IT Risk Management Strategies: Key Metrics & Trends
Cyberattacks and data breaches have ranked as the number one global business concern for three consecutive years, according to Aon’s 2025 Global Risk Management Survey. The organizations still managing risk reactively are paying a measurable price. Hyperproof’s 2026 IT Risk and Compliance Benchmark Report found that 50% of those organizations suffered a breach in 2025. Among organizations with integrated, automated programs, the breach rate dropped to 27%. That 23-point gap reflects a strategic difference in program design: how often risk is assessed,…
Internet-Exposed OT: What the UK Generator Incident Tells CNI Operators About Attack Surface
Key Takeaways A small UK power generator was reportedly forced offline for four days in July 2026. Press reporting attributes the incident to Iran-linked actors, but the UK government has confirmed only that an incident occurred, declining to attribute it or identify the facility. The initial access vector has not been disclosed. Operators cannot map the incident to a specific product or vulnerability, and any vendor claiming otherwise is speculating. CISA’s Internet Exposure Reduction Guidance, revised on 21 August 2026, sets out four steps for identifying and removing unnecessary internet…
Worse Than First Reported: What CISA’s Revised Water Sector Numbers Mean for Every Utility
Key Takeaways CISA has confirmed that the July 2026 campaign against US water utilities targeted more than 100 internet-exposed systems across at least 12 states — over three times the roughly 30 Minnesota systems disclosed when the story first broke [2][4]. Georgia, Michigan, South Dakota and New Jersey have since confirmed their own incidents, including a precautionary boil-water advisory at a Georgia utility that was lifted after testing showed no water quality impact[5]. A second, separate joint advisory (AA26-231A), published August 19, describes threat actors using AI-generated…
The DRM Flag That Isn’t DRM
SetWindowDisplayAffinity makes a window disappear from screenshots, screen shares, and Recall snapshots. Vendors sell that as “screenshot protection,” and procurement checklists tick it off as data-exfiltration risk mitigated. Microsoft’s own documentation for the API says otherwise. This post breaks down what the flag actually guarantees, who can route around it and how, and why a black screenshot is the beginning of a threat model rather than the end of one. The Pitch, and the Problem with It Open a modern secure-messaging app, password manager, or exam browser on Windows 11,…
Signal Windows Desktop: contentProtection Bypass
Signal Desktop on Windows ships a screen-capture protection feature that prevents the application window from appearing in screenshots or screen recordings. In this post, we walk through how we identified the underlying Windows API powering that feature, why naïve attempts to disable it fail even from a privileged process, and how we ultimately bypassed the protection by executing code within Signal’s own process context using CreateRemoteThread. In this post we cover two distinct phases of the research: Static analysis — locating the contentProtection API chain through…
Key Takeaways from the 2026 OCP APAC Summit
IOActive recently attended the 2026 OCP APAC Summit in Taipei. Below are our key takeaways from two days with the Open Compute community, along with a short recap video from the show floor at the end of this post. Key Takeaways The 2026 OCP APAC Summit (August 11–12) drew hyperscalers, semiconductor companies, device manufacturers, and infrastructure providers under the theme “Leading the Future of AI.” AI security conversations extended beyond compute performance to the full stack: networking, cooling, storage, power, firmware, and the security controls underneath all of it. Openness…
The Five Eyes AI Shift in Cyber Risk Statement: What Industry Leaders Need to Know Now
Key Takeaways On 22 June 2026, the leaders of the Five Eyes cyber security agencies issued a joint statement, The AI Shift in Cyber Risk: Why Leaders Must Act Now, warning that frontier AI is transforming cyber risk on a timeline measured in months, not years. The statement is signed by the heads of the National Cyber Security Centre (NCSC, UK), Cybersecurity and Infrastructure Security Agency (CISA, US), National Security Agency (NSA, US), Australian Signals Directorate (ASD, Australia), Communications Security Establishment (CSE, Canada), and Government Communications Security Bureau (GCSB, New…
Red Team vs Penetration Testing: Key Differences
“Penetration testing identifies vulnerabilities. Red teaming evaluates how effectively an organization can detect and respond to realistic attacks.” IOActive Security Team The decision between red team vs penetration testing comes down to one question: What are you trying to learn? Most mature security programs need both methodologies, deployed in sequence: penetration testing to close technical gaps, and red teaming to validate that the controls protecting what remains will hold under real adversarial pressure. This article breaks down the differences between red team…
When the Advisory Arrives First: Minnesota’s Water Utilities and the Limits of Warning
Key Takeaways More than 30 Minnesota community water systems were targeted across July 26 and 27, 2026 in what Minnesota IT Services (MNIT) has characterized as a coordinated cyberattack. Automated control functions were affected at several utilities, and the City of Braham briefly took its water treatment plant offline [4][6][9]. No attribution has been made. Officials have not named a threat actor, identified an exploited vulnerability, confirmed which products were affected, or established whether data was taken [4][7]. The incidents followed four days after the…
Security Challenges in AI Adoption: 2026
As enterprise AI adoption accelerates in 2026, organizations are discovering that deploying AI responsibly requires a fundamentally different security approach. AI is now embedded in development pipelines, customer-facing applications, operational workflows, and automated decision-making systems. Each deployment extends the attack surface in ways that existing security controls were not built to detect or contain. This article breaks down the most significant security challenges in AI adoption for Global 1000 enterprises, supported by current research and IOActive’s adversarial testing experience. Attackers are exploiting the risks documented here…
