Connect with us

Technology

OpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europe

Published

on

Four new members and significant CRA resources released by the Foundation as systemic collaboration on open source security gains momentum

PRAGUE, Oct. 6, 2026 /PRNewswire/ — The Open Source Security Foundation (OpenSSF), a cross-industry initiative of the Linux Foundation focused on sustainably securing open source software, today announced new membership growth, welcoming A-Team Systems, Emphere, DACHS IT GMBH, and JetBrains to the foundation. The OpenSSF also notes new and renewed efforts to deepen Cyber Resilience Act (CRA) preparedness, in both the EU and beyond, releasing guides, user journeys, and a case study.

“Securing the open source ecosystem requires proactive, systemic collaboration across the entire industry.”

Regulatory pressure grows for companies selling products to the EU, as the mandatory vulnerability and incident reporting aspect of the CRA came into effect last month. Clear, direct, and easy-to-understand guidance on this global legislation is critical, especially with AI significantly hastening vulnerability discovery and reporting. With bugs easier to find and reporting windows shrinking, OpenSSF continues to serve as a trusted, neutral hub for CRA education, collaboration, and security. 

“Securing the open source ecosystem is no longer just about patching isolated vulnerabilities. It requires proactive, systemic collaboration across the entire industry,” said Steve Fernandez, General Manager of OpenSSF. “Initiatives like the Open Secure AI Alliance and pioneering projects such as Akrites reflect this critical shift. We are moving beyond fragmented defenses and building a unified front, equipping the global developer community with the comprehensive frameworks needed to secure the next generation of software. OpenSSF and our members are a key element in this shift.”

New OpenSSF members include A-Team Systems, Emphere, DACHS IT GMBH, and JetBrains who join the Foundation as General Members. These organizations join a community of working groups, technical groups, and experts that are shaping the future of OpenSSF and software security. Their membership has a direct impact on the long term sustainability of open source and the projects that are critical to modern infrastructure.

Q3 Foundation Achievements
In addition to membership growth in the third quarter of 2026, OpenSSF achieved the following milestones:

Publication of the CRA Readiness practitioner’s guide — OpenSSF published practical compliance guidance for the EU Cyber Resilience Act. With CRA obligations now legally live, this guide converts policy analysis into actionable steps for maintainers and vendors who must comply. OpenSSF also released a CRA Readiness User Journey to support greater preparedness around the important regulation, regardless of where an organization is starting.CRA case study: 1,400 upstream fixes from Ericsson — Ericsson Software Technology eliminated private forks and contributed over 1,400 dependency updates and security fixes upstream to meet CRA obligations, guided by OpenSSF principles. This case study is concrete proof that “fix it upstream, not in a fork” scales at enterprise level — behavior that fosters a more secure software supply chain.User Journeys for role-based security — OpenSSF rolled out role-based “User Journeys,” for security practitioners looking to find the right guidance and resources. These curated navigation paths for developers, security engineers, OSPO leaders, marketers, and executives ensure that the right information makes it into the hands of those that seek it out.OpenBao v2.6 release — A new version of the open source secrets management tool shipped with per-namespace sealing and a new workflow engine for cross-plugin communication.BOMHort joined OpenSSF Sandbox — A new Kubernetes-native SBOM visualization and governance tool entered the OpenSSF Sandbox. As SBOMs shift from best practice to regulatory requirement (CRA, NIST SSDF, EO 14028), tooling that helps teams actually manage and query SBOMs at scale, not just generate them, fills an important security gap.

Supporting Quotes

“Open source software has been central to our work supporting Linux and FreeBSD systems in critical production environments for more than two decades. We depend on the security work happening throughout the open source ecosystem. OpenSSF provides part of the foundation that makes secure, reliable production operations possible. Joining OpenSSF reflects our commitment to materially supporting the people who make open source what it is today. We look forward to contributing an infrastructure operations perspective and supporting the important work OpenSSF is doing across the open source community.”
– Adam Strohl, President, A-Team Systems

“Virtually every critical enterprise builds on an open source foundation. When everyone relies on the digital common ground, maintaining its safety is a shared responsibility. Securing the supply chain helps ensure that open-source software remains safe, trusted, and open for everyone. Through our continuous work in the Linux Foundation and CNCF, we’ve helped build cloud-native ecosystems. Now, through OpenSSF, we’re expanding our work to help protect and nurture the security foundation they rely on.”
– Alexander Schaber, Founder and CEO, DACHS IT GMBH

“Open source is shared code, and so is the responsibility to secure it. Emphere is glad to join OpenSSF to help the community outpatch attackers, human and AI alike.”
– Ankit Kumar, CEO, Emphere

“Software development is at an inflection point. AI is changing how software is built and creating new security challenges, making it more important than ever that developers can understand, verify and trust the software they produce. JetBrains has supported professional software development for more than two decades, and we believe staying ahead of these challenges is best done collaboratively and in the open. OpenSSF brings together some of the strongest expertise in the industry, and we are glad to join the community and help shape the future of secure software development.”
– Katherine Druckman, Head of Community and Partnership Engagement, JetBrains

Events and Gatherings
OpenSSF members are gathering this week in Prague at OpenSSF Community Day Europe and hosting the Workshop: Operationalizing the Cyber Resilience Act on Friday, October 9. To get involved with the OpenSSF community, join us at the following upcoming events: AGNTCon + MCPCon North America (San Jose, California; October 22-23) and Open Source SecurityCon North America (Salt Lake City, Utah; November 9).

Additional Resources

View the complete list of OpenSSF membersContribute efforts to one or more of the active OpenSSF working groups and projectsSign up for the OpenSSF newsletter to receive updates on upcoming events, resources, and community news.

About the OpenSSF
The Open Source Security Foundation (OpenSSF) is a cross-industry organization at the Linux Foundation that brings together the industry’s most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaboration and working both upstream and with existing communities to advance open source security for all. For more information, please visit us at openssf.org.

About the Linux Foundation
The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects, including Linux, Kubernetes, Model Context Protocol (MCP), OpenChain, OpenSearch, OpenSSF, OpenStack, PyTorch, Ray, RISC-V, SPDX and Zephyr, provide the foundation for global infrastructure. The Linux Foundation is focused on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see its trademark usage page: www.linuxfoundation.org/trademark-usage. Linux is a registered trademark of Linus Torvalds.

Media Contact
Grace Lucier
The Linux Foundation
pr@linuxfoundation.org 

View original content to download multimedia:https://www.prnewswire.com/news-releases/openssf-shares-expanded-membership-and-new-global-policy-resources-during-community-day-europe-302898933.html

SOURCE OpenSSF

Continue Reading

Technology

CreditNirvana Launches India’s First Integrated AI Suite for Voice Co-Browsing and Agentic Debt Collections Orchestration

Published

on

By

CognifAI Assist guides customers in the digital lending and servicing process through voice and visual co-browsing, while ORCA uses 200+ AI agents to orchestrate account-level collections.60-70% of collection journeys completed autonomously without human intervention, driven by outcome-based models.

BENGALURU, India, Oct. 6, 2026 /PRNewswire/ — CreditNirvana, a Perfios company focused on agentic AI-driven debt management, today introduced ORCA and CognifAI Assist, an integrated AI suite that helps lenders collect at 40% lower cost with a 30% higher connect rate, and complete 60-70% of collection journeys autonomously without any human intervention.

As digital lending continues to accelerate, financial institutions face a persistent dual challenge of steep customer drop-off rates during complex onboarding processes like re-KYC and loan origination, paired with escalating debt collection costs caused by rigid, repetitive outreach strategies. Overcoming these hurdles has historically required costly, time-consuming core infrastructure overhauls that slow down innovation and strain operational margins.

CreditNirvana resolves this through a non-intrusive agentic AI layer that can be easily deployed over existing banking portals, mobile applications, and third-party systems without requiring core-system overhauls. CognifAI and ORCA function as AI solutions within CreditNirvana’s broader agentic portfolio, operating with its flagship debt collection platform, Maestro, to deliver targeted automation across distinct stages of the credit lifecycle.

Unlike conventional collections platforms that rely on predefined sequences of calls, messages and follow-ups, ORCA uses an agentic, contextualised and closed-loop approach to decide the next best action for each account, execute it, observe outcomes and adapt subsequent strategies.

Powered by more than 200 specialised AI agents, ORCA coordinates collections across digital, voice, calling, field and legal touchpoints. Lenders define recovery objectives and constraints, while ORCA determines account-level strategies within lender-defined compliance guardrails and with human-in-the-loop control.

Vinay Sathyanarayan, CEO of CreditNirvana, said, “The future of lending lies in making every customer interaction more contextual, efficient and seamless. With CognifAI and ORCA, we are extending the agentic AI layer across the lending lifecycle, from helping customers navigate digital journeys to enabling lenders to make more informed, account-level collections decisions leading to better collection strategy. Our focus is on combining measurable business outcomes with responsible AI deployment, customer experience and compliance guardrails.”

ORCA’s measurement framework incorporates baselines, controls and outcome attribution. Its four interconnected layers – Signals, Decision, Execution and Measurement, continuously assess borrower behaviour, delinquency, promise-keeping and channel response, real time financial data to strategize collections decisions.

Complementing ORCA, CognifAI combines an AI voice assistant capable of conversing across multiple Indian regional languages as well as global languages including Spanish, Mandarin, Arabic, and Bahasa, with secure visual co-browsing to guide customers screen-by-screen through digital lending, origination, and servicing journeys. Operating as an overlay requiring no app downloads, it highlights fields, pre-fills data, and supports in-session rate and tenure negotiations within approved guardrails. To protect sensitive customer information, CognifAI incorporates end-to-end encryption and field-level data masking for PAN, OTP, and account data, enabling lenders to achieve 30% higher journey completion and 35% lower handling time.

Together, CognifAI and ORCA extend AI-led assistance and automation across customer acquisition, onboarding, servicing and collections. Built on CreditNirvana’s enterprise-grade architecture, the platform currently orchestrates over $30 billion in Assets Under Management (AUM) across 100+ million loan accounts.

By unifying real-time voice guidance with autonomous collections intelligence, CreditNirvana is setting a new operational benchmark for digital financial services. As lenders navigate evolving regulatory standards and rising customer expectations, this enterprise-grade AI suite provides a scalable, compliant foundation for institutions seeking to maximize lifetime customer value, reduce operational friction, and drive sustainable credit growth.

About CreditNirvana

CreditNirvana, a Perfios company, provides AI-driven solutions across the lending lifecycle, helping financial institutions enhance collections, improve operational efficiency and deliver more contextual borrower experiences. Its technology combines AI-led decisioning, automation and analytics to support financial institutions in managing lending and collections workflows. CreditNirvana platform currently touches over $30 billion in Assets Under Management (AUM) across 100+ million loan accounts. For more information, visit creditnirvana.ai.

 

View original content to download multimedia:https://www.prnewswire.com/in/news-releases/creditnirvana-launches-indias-first-integrated-ai-suite-for-voice-co-browsing-and-agentic-debt-collections-orchestration-302899564.html

Continue Reading

Technology

Techman Robot strengthens cybersecurity for trusted Physical AI deployment

Published

on

By

Techman Robot becomes the world’s first built-in vision AI cobot manufacturer to obtain IEC 62443-4-2 SL2 certification

TAIPEI, Oct. 6, 2026 /PRNewswire/ — Techman Robot has obtained IEC 62443-4-2 Security Level 2 (SL2) cybersecurity certification for its TM AI Cobot S Series following an independent assessment by DEKRA. The milestone strengthens the cybersecurity foundation for deploying collaborative robots in connected manufacturing environments.

As Physical AI moves into production, robots increasingly connect with equipment, manufacturing systems and data infrastructure. Manufacturers need both intelligent automation and confidence in the cybersecurity capabilities of the products they deploy.

Techman Robot integrates built-in vision, artificial intelligence and robotic execution through its SEE • THINK • ACT approach. Independently verified cybersecurity capabilities provide a foundation for trusted deployment.

IEC 62443-4-2 specifies security requirements for industrial automation and control system components. The certification gives manufacturers and system integrators an independently verified reference for assessing the product cybersecurity capabilities of the TM AI Cobot S Series.

Scott Huang, Chief Operating Officer of Techman Robot, said:

“As Physical AI enters production, customers care about more than how intelligent a robot is. They need to know whether it can operate safely and reliably alongside their manufacturing environment over the long term. SEE • THINK • ACT is central to Techman Robot’s AI robotics approach, and trusted deployment is a foundation for putting that intelligence to work on the factory floor. The IEC 62443-4-2 SL2 certification reflects our continued efforts to integrate intelligence, cybersecurity and practical manufacturing needs into product development.”

Beyond certification, TM AI Cobot has established product lifecycle cybersecurity mechanisms covering vulnerability management, incident reporting and security updates. Techman Robot continues to strengthen these mechanisms in line with the requirements of the European Union’s Cyber Resilience Act (CRA).

From built-in vision to built-in AI, Techman Robot remains focused on bringing intelligence into real manufacturing environments with a trusted foundation for deployment.

View original content to download multimedia:https://www.prnewswire.co.uk/news-releases/techman-robot-strengthens-cybersecurity-for-trusted-physical-ai-deployment-302899568.html

Continue Reading

Technology

Ontinue Expands External Threat Visibility with ION for Dark Web Monitoring

Published

on

By

New Add-On Service Extends ION MXDR Beyond the Enterprise Perimeter to Identify Exposed Credentials, Brand Impersonation, and Emerging Risks Before They Become Security Incidents

ZURICH, Switzerland, Oct. 6, 2026 /PRNewswire/ — Ontinue, a leading MXDR partner providing nonstop managed security operations through its Agentic SOC, today announced the launch of ION for Dark Web Monitoring (DWM), a new managed add-on service that extends ION MXDR to continuously identify exposed credentials, detect brand impersonation attempts, and uncover emerging external threats before attackers can exploit them.

Compromised credentials are traded across criminal forums, lookalike domains are created to impersonate trusted brands, and sensitive information can surface across deep and dark web sources long before security teams become aware of the exposure. Exposed credentials can show up on the dark web within 24 hours. Yet reports have shown that only 19% of organizations continuously monitor for that exposure and automatically remediate it. Most organizations lack the visibility, expertise, and operational processes needed to identify and respond to these risks before they lead to compromise.

ION for Dark Web Monitoring addresses this challenge by combining continuous monitoring across curated threat intelligence sources with the same investigation, automation, and response capabilities that power Ontinue’s managed security operations service. Rather than simply generating alerts, ION for DWM operationalizes external threat intelligence, transforming exposures into investigated incidents and actionable security outcomes.

“The security perimeter no longer ends at the edge of the enterprise,” said Moritz Mann, CEO of Ontinue. “Organizations need visibility into the threats that exist beyond their environment, whether that’s stolen credentials being offered for sale, new brand impersonation campaigns, or emerging signs of attacker activity. Most dark web monitoring solutions stop at detection. ION for Dark Web Monitoring goes further by investigating findings, assessing risk, and helping customers take action before exposures become incidents.”

Turning External Threat Intelligence into Action

ION for Dark Web Monitoring continuously monitors customer-owned domains and brand assets across trusted intelligence sources spanning the clear, deep, and dark web. Findings are validated, enriched, and operationalized through the ION SecOps Platform, enabling customers to leverage the same Cyber Defense Center analysts, automation workflows, and response capabilities already protecting their environments 24/7.

Key capabilities include:

Continuous Monitoring for Exposed Credentials: ION for DWM continuously identifies credentials associated with customer domains that may have been exposed through breaches, criminal marketplaces, or other external sources, helping organizations reduce the likelihood of account compromise and unauthorized access.Detection of Typosquatting and Brand Impersonation: The service detects suspicious domains designed to mimic trusted brands and assesses their potential risk, enabling organizations to identify and disrupt phishing, fraud, and impersonation campaigns earlier.Integrated Investigation and Response: Unlike traditional monitoring tools that generate raw alerts, ION for DWM validates findings, assesses relevance and severity, and operationalizes them through ION MXDR workflows. Approved response actions can be executed automatically or with customer oversight based on predefined rules of engagement.Unified Security Operations: External exposures flow directly into Microsoft Sentinel and the ION SecOps Platform, where they are investigated alongside other security signals using the same automation, detection, and response processes that support Ontinue’s Agentic SOC.

“ION for Dark Web Monitoring expands our visibility beyond our existing tools, giving us better insight into external risks and bringing validated findings into the managed security operations we already trust,” said Jason Burzenski, Vice President, Global Head of Cyber Security at Epiq.

A Managed Approach to Reducing Exposure Risk

Many organizations receive threat intelligence feeds and dark web monitoring alerts but lack the resources to investigate findings, determine relevance, or coordinate response actions. As a result, exposures often remain unresolved until attackers take advantage of them.

ION for Dark Web Monitoring was designed to close that gap by providing a managed service experience rather than another security dashboard. Every finding benefits from expert review, contextual analysis, and operational response, helping security teams focus on reducing risk rather than managing alerts.

“Dark web monitoring has moved from a nice-to-have add-on to a meaningful component of a mature MDR program. Adversaries do not operate in isolation from the organizations they target. Credential exposure, ransomware leak staging, and brand impersonation activity on dark web forums often precede or accompany active intrusions. IDC’s research shows that roughly one in three MDR customers globally still lack dark web monitoring as part of their service, which represents a significant visibility gap at a time when pre-compromise intelligence is increasingly what separates early detection from late discovery. Providers that integrate dark web monitoring with analyst-triaged intelligence and actionable takedown capability, rather than delivering raw feed data, are closing that gap in a way that directly improves security outcomes for their customers.” Yogesh Shivhare, Sr. Research Manager, Security and Trust at IDC. 

Built for Microsoft-Centric Security Operations

Built for Ontinue’s Microsoft-first security operations model, ION for Dark Web Monitoring helps organizations extend visibility beyond their environment without adding another technology platform. Findings, investigations, and response activities become part of a unified security operations workflow, reducing operational complexity while strengthening overall resilience.

ION for Dark Web Monitoring is available immediately as an add-on service for ION MXDR customers.

For more information about Ontinue, visit our Dark Web Monitoring page.

Additional Resource: 

Blog: Beyond the Perimeter: What Security Teams Are MissingWebinar: Ontinue Offers new Dark Web Monitoring service for ION MXDR Customers

About Ontinue

As a leading provider of AI-powered managed security operations, Ontinue is on a mission to give every organization the freedom to focus on what they do best; by making nonstop security excellence accessible, not just aspirational. By combining advanced AI with deep human expertise, Ontinue delivers managed security operations that are tailored to each organization’s unique environment, operational needs, and risk profile.

Ontinue’s ION SecOps Platform integrates AI-driven insights, automation, and real-time collaboration to continuously prevent, detect, and respond to threats. With deep expertise in Microsoft security technologies, Ontinue helps customers maximize the value of their existing investments while achieving stronger, more scalable security outcomes.

Continuous protection. AI-powered Nonstop SecOps. That’s Ontinue.

Media Contact
Alison Raymond
araymond@icrinc.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/ontinue-expands-external-threat-visibility-with-ion-for-dark-web-monitoring-302898964.html

SOURCE Ontinue

Continue Reading

Trending