a stale account is worth more attention than a million failures.

    Background

    Password spraying has been a staple of credential attacks for over a decade precisely because it exploits policy, not software: lockout rules watch for many failures on one account, while spraying spreads failures thinly across many. Its effectiveness has been amplified by the steady accumulation of breach dumps — billions of real username-and-password pairs that attackers replay against organizations where rotation never happened. Meanwhile, the industry’s answer, multi-factor authentication, has gone from rarity to near-mandate, pushed by cyber insurers and frameworks alike.

    The unresolved seam between those two trends is legacy authentication. Protocols and grants that predate MFA — ROPC among them — persist inside cloud identity platforms like Microsoft Entra ID for backward compatibility, and each one is a path where a password alone still suffices. Campaigns like the one Huntress documented are best understood as the market discovering, at industrial scale, exactly where those seams are.

    Source: Password spraying attacks surge 155x as hackers exploit MFA gaps — a BleepingComputer article, sponsored and written by Huntress Labs, detailing the H1 2026 password-spraying surge and the LSHIY campaign against Azure CLI logins.

  • AI-Assisted Defense Hardens Satellite Communications After 2022 Russian Hack

    AI-Assisted Defense Hardens Satellite Communications After 2022 Russian Hack

    An AI-assisted cybersecurity tool has been credited with helping secure a satellite communication system in the aftermath of the 2022 Russian hacking campaign, according to a report from the Associated Press. The 2022 incident — the most consequential known cyberattack on commercial satellite communications to date — struck at the opening of Russia’s full-scale invasion of Ukraine and disrupted connectivity for users across Europe.

    The report positions the tool as a working example of artificial intelligence applied to defending space-based connectivity infrastructure, an area regulators and militaries have flagged as critically exposed since that attack.

    Executive Summary

    The announcement, carried by AP, describes an AI-assisted tool that helped secure a satellite communication system following the 2022 Russian hack — widely understood to reference the attack on Viasat’s KA-SAT network on the day Russia invaded Ukraine. That attack used wiper malware to disable tens of thousands of satellite modems, cutting off Ukrainian users and collateral customers across Europe, including remote monitoring for thousands of German wind turbines.

    Why it matters: satellite links carry traffic that terrestrial fiber cannot reach — rural broadband, maritime and aviation connectivity, military communications, and backup paths for critical infrastructure. The 2022 attack proved a nation-state could take a commercial satellite network’s user base offline in hours. Evidence that AI-assisted tooling has since been used to harden such a system marks a shift in defensive AI from lab pilots and vendor demos to operational deployment on infrastructure that has already been targeted in wartime.

    For infrastructure operators, the signal is that AI-augmented defense is becoming table stakes for any network — space-based or terrestrial — that adversaries consider a strategic target.

    From Pilot to Proven: Defensive AI Grows Up

    For years, ‘AI in cybersecurity’ mostly meant anomaly-detection features bolted onto marketing decks. What makes this report notable is the context: the tool is credited with helping secure a system that suffered one of the most damaging real-world attacks on record, not a simulated range exercise. Securing a post-breach environment is the hardest test in the discipline — the adversary has demonstrated capability and intent, and defenders must assume they will return.

    AI’s genuine advantage in this setting is scale and speed of pattern analysis. Satellite ground networks generate enormous telemetry streams from modems, gateways, and management servers. Human analysts cannot review that volume; machine-learning systems can flag deviations — an unusual firmware push, an unexpected management-plane login path — fast enough to matter. That is precisely the vector the 2022 attackers exploited, reaching modems through a compromised management network.

    The Ground Segment Is the Soft Underbelly of Space

    A persistent misconception is that hacking a satellite network means attacking the spacecraft. The 2022 incident showed otherwise: the attackers never touched the satellite. They compromised the terrestrial management infrastructure — the ‘ground segment’ — and used it to push destructive commands to customer modems. Wiper malware, which destroys a device’s software rather than stealing data, rendered the modems inoperable.

    That architecture lesson generalizes across all infrastructure: the management plane is the crown jewel. Data centers, carrier networks, and cloud platforms share the same exposure — whoever controls the orchestration layer controls everything downstream. AI-assisted monitoring of that layer, rather than only the customer-facing edge, is where defensive investment is now flowing.

    Market Stakes: Space Cybersecurity Becomes a Line Item

    The commercial satellite connectivity market has expanded rapidly since 2022, driven by low-Earth-orbit constellations, in-flight and maritime connectivity, and government demand for resilient communications. Every new terminal is an endpoint an adversary can target. Insurers, defense customers, and regulators have all raised security expectations for satellite operators since the 2022 attack, and demonstrated AI-assisted hardening gives operators something concrete to point to in procurement and compliance conversations.

    Winners in this shift are operators who can prove security posture, and vendors selling AI-driven monitoring for operational-technology environments. Under pressure are smaller operators and legacy VSAT (very-small-aperture terminal) networks running aging ground infrastructure that predates modern security assumptions — retrofitting is expensive, and the talent to do it is scarce.

    The Limits: AI Defends, But Humans Still Own the Outcome

    Caution is warranted. AI-assisted defense narrows the detection gap but does not eliminate the fundamentals: patching, segmentation of management networks, and credential hygiene — the exact weaknesses exploited in 2022. AI models also introduce their own attack surface, from data-poisoning risks to false-positive floods that exhaust analysts. And adversaries use AI too, accelerating vulnerability discovery and phishing at the same pace defenders accelerate detection.

    The realistic read is that AI has become a force multiplier for well-run security programs, not a substitute for them. The systems most likely to benefit are those where operators pair AI tooling with disciplined architecture — which, based on this report, appears to be the path taken here.

    Background

    Commercial satellite communications became a wartime target on the first day of Russia’s 2022 invasion of Ukraine, when the KA-SAT broadband network operated by Viasat was hit with wiper malware delivered through its ground-based management systems. The attack disabled tens of thousands of modems, disrupted Ukrainian communications at a critical moment, and caused collateral outages across Europe. Western governments formally attributed it to Russia, and the incident became the canonical case study in space-infrastructure cybersecurity.

    Since then, satellite connectivity has grown strategically and commercially — low-Earth-orbit constellations, aviation and maritime services, and military resilience programs have multiplied the number of networked terminals in orbit and on the ground. That growth has drawn sustained investment into securing the ground segment, where artificial intelligence is increasingly applied to detect intrusions and harden systems at a scale human teams cannot match.

    Source: AI-assisted tool helped secure satellite communication system after 2022 Russian hacking — Associated Press report on defensive AI deployed to harden satellite communications infrastructure targeted in the 2022 Russian cyberattack.